Back to Blog

Tornado Cash Tracing: What Two Real Investigations Reveal About Mixer Forensics

Phalcon Compliance
September 10, 2026
5 min read

Tornado Cash tracing is possible, and two documented investigations show exactly how. In the Li.Fi attack of 2024, more than 99 percent of the stolen 11.6 million dollars moved into Tornado Cash across 114 transactions over three months, and investigators mapped the entire path. In the Nomad Bridge incident, 190 million dollars scattered through the mixer in a free-for-all exploit, and the tracing still held. This is what the evidence from those cases teaches about how mixer forensics actually works.

What Tornado Cash Is and Why It Matters

Tornado Cash is a non-custodial mixer on Ethereum: users deposit from one address and withdraw to a different address. The pool design makes direct linking between a specific deposit and a specific withdrawal computationally hard. It became the reference case for mixer-assisted laundering, so much so that in 2022 the U.S. Treasury's OFAC sanctioned the protocol itself, a first for a smart contract, per the Treasury press release on the Tornado Cash designation. A federal appeals court unwound that designation in late 2024, OFAC formally delisted the protocol in March 2025, and sanctions on co-founder Roman Semenov and his associated addresses remain in place, now under OFAC's DPRK program. The regulatory story matters to compliance teams, but the tracing story is the operational one. The FATF standards for virtual assets and VASPs frame the screening obligation that mixer exposure touches, regardless of how a specific protocol's designation status moves.

The reason Tornado Cash matters for forensics is its volume. When the majority of stolen funds in major incidents route through one mixer, the mixer boundary is where investigations concentrate. And as the two cases below show, the boundary is hard, not impenetrable.

Case One: Li.Fi, $11.6M Through 114 Transactions

The Li.Fi attack of July 2024 offers an unusually complete picture of mixer discipline. The attackers stole roughly 11.6 million dollars in crypto and swapped the stolen stablecoins into ETH through decentralized exchanges. The proceeds then went into Tornado Cash in a sustained campaign, a monthslong series of deposits that carried almost the entire haul into the mixer.

The tracing, documented by BlockSec using MetaSleuth in the Li.Fi illicit fund flow case study, mapped the structure around the mixer even where the inside stayed opaque. Downstream of the initial attack addresses, 32 receiving addresses split the funds: 15 of them took token amounts of roughly 0.1 ETH each, while 17 addresses handled nearly all the value. The longest observed path ran 20 hops. The pattern inside the mixer discipline was consistent: the attackers used fresh, deeper addresses for every Tornado Cash operation. Large amounts moved through as many as 12 hops before entering the mixer; only the small remainder went to the exchange eXch for direct cash-out. That boundary record is evidence, and in the Li.Fi case the entry-side numbers, 114 transactions, three months, 99 percent, are the backbone of the public analysis.

Cross-chain tracing view with a risk-category legend, hop-by-hop fund flow, and address detail panel
Cross-chain tracing view with a risk-category legend, hop-by-hop fund flow, and address detail panel

The lesson is about the shape, not the inside. The mixer hides deposit-withdrawal pairs, but everything before entry and after exit remains public, and the discipline of the operator is the real variable.

Case Two: Nomad Bridge, $190M in a Free-for-All

The Nomad Bridge incident of August 2022 was a different anatomy: a configuration error let hundreds of independent copycats drain roughly 190 million dollars in a free-for-all, with no single professional laundering crew. Tornado Cash featured again as a destination, this time across dozens of independent actors with varying skill. The configuration failure behind the incident is documented in the Nomad Bridge root-cause analysis.

For forensics, the case demonstrates the mixer at population scale. Untrained actors made operational mistakes that trained crews avoid: address reuse, rushed timing, exits to traceable services. Tracing through the aftermath exploited the human layer around the cryptography, not the cryptography itself. The Li.Fi investigation is documented with a public analysis canvas, so the paths, hops, and exit points can be inspected rather than taken on faith.

The two cases side by side show what changes with operator discipline and what does not:

Dimension Li.Fi 2024 Nomad Bridge 2022 Compliance Takeaway
Loss size $11.6M $190M Mixer relevance holds across scales
Actors One disciplined crew Hundreds of independent copycats Discipline, not skill, decides traceability
Mixer use 114 transactions over 3 months, 99%+ of funds Dozens of actors, varying patterns Boundary records scale with volume
Longest path 20 hops Varies by actor Multi-hop tracing is the default requirement
What tracing kept Full structure from entry through the mixer boundary Exit-side mistakes, address reuse Entry and exit stay public evidence

How Mixer Tracing Actually Works

The method across both cases is consistent, and it generalizes. Trace to the mixer boundary and document it precisely: which addresses deposited, how much, when, in how many transactions. Then work the exits: withdrawal-side addresses get clustered, timed against deposits, and cross-referenced against exchange listings and subsequent movement. Direct deposit-withdrawal pairing stays hard inside the pool, but exits inherit behavior, fresh addresses still touch services, and services are labelable.

Finally, watch rather than guess. Stolen funds sit and move on timelines; the Li.Fi cash-out came months after the theft. Continuous monitoring of the boundary addresses, with alerting on movement, is what turns a dormant case into a traced one. Per BlockSec, MetaSleuth provides exactly this loop: multi-hop tracing with saved analysis canvases, and real-time monitoring of stolen-fund movement across chains. For the broader methodology of working mixer boundaries, see How to Trace Stolen Crypto Through a Mixer. Book a demo of Phalcon Compliance to screen counterparty addresses for mixer-linked exposure, or open MetaSleuth and trace a case yourself.

Analysis canvas for adding private labels, name tags, and memos to nodes on a tracing graph
Analysis canvas for adding private labels, name tags, and memos to nodes on a tracing graph

FAQ: Tornado Cash Tracing

Can funds sent through Tornado Cash be traced? The mixer hides direct deposit-withdrawal pairs. Everything before entry and after exit stays public, and clustering plus intelligence on the exit side routinely reassembles trails, as both documented cases show.

Is Tornado Cash still sanctioned? A federal appeals court struck down the protocol-level designation in November 2024, and OFAC formally delisted Tornado Cash in March 2025. Sanctions tied to co-founder Roman Semenov and his associated addresses remain, now under OFAC's DPRK program; screening against current lists is the operative practice.

Why do attackers still use mixers if tracing works? Mixers raise cost and delay rather than providing invisibility. The Li.Fi crew took three months of discipline and was still mapped from entry through the mixer boundary.

What should a compliance team do with mixer exposure? Screen for mixer interaction risk, treat mixer-linked exposure as elevated, and document the boundary facts. Risk engines that flag mixer labels on counterparties make this systematic.

Start Real-Time AML with Phalcon Compliance

Turn Phalcon Network alerts into actions with Phalcon Compliance. Use verified blockchain intelligence to screen wallets, monitor transactions and investigate risks. This helps you respond quickly and stay compliant in the digital assets ecosystem.

Phalcon Compliance