Cointime

Download App
iOS & Android

Mixers and Tumblers: Regulatory Overview and Use in Illicit Activities

Validated Media

The use of mixers and tumblers in various illicit activities such as money laundering and hacks is rapidly increasing. Attackers run illicit proceeds through mixers and tumblers to obscure the trail of ownership by pooling others’ holdings, scrambling it, and redistributing the funds on the other end. On January 18, 2022, $34 million in crypto was stolen from Singapore-based crypto exchange, Crypto.com. Reportedly, the stolen Ethereum (ETH) was laundered through Tornado Cash — an ETH mixer protocol  — and Bitcoin was laundered through an unknown Bitcoin mixer.

However, with the rise in the use of mixers and tumblers for illicit activities, the regulatory scrutiny around them is also increasing. The FATF in its Second 12 Month Review Report, under the section, Trends in the use of Virtual Assets (VA) for ML/TF purposes, noted that the use of mixers/tumblers by bad actors for obfuscating the source of funds has significantly gone up.

Use of cryptocurrency tumblers in conducting illicit activities

Hacks: Crypto mixers and tumblers are services that help attackers confuse the trail of crypto transactions by associating unrelated funds together using various methods. Attackers often use unregulated decentralized mixers and tumblers on the darknet to surpass regulatory requirements such as the Know Your Customer (KYC) requirement

In 2021, a large number of hackers used mixers and tumblers to evade detection. In the Liquid Global Hack, hackers sent roughly 6,000 stolen Ethereum (ETH) amounting to $20 million to Tornadocash.com, allowing them to hide their transactions by mixing their coins in with the others. Similarly, in the BitMart Hack hackers stole $150 million worth of tokens from ETH and Binance Smart Chain (BSC) hot wallets. The hackers swapped the stolen tokens by using the 1inch — decentralized exchange aggregator — and then used Tornado Cash to deposit the funds, allowing them to keep their identities hidden.

Darkweb: Criminals may use mixers and tumblers and the dark web to clean dirty crypto. Mixers and tumblers clean dirty crypto by bouncing it between various addresses, before recombining the full amount through a crypto wallet hosted on the dark web.

To conduct illicit activities using mixers and tumblers, attackers usually use one crypto wallet hosted on Clearnet (public internet) and two or more crypto wallets running solely on the dark web. For example, an attacker will send crypto from a wallet hosted on Clearnet to mixers and tumblers. After tumbling the clean crypto is transferred to the attackers’ TOR wallets. TOR wallets are anonymous wallets designed to keep their user’s identities hidden. TOR works by changing the location of the users’ internet address and encrypts the internet address by rerouting the users’ network via multiple remote servers. These encrypted transactions are repeated multiple times across dark web crypto addresses, adding a layer of obfuscation with each transaction.

Money laundering: The process of running dirty crypto through mixers and tumblers is very similar to the three stages of money laundering. The three stages of the money laundering process are placement, layering, and integration.

In the placement, stage criminals deposit dirty crypto into the tumbler. In a decentralized mixer, users receive crypto from other users during this stage. They are at the risk of receiving dirty crypto, which has been used for illicit activities, and can now connect them to these activities.

The second stage is called layering. In this phase, criminals use various types of services such as mixers and tumblers to create a complex transaction trail, removing the direct association with funds’ origin. Mixers split transactions into multiple smaller transactions and combine them again. Money launderers use mixes multiple times at various steps, making the source of funds unidentifiable.

The third stage is known as Integration. Once the process of mixing is complete, clean crypto is transferred to pre-determine wallets —either back to the sender or the new owner. Now, that the source of these funds is untraceable, the final phase is to legitimize the funds. There are many ways of doing this, sometimes money launderers may create new businesses providing services, which accept crypto payments. Then convert the crypto received into fiat currency through off-shore banking services.

Regulatory overview

FATF: The FATF in its Second 12 Month Review Report, under the sections — Trends in the use of Virtual Assets (VA) for ML/TF purposes — noted that the use of mixers/tumblers by bad actors for obfuscating the source of funds has significantly gone up. The FATF also observed that several mixer/tumbler services have been taken offline following enforcement action for operating as unregistered VASPs.

Further, in its Virtual Assets Red Flag Indicator Guidance, the FATF has stated that the transactions making use of mixing and tumbling services should be flagged, as they suggest an intent to obscure the flow of illicit funds between known wallet addresses and darknet marketplaces.

The U.S.: Under the Bank Secrecy Act (BSA), a money transmitter is required to develop and maintain a functional anti-money laundering (AML) compliance program and adhere to the applicable reporting and recording-keeping requirements. FinCEN further clarified its guidance in 2019 with FIN-2019-G001, stating the crypto anonymizing services — mixers and tumblers—are also considered money transmitters under the BSA.

The Department of Justice (DOJ) first charged Larry Harmon, the primary operator of bitcoin mixers Helix and Ninja, in 2019, with three crimes — conspiracy to commit money laundering, operating an unlicensed money transmitting business, and conducting money transmission without a license. In October 2020, FinCEN assessed a civil monetary penalty of $60 million against Harmon for not registering Helix as a money service business. Finally, in August 2021, Harmon pleaded guilty to helping darknet market criminals launder around $300 million.

In April 2021, U.S. authorities arrested Roman Sterlingov — Russian-Swedish founder of bitcoin tumbling service Bitcoin Fog — for helping people launder $335 million

In its first government-wide list of priorities for AML/CFT, the FinCEN made virtual currency considerations one of its top priorities. Further, the FinCEN had also issued a warning, noting that in cases of hacks, criminals may leverage tools such as mixers and tumblers in order to break the connection between the sender address and the receiver address.

On October 6, 2021, the U.S. Department of Justice announced the National Cryptocurrency Enforcement Team (NCET), an enforcement team dedicated to investigating and prosecuting criminal misuses of cryptocurrency — in particular mixers and tumblers.

 On August 8, 2022, the U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) sanctioned cryptocurrency mixer Tornado Cash, which has been used to launder more than $7 billion worth of crypto since 2019. 

Tornado Cash is the most popular coin-mixing service on the Ethereum blockchain. The service offers a set of smart contracts that enable the user to obfuscate their funds by cutting the link between their original address and the address they eventually receive the funds in.

This is not the first time a crypto mixer has been sanctioned by the U.S. Treasury. In May 2022, the OFAC added the crypto mixing service Blender. io to its Specially Designated Nationals list. The OFAC revealed that the crypto currency mixer was used to process more than $20.5 million in the Ronin Network Attack, which the U.S. Treasury had linked to the North Korea- backed Lazarus Group. This move is the latest in the Biden Administration's efforts to disrupt the illicit flow of funds from cyberattacks, especially crypto-centric North Korean cyberattacks. The OFAC has added Tornado Cash and 44 associated Ethereum and USD Coin (USDC) wallet addresses to its SDN list.According to the OFAC, Lazarus Group used Tornado Cash to launder circa $450 million. In fact, Tornado Cash has been at the center of multiple recent hacks including the Ronin bridge attack, Harmony bridge exploit, Nomad heist, Beanstalk flash loan attack, and more.“Despite public assurances otherwise, Tornado Cash has repeatedly failed to impose effective controls designed to stop it from laundering funds for malicious cyber actors on a regular basis and without basic measures to address its risks. Treasury will continue to aggressively pursue actions against mixers that launder virtual currency for criminals and those who assist them.” warned Under Secretary of the Treasury for Terrorism and Financial Intelligence Brian E. NelsonTornado Cash is the most popular coin-mixing service on the Ethereum blockchain. The service offers a set of smart contracts that enable the user to obfuscate their funds by cutting the link between their original address and the address they eventually receive the funds in. As a result of today’s sanctions all property and interests in the property of Tornado Cash that is in the U.S. or in the possession or control of the U.S. persons are blocked and must be reported to OFAC. Moreover, U.S. persons or entities cannot interact with Tornado Cash.

Comments

All Comments

Recommended for you

  • Spot Gold Declines by 2%

    On May 27, spot gold saw its intraday decline widen to 2%, trading at $4,416.32 per ounce.

  • Analysis: Bitcoin May Continue 'May Sell-off', Historical Signals Indicate About 10% Short-term Correction Risk

    Bitcoin has been weakening for a month, retreating after being blocked near $83,000, and is currently moving towards a decline in May, which the market views as a classic seasonal signal of 'May sell-off' re-emerging. Historical data shows that Bitcoin's average return one month after a 'red May' is approximately -10%, and about -3.3% over three months, with short-term trends typically continuing to weaken; based on historical averages, the price could fall to around the $68,200 range. Analysis indicates that 'red May' in a bear market structure is often more destructive; however, Bitcoin's average increase over the six months following 'red May' can reach about +139%, and even after excluding anomalous years, it remains around +12.9%, indicating that the long-term trend has not been disrupted by seasonal signals.

  • U.S. Stocks Open Higher with All Three Major Indices Up

    U.S. stocks opened higher, with all three major indices rising: the Dow Jones increased by 0.18%, the S&P 500 rose by 0.07%, and the Nasdaq gained 0.17%. Micron Technology (MU.O) surged by 6.6% after UBS significantly raised its target price to $162.50.

  • BTC Falls Below $75,000

    Market data shows that BTC has fallen below $75,000, currently priced at $74,968.47, with a 24-hour decline of 2.42%. The market is experiencing significant volatility, so please ensure proper risk management.

  • UCarpay CARDPIE: Connecting Digital Assets with Global Cross border Payment Channels

    As global demand for digital asset circulation and cross-border payments continues to grow, users are increasingly facing challenges such as limited access to traditional payment channels, high foreign exchange costs, and fragmented card management. In response to these market needs, CARDPIE, a professional USDT card aggregation platform, is building a seamless bridge between digital assets and global spending by delivering a comprehensive stablecoin payment solution for both individuals and enterprises.

  • Astarter releases multi chain expansion roadmap signal plan to extend to EVM and Solana ecosystems

    The Cardano ecological infrastructure project Astarter has released a multi chain expansion roadmap signal in public materials, gradually extending its clearing layer infrastructure to mainstream public chain ecosystems such as EVM and Solana. The Astarter team believes that the Al Agent economy and DePIN network essentially run across chains, and the execution layer that only anchors a single public chain is structurally limited. Multi chain expansion is a crucial step for Astarter to reach all AI agent economic activities. The specific deployment goals and timeline for the second public chain will be announced in subsequent announcements. Cardano will still be retained as the basic anchor chain.

  • US Spot Ethereum ETF Sees Net Outflow of $35.1 Million Yesterday

    On May 27, according to monitoring data from Farside Investors, the US spot Ethereum ETF experienced a net outflow of $35.1 million yesterday.

  • US Spot Bitcoin ETF Sees Net Outflow of $333.61 Million Yesterday

    On May 27, according to monitoring by Trader T, the US spot Bitcoin ETF experienced a net outflow of $333.61 million yesterday.

  • Supreme Court's Liu Guixiang: In-depth Study of Judging Rules for New Cases like Virtual Currency and Cross-Border Finance

    On May 27, Liu Guixiang, a deputy-level full-time member of the Supreme People's Court Judicial Committee and a second-level justice, stated at a press conference held by the State Council Information Office that the people's courts will legally support compliant and lawful financial innovation models, combat financial illegal activities, and conduct in-depth research on the judging rules for new cases such as virtual currency and cross-border finance.

  • Micron Technology Soars 12%, Market Value Reaches $950 Billion

    On May 26, Micron Technology's stock price rose by 12.09%, reaching $841.76 per share, with a total market value of $950 billion, setting a new historical high.