Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Crypto Firms Say US Sanctions Limit Use of Privacy Software

The Treasury Department is facing pushback from the cryptocurrency industry over sanctions imposed on a firm accused of helping to launder billions of dollars — with some funds going to North Korean hackers.

The Treasury Department is facing pushback from the cryptocurrency industry over sanctions imposed on a firm accused of helping to launder billions of dollars — with some funds going to North Korean hackers.

Earlier this month, the Treasury Department imposed sanctions on the virtual currency mixing firm, Tornado Cash, which allegedly helped to launder more than $7 billion worth of virtual currency since its creation in 2019.

Mixing services combine various digital assets, including potentially illegally and legitimately obtained funds, to keep the origins of the funds secret, including money that has been stolen.

In the weeks after the sanctions were announced, crypto firms, lobbyists and at least one lawmaker have come to the firm’s defense, saying the sanctions open the door to limiting Americans’ usage of privacy software.

Coin Center, a nonprofit crypto advocacy firm, says Treasury’s financial crimes enforcement arm “overstepped its legal authority” through its sanctions, which “potentially violates constitutional rights to due process and free speech.”

One cryptocurrency firm, Tether, has said it would not freeze its accounts tied to Tornado Cash and intends to keep them open. And Rep. Tom Emmer (R-Minn.), who has received at least $50,000 in contributions from the Blockchain Association this year, wrote to Treasury Secretary Janet Yellen this week asking for the rationale for sanctioning Tornado Cash, saying the sanctions “impact not only our national security, but the right to privacy of every American citizen.”

{ Read: How Economic Changes and Crypto’s Rise Are Fueling the use of “Cyber Mules” }

He told The Associated Press the sanctions punish Americans who use the firm’s software for legitimate purposes. “My government has no business sanctioning my ability to use a software that protects my anonymity, especially when I’m using it for legitimate purposes,” he said.

Advertisement. Scroll to continue reading.

The defense of the firm comes as a Tornado Cash developer Alexey Pertsev was arrested by Dutch authorities in early August, days after U.S. sanctions were imposed, for allegedly facilitating money laundering.

Treasury’s Office of Foreign Assets Control says Tornado Cash’s systems were used, among other things, to launder more than $96 million drawn from the June Harmony blockchain bridge theft and August Nomad crypto firm heist.

{ Read: North Korea Lazarus Hackers Blamed for $100 Million Horizon Bridge Heist }

A Treasury spokesperson said that the agency is focused on disrupting criminal behavior and will use its sanctions authorities to protect the U.S. financial system from illicit activity like cyber theft, money laundering, and weapons proliferation financing.

Kristin Smith, executive director of the Blockchain Association, said the sanctions impact law abiding users of crypto mixing technology.

“If you are paid in cryptocurrency, transactions on most blockchains are transparent,” she said, adding that mixers are used by those who don’t want their transactions viewable on a public ledger.

“I think we do need to have a conversation around privacy and empower law enforcement without undermining people’s ability to have private transactions,” Smith said.

This is not the first set of sanctions on a digital asset mixing firm.

In May, the U.S. announced sanctions against North Korean digital currency mixing firm Blender.io, accused of helping Lazarus Group, the sanctioned North Korean cyber hacking group, carry out a $600 million digital currency heist in March.

Since the Tornado Cash sanctions, crypto experts have speculated on whether expected regulations would result in a ban on mixing services.

The Biden administration issued an executive order on digital assets in March that calls, in part, for regulations on the industry.

“This may be the end,” Smith said “but we wont know until we see the regulations.”

Related: Google Warning: North Korean Gov Hackers Targeting Security Researchers

Related: North Korea Gov Hackers Caught Sharing Chrome Zero-Day

Related: North Korean Hackers Back With Fake Pen-Test Company

 

Related: The Curious Case of the $600 Million Crypto Heist

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.