The Conventional Wisdom
Sanctions professionals often treat decentralized protocols like traditional entities. When OFAC adds something to the Specially Designated Nationals and Blocked Persons List, your team blocks it. If Tornado Cash appears on the SDN List, you screen for it, block transactions involving it, and report matches. The underlying technology doesn't matter, a designated entity is a designated entity, whether it's a shell company or a cryptocurrency mixer.
This approach seems logical. OFAC publishes the list, and you enforce it. Sanctions compliance has always worked this way across asset classes and technology platforms. Why should decentralized finance be different?
Why This Approach Is Incomplete
The Fifth Circuit's Tornado Cash ruling exposes a critical gap: you can't sanction what isn't property under the International Emergency Economic Powers Act 1977. The court ruled that immutable smart contracts, code that executes automatically and can't be altered once deployed, don't qualify as property that OFAC can block.
This ruling is significant for sanctions analysts. It forces you to distinguish between an entity and its technical components. The court didn't rule that Tornado Cash as a whole can't be sanctioned. It ruled that specific Ethereum addresses running immutable smart contracts can't be designated because those addresses don't represent controllable property.
This distinction matters because your screening systems don't make it. When you screen against OFAC's SDN List, you're matching against addresses OFAC designated. If some of those addresses represent immutable smart contracts that the Fifth Circuit says can't legally be designated, you're enforcing sanctions that may not withstand judicial review, at least in the Fifth Circuit's jurisdiction.
The conventional wisdom assumes legal designation equals legal enforceability. The Tornado Cash ruling shows that assumption breaks down when the designated item doesn't meet the statutory definition of sanctionable property.
The Evidence
The Fifth Circuit's reasoning is based on statutory interpretation. IEEPA authorizes the President to block "any property in which any foreign country or a national thereof has any interest." The court concluded that immutable smart contracts aren't property under this definition because no one, not Tornado Cash's creators, not foreign nationals, can control or modify them once deployed.
This creates an enforcement problem. OFAC designated specific Ethereum addresses that interact with Tornado Cash's smart contracts. According to CoinBase's chief legal officers Paul Grewal and Leah Bressack, the judgment doesn't require OFAC to remove Tornado Cash from the SDN List entirely. It only invalidates the designation of immutable smart contract addresses. Mutable smart contracts, servers, funds, and other property interests that Tornado Cash controls could still be sanctioned.
Here's the operational challenge: OFAC has until January 21 to appeal. Until this becomes final, and until OFAC removes the invalid addresses (if it does), your screening system still flags them. You're potentially blocking transactions based on designations that a federal appeals court says exceed OFAC's statutory authority.
The Eleventh Circuit is hearing a separate challenge to the same sanctions. If that court reaches a different conclusion, you'll have circuit-split uncertainty, lawful in one jurisdiction, unlawful in another.
What to Do Instead
First, stop assuming every OFAC designation is technically and legally identical. When you encounter a decentralized protocol on the SDN List, ask: what exactly did OFAC designate? The entity? Specific addresses? Both?
For Tornado Cash specifically, review your transaction monitoring and screening protocols. If you operate in the Fifth Circuit's jurisdiction (Texas, Louisiana, Mississippi), consult legal counsel about whether to continue blocking transactions involving the immutable smart contract addresses. If you operate nationally, you face a harder choice: accept potential legal risk in the Fifth Circuit or accept potential sanctions violations elsewhere.
Second, build flexibility into your screening workflows. Your sanctions screening system should let you selectively disable specific addresses while keeping the broader entity designation active. This is essential. If OFAC removes certain addresses following the Fifth Circuit's mandate, you need to update your screening rules without removing Tornado Cash entirely.
Third, document your risk assessment. If you continue blocking the immutable smart contract addresses despite the Fifth Circuit ruling, document why. If you stop blocking them in certain jurisdictions, document that decision and the legal basis. OFAC examiners will want to see your reasoning either way.
Fourth, watch the Eleventh Circuit case and any potential Supreme Court appeal. The Fifth Circuit's reasoning may not survive higher review. OFAC may appeal, or the Eleventh Circuit may reject the Fifth Circuit's interpretation. Your compliance approach needs to adapt as the legal landscape shifts.
Finally, prepare for more cases like this. Decentralized protocols don't fit traditional sanctions frameworks. Courts will continue wrestling with whether code can be property, whether protocols can be entities, and whether sanctions designed for bank accounts and cargo ships apply to autonomous smart contracts. Your sanctions compliance program needs analytical frameworks that account for these distinctions, not just screening rules that treat everything the same.
When the Conventional Wisdom Is Right
The conventional wisdom absolutely applies to centralized aspects of decentralized protocols. Tornado Cash's creators, Roman Storm and Roman Semenov, can be sanctioned as individuals. Their servers, bank accounts, and business interests are property. Mutable smart contracts they control are arguably property. Funds the protocol generates are property.
If OFAC designates a decentralized protocol's founders, operators, or corporate entities, block them. If OFAC designates wallets, servers, or other controllable assets, block those too. The Fifth Circuit ruling doesn't create a blanket exemption for anything crypto-related.
The conventional wisdom also holds for protocols with governance mechanisms. If token holders can vote to modify the protocol, if developers can upgrade the code, if anyone exercises meaningful control, you're back in traditional sanctions territory. The Fifth Circuit's reasoning applies specifically to immutable smart contracts, code that truly runs autonomously without human intervention.
For most sanctions compliance work, the traditional approach remains correct: OFAC designates, you block, you report. The Tornado Cash ruling creates a narrow exception for a specific technology configuration. Don't overgeneralize it, but don't ignore it either.



