Moderate risk — proven privacy technology with the largest anonymity set in DeFi, offset by governance vulnerabilities, regulatory uncertainty, and supply chain security concerns.
Risk Breakdown
Top Risks
Governance was compromised in May 2023 when an attacker used a malicious proposal with hidden SELFDESTRUCT/CREATE2 logic to grant themselves 1.2M votes, exceeding the legitimate 700K votes. The attacker later returned control, but the attack vector demonstrated that DAO proposal auditing is insufficient to prevent governance takeover.
OFAC sanctions from August 2022 to March 2025 severely restricted Tornado Cash usage by US persons and entities. While sanctions were lifted, regulatory risk remains elevated as privacy protocols face ongoing scrutiny from global financial regulators.
The protocol's anonymity set degrades at low usage periods — fewer deposits and withdrawals in a given pool denomination make it easier to correlate transactions. TVL volatility driven by regulatory uncertainty directly impacts privacy guarantees.
A supply chain attack implanted backdoor code in the Tornado Cash npm package, marking the second major security breach after the governance hack. This highlights risks in the protocol's open-source maintenance model post-sanctions.
Frequently Asked Questions
Is Tornado Cash safe to use?
What are the main risks of using Tornado Cash?
What is Tornado Cash's risk score breakdown?
How does Tornado Cash compare to other DeFi protocols?
Has Tornado Cash ever been hacked or exploited?
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.