← Back to Home

tornado.cash Scam Check: 20/100 Trust | ScamMinder

Website: tornado.cash

Screenshot of tornado.cash

Safety Score

20/100
✗ Scam Risk

Exercise caution when interacting with this website.

AI Analysis Results

Category: Financial Services
About this website:

Detailed Analysis Report: Is Tornado.cash Safe and Legit? Website Overview and Purpose Tornado.cash is a decentralized privacy protocol designed for secure and anonymous transactions on the Ethereum blockchain. It aims to enhance user privacy by breaking the on-chain link between source and destination addresses, allowing users to conduct transactions without revealing their identities. Content Quality and User Experience Key Experience Highlights Offers a user-friendly interface for managing private transactions. Provides detailed documentation and FAQs to assist users. Includes statistics on total ETH deposited and unique users. Features governance through community participation via TORN tokens. Claims Verification and Red Flags ⚠️ Red Flags Detected Several red flags have been identified that raise concerns about the legitimacy of Tornado.cash: Regulatory Issues: The protocol has faced scrutiny from regulatory bodies, which may indicate potential legal risks. Security Concerns: The presence of a single detection on VirusTotal raises questions about the site's safety. Domain Age: The domain age is unverified, which is a common characteristic of potentially fraudulent sites. Unclear Ownership: Lack of transparency regarding the team behind the protocol and their credentials. High-Risk Business Model: The nature of the service, focusing on anonymity in transactions, is often associated with scams and illegal activities. ⚠️ Caution Points Users should exercise caution when engaging with the protocol and verify all claims independently. Be wary of any requests for sensitive information or wallet connections. Security Note: The website uses a DV SSL certificate, which does not guarantee legitimacy. Legitimacy and Reputation Assessment The domain's age is currently unverified, and there is no substantial archive history available. The hosting provider is located in the Netherlands, which may not offer the same level of consumer protection as other jurisdictions. The website's reputation is further compromised by its association with privacy protocols that have been scrutinized by authorities. Final Verdict and Recommendations Conclusion: Tornado.cash presents several red flags that suggest it may not be a safe platform for users. The lack of transparency, regulatory scrutiny, and potential security risks warrant caution. Users are advised to conduct thorough research and consider alternative platforms with clearer regulatory compliance and transparency.

Risk Assessment: scam
⚠️ Red Flags:
  • [GUARDRAIL] No deterministic evidence for scam; downgrading to warning
  • [REGULATORY] The protocol has faced scrutiny from regulatory bodies, which may indicate potential legal risks.
  • [SECURITY] The presence of a single detection on VirusTotal raises questions about the site's safety.
  • [DOMAIN] Domain age is unverified, which is a common characteristic of potentially fraudulent sites.
  • [TRANSPARENCY] Lack of transparency regarding the team behind the protocol and their credentials.
📊 Analysis Reasons:
  • [REGULATORY] Tornado.cash has faced scrutiny from regulatory bodies, indicating potential legal risks.
  • [SECURITY] The presence of a single detection on VirusTotal raises concerns about the site's safety.
  • [DOMAIN HISTORY] Domain age is unverified, which is a common characteristic of potentially fraudulent sites.
  • [TRANSPARENCY] Lack of transparency regarding the team behind the protocol and their credentials.
  • [BUSINESS MODEL] The focus on anonymity in transactions is often associated with scams and illegal activities.
🛡️ Safety Actions Applied:
  • {"type":"scam_downgraded","reason":"No deterministic evidence for scam; downgrading to warning","scoreCeiling":null,"targetStatus":"warning"}
Score Source: openai_guardrail
AI Confidence: medium

Technical Details

Tornado Cash Classic

A fully decentralized protocol for private transactions on Ethereum.

\n Launch App\n
IPFS Hash: \n QmNYd99v6bEnnVRUEAXTkSUcXdTGZ4SyJL4FjnHqNZPJdx\n

Tornado Cash Nova

Second-generation privacy protocol supporting arbitrary amounts and shielded transfers.

\n Launch Nova\n
IPFS Hash: \n QmVS4SPsH44oJPCffUZZUGTXqCpSx3eK8UJ8YmZsSDygop\n

Supported Networks

Ethereum Mainnet
Binance Smart Chain
Polygon Network
Optimism
Arbitrum One
Gnosis Chain
Avalanche Mainnet
Ethereum Goerli

How Tornado Cash works

Deposit

A user generates a random key (note) and deposits Ether or an ERC20, along with submitting a hash of the note to the Tornado Cash smart contract.

Wait

After depositing, users should wait some amount of time before withdrawing to improve their privacy.

Withdraw

A user submits a proof of having the valid key to one of the notes deposited and the contract transfers Ether or the ERC20 to a specified recipient.

How Tornado Cash achieves privacy

Tornado Cash improves transaction privacy by breaking the on-chain link between source and destination addresses. It uses a smart contract that accepts ETH deposits that can be withdrawn by a different address. To preserve privacy a relayer can be used to withdraw to an address with no ETH balance. Whenever ETH is withdrawn by the new address, there is no way to link the withdrawal to the deposit, ensuring complete privacy.

1,005,116
Total ETH deposited
11,583
Unique users
41,215
Total deposits

Status of Tornado Cash decentralization

Tornado Cash protocol is fully decentralized and owned by the community: Tornado Cash initial developers have no control over it and are not running any servers

Tornado Cash smart contracts, circuits, and toolchain are fully open sourced.

\n

Tornado Cash smart contracts are unstoppable: there are no admins and no upgradability. Nobody including Tornado Cash initial developers can change it or shut it down.

\n

User interface is hosted by the community on IPFS. It is accessible as long as at least 1 user in the world is hosting it.

\n

Tornado Cash governance and mining smart contracts are deployed by the community in a decentralized way, there is no single deployer.

\n

Protocol parameters and token distribution are controlled by the community via governance.

\n

Trusted setup ceremony for zkSNARKs has 1114 contributions, as long as at least 1 contribution is honest, the zkSNARK keys are secure.

\n

Tornado Cash protocol is developed based on awesome open source research by Zcash team with the help of amazing Ethereum community.

\n

Our Products

Governance

Tornado Cash is completely decentralized, controlled and governed by its community. By acquiring TORN tokens, you can participate by voting on governance proposals and weighing in on the evolution of the protocol.

Read More

Anonymity Mining

By using Tornado Cash, you also mine TORN, the governance token of Tornado Cash. The more you use it, the more say you have in the evolution of the protocol.

Read More

Compliance

Maintaining financial privacy is essential to preserving our freedoms. Tornado Cash has built-in tools for proving your transaction history and selectively disclosing Tornado deposits.

Read More

Trusted Setup Ceremony

Trusted setup ceremony for zkSNARKs has 1114 contributions, as long as at least 1 contribution is honest, the zkSNARK keys are secure.

Read More

Initiation

Tornado Cash Governance protocol was deployed by community in a decentralized way. It's only possible using CREATE2 opcode and EIP-2470 deployer.

Read More

Relayers Network

Relayers are used to send a withdrawal transaction to an account with no balance, which promotes further user anonymity. To become a relayer, one must register on the Decentralized Relayers Network Registry and meet minimum requirements.

Read More

Frequently asked questions

Is it possible to compromise the protocol and find out information about depositors?

No, Tornado Cash is a decentralized protocol based on zero knowledge proofs. Its smart contracts are immutable, have no admins, and the proofs are based on strong cryptography. Only the user possessing the Note is able to link deposit and withdrawal.

\n
Do you collect data?

The Tornado Cash project does not collect any user data. The UI is hosted in a decentralized way on IPFS and can be accessed using following link tornadocash.eth.limo. Users can also run it locally or use the CLI tool.

\n
Which steps can be taken to ensure the anonymity of participation in the protocol?

The Tornado Cash protocol solves only on-chain piece of the privacy. Users also must follow these best practices to achieve privacy.

\n
Has the protocol been audited?

The Tornado Cash protocol was audited by multiple professional audit companies. Here are the links of the reports:

\n\n

The Tornado Cash anonymity mining protocol also was audited multiple times:

\n\n

The Tornado Cash Nova protocol audited too:

\n\n
What is a relayer?

Relayers are used to withdraw to an account with no ETH balance. The relayer sends a withdrawal transaction and takes a part of the deposit as compensation (the protocol itself does not collect any fees). The relayer cannot change any withdrawal data including recipient address. The Tornado Cash initial developers do not control or play any role in relaying transactions, the relay network is independent and run by community. If you want to run your own relayer, follow these instructions.

\n
Is the code open-source?
Can I prove my source of funds if I use Tornado Cash?

Yes, you can use the compliance tool to generate a report which proves your source of funds.

\n
","screenshot":"https://cdn.scamminder.com/include/uploads/2025/11/tornado.cash-20251113-014427.webp","loadTimeInSeconds":4.502,"title":"Tornado.cash","keywords":"Tornado, Tornadocash, Ethereum, ERC20, dapp, smart contract, secure, anonymous, private, decentralized, metamask, zksnark, zero knowledge","description":"Ethereum is a decentralized, surveillance-free privacy protocol that keeps your assets, transactions secure and private","links":["https://tornado.cash","https://tornado.cash/audits/TornadoCash_cryptographic_review_ABDK.pdf","https://tornado.cash/audits/TornadoCash_contract_audit_ABDK.pdf","https://tornado.cash/audits/TornadoCash_circuit_audit_ABDK.pdf","https://tornado.cash/audits/TornadoCash_Classic_dApp_audit_Decurity.pdf","https://tornado.cash/audits/TornadoCash_anonymity_mining_first_audit_ABDK.pdf","https://tornado.cash/audits/TornadoCash_anonymity_mining_final_audit_ABDK.pdf","https://tornado.cash/audits/TornadoCash_anonymity_mining_recheck_audit_ABDK.pdf","https://tornado.cash/audits/TornadoCash_anonymity_mining_audit_Zeropool.pdf","https://tornado.cash/audits/TornadoCash_Nova_audit_Zeropool.pdf"],"scraper_engine":"Puppeteer (Enhanced)","screenshot_size_bytes":51451,"domSignals":{"lang":"en","canonical":"https://tornado.cash/","hasLogin":false,"hasCheckout":false,"hasContact":false,"hasPolicy":false,"ogTitle":"Tornado.Cash","ogSite":"","ogDescription":"Ethereum is a decentralized, surveillance-free privacy protocol that keeps your assets, transactions secure and private"},"formRisks":[],"httpStatus":200,"finalUrl":"https://tornado.cash/","htmlLength":410248,"textLength":5824,"lowEvidenceRecovery":false,"parkingDetection":{"isParked":false},"otherpages":{"internalLinks":["https://tornado.cash"],"internalPageContents":[""]}},"webrisk":{"overall_risk":"unknown","threats":[],"malware":false,"social_engineering":false,"unwanted_software":false,"error":"Request failed with status code 400"},"metadata":{"preflight":{"bestUrl":"https://tornado.cash","probes":[{"url":"https://tornado.cash","ok":true,"status":200},{"url":"https://www.tornado.cash","ok":true,"status":200},{"url":"http://tornado.cash","ok":true,"status":200}],"zyteCheck":null},"best_url":"https://tornado.cash","phase_a_duration_ms":3501,"phase_b_duration_ms":13419,"early_exit_reason":null,"tls_warnings":[],"zyte_preflight":null,"low_evidence_recovery":false},"virustotal":{"malicious":1,"suspicious":0,"total":98,"scanned":true},"archive_gap":{"suspicious":1,"details":{"domain_age_days":0,"total_snapshots":205,"unique_snapshots":166,"snapshot_span_days":2232,"first_snapshot":"2019-08-08","last_snapshot":"2025-09-17","consistency_analysis":{"avg_snapshots_per_month":5,"months_with_snapshots":41,"gap_count":33,"longest_gap_months":30,"longest_recent_gap_months":15},"yearly_activity":[{"year":2020,"count":39,"months_active":11,"active":true},{"year":2021,"count":57,"months_active":11,"active":true},{"year":2022,"count":69,"months_active":8,"active":true},{"year":2023,"count":0,"months_active":0,"active":false},{"year":2024,"count":0,"months_active":0,"active":false},{"year":2025,"count":32,"months_active":7,"active":true}],"recent_gaps":{"recent_gap_count":6,"longest_recent_gap":4},"suspicious_score":1,"suspicious_reasons":["Extremely new domain (<60 days) with disproportionate coverage"]},"reasons":[]},"evidence_coverage":"70"},"reviews":[],"has_archive":false,"archive_data":null,"archive_stats":null}};