Skip to content

LibraryPrivacy2019Design paperCorpus record

Tornado Cash: a fixed-denomination mixer proved by a succinct argument

Tornado Cash. Tornado Cash developers.

The tornado-core repository publishes a mixer: a deposit of a fixed denomination is a commitment, and a withdrawal proves knowledge of some unused commitment without saying which.

A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.

The tornado-core repository publishes a mixer: a deposit of a fixed denomination is a commitment, and a withdrawal proves knowledge of some unused commitment without saying which.
Evidence
Primary paper
Re-measured
No
Assumptions
3
Records linked
2

01 Claim ledger

What the paper is allowed to say

Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.

  1. Claim 01 · Paper model

    The defect

    A mixer is an anonymity set of equal deposits. It is not a shielded account system, and it is not private against a relayer or a user who reuses behaviour outside the circuit.

  2. Claim 02 · Paper model

    The proposal

    The tornado-core repository publishes a mixer: a deposit of a fixed denomination is a commitment, and a withdrawal proves knowledge of some unused commitment without saying which.

  3. Claim 03 · Paper model

    The mechanism

    The commitment goes into a tree. The withdrawal reveals a nullifier and a proof of membership. The denomination is fixed so amounts do not distinguish deposits.

  4. Claim 04 · Paper model

    The bound

    This note states no volume and no anonymity-set size.

02 Three cuts

Observation, model, falsifier

A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.

  1. 01 The defect

    Observation

    What the study says

    A mixer is an anonymity set of equal deposits. It is not a shielded account system, and it is not private against a relayer or a user who reuses behaviour outside the circuit.

    Model

    What has to hold

    You are reading the tornado-core repository as a design. This desk does not provide instructions for using it.

    Falsifier

    What would retire it

    What is revealed on withdrawal: nullifier, recipient, relayer?

  2. 02 The proposal

    Observation

    What the study says

    The tornado-core repository publishes a mixer: a deposit of a fixed denomination is a commitment, and a withdrawal proves knowledge of some unused commitment without saying which.

    Model

    What has to hold

    You are reading the tornado-core repository as a design. This desk does not provide instructions for using it.

    Falsifier

    What would retire it

    What denomination does the instance you opened fix?

  3. 03 The mechanism

    Observation

    What the study says

    The commitment goes into a tree. The withdrawal reveals a nullifier and a proof of membership. The denomination is fixed so amounts do not distinguish deposits.

    Model

    What has to hold

    No price, supply, yield, or adoption figure is added by this desk.

    Falsifier

    What would retire it

    What is revealed on withdrawal: nullifier, recipient, relayer?

  4. 04 The bound

    Observation

    What the study says

    This note states no volume and no anonymity-set size.

    Model

    What has to hold

    You are reading the tornado-core repository as a design. This desk does not provide instructions for using it.

    Falsifier

    What would retire it

    What denomination does the instance you opened fix?

03 Sequence

One action, as an operating tape

  1. 01The commitment goes into a tree. The withdrawal reveals a nullifier and a proof of membership. The denomination is fixed so amounts do not distinguish deposits.
  2. 02A relayer can submit the withdrawal so the recipient does not need a pre-existing balance for gas. The relayer sees the destination the user gives them.
  3. 03The contract does not know the law. This note describes the mechanism. It does not advise anyone to use it.

04 Load-bearing

The argument, and where a pitch drops it

  1. What the name has to mean

    The cut

    The tornado-core repository publishes a mixer: a deposit of a fixed denomination is a commitment, and a withdrawal proves knowledge of some unused commitment without saying which.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    Fixed denomination privacy collapses if users split and recombine in public around the contract.

  2. What actually moves

    The cut

    A relayer can submit the withdrawal so the recipient does not need a pre-existing balance for gas. The relayer sees the destination the user gives them.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A later client, parameter or reward formula is a different object from this paragraph.

  3. What a later deployment may change

    The cut

    The contract does not know the law. This note describes the mechanism. It does not advise anyone to use it.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    Fixed denomination privacy collapses if users split and recombine in public around the contract.

05 Register

What has to be true

  • Model · Not re-measured

    You are reading the tornado-core repository as a design. This desk does not provide instructions for using it.

  • Model · Not re-measured

    The document is the one at the source URL. A marketing page with the same brand is not this text.

  • Model · Not re-measured

    No price, supply, yield, or adoption figure is added by this desk.

06 Divergence

What happened after the paper

Fixed denomination privacy collapses if users split and recombine in public around the contract.

A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.

07 Pre-mortem

What to check before you use the idea

  1. 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.

08 Anatomy

The paper, in the order a builder needs

The problem it names

A mixer is an anonymity set of equal deposits. It is not a shielded account system, and it is not private against a relayer or a user who reuses behaviour outside the circuit.

What the design proposes

  • The commitment goes into a tree. The withdrawal reveals a nullifier and a proof of membership. The denomination is fixed so amounts do not distinguish deposits.
  • A relayer can submit the withdrawal so the recipient does not need a pre-existing balance for gas. The relayer sees the destination the user gives them.
  • The contract does not know the law. This note describes the mechanism. It does not advise anyone to use it.

How the mechanism is specified

  • The commitment goes into a tree. The withdrawal reveals a nullifier and a proof of membership. The denomination is fixed so amounts do not distinguish deposits.
  • A relayer can submit the withdrawal so the recipient does not need a pre-existing balance for gas. The relayer sees the destination the user gives them.
  • The contract does not know the law. This note describes the mechanism. It does not advise anyone to use it.

What this page does not treat as proven

  • This note states no volume and no anonymity-set size.
  • It is not legal advice, and it is not a description of any sanction. Those are outside the repository.
  • Fixed denomination privacy collapses if users split and recombine in public around the contract.

Why the desk still reads it

The tornado-core repository publishes a mixer: a deposit of a fixed denomination is a commitment, and a withdrawal proves knowledge of some unused commitment without saying which.

09 Lexicon

Terms, opened into the record

Commitment
The hash placed in the tree at deposit. The withdrawal should not point at it.
Nullifier
The marker that stops the same deposit being withdrawn twice.

10 Repository

Every linked record on this page

Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.

Concepts

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.