If your goal is financial privacy without evading sanctions or KYC/AML controls, the safest approach is to treat privacy as a data-minimization problem—not as a way to conceal counterparties, source of funds, or jurisdiction.
One important current-law point: Tornado Cash was removed from OFAC's SDN list in March 2025, so older advice saying that interacting with Tornado Cash itself is categorically prohibited under the U.S. sanctions listing is outdated. U.S. Department of the Treasury OFAC That does not mean every transaction involving a mixer or privacy protocol is automatically compliant: other sanctioned addresses, persons, jurisdictions, and transaction circumstances can still create sanctions exposure. OFAC continues to maintain and update its sanctions lists.
A conservative operating model
- Prefer privacy tools that don't function as opaque custodial mixers. Non-custodial privacy mechanisms, selective-disclosure systems, shielded transactions, and zero-knowledge applications can provide privacy while allowing you to retain control of your assets and potentially prove facts about a transaction when required.
- Don't use privacy technology to defeat an exchange's KYC/AML requirements. If an exchange requires identity verification, geographic restrictions, source-of-funds information, or blockchain-history information, comply rather than routing around those controls.
- Screen counterparties and addresses. Before interacting with a privacy protocol, bridge, relayer, DEX, or other service, check whether the relevant organization, people, domains, and known wallet addresses appear on applicable sanctions lists. OFAC provides an official sanctions-search tool.
- Avoid funds with unexplained provenance. Privacy should protect legitimate financial information, not make suspicious incoming funds harder to investigate. Keep records showing where your own funds came from and why transactions occurred.
- Don't circumvent geographic controls. Using VPNs, proxy infrastructure, or alternative RPC endpoints specifically to defeat a provider's sanctions/geolocation restrictions can create additional compliance risk. OFAC has specifically discussed IP/geolocation controls in the virtual-currency context.
- Keep an audit trail privately. You can use privacy-preserving wallets while retaining transaction hashes, acquisition records, exchange statements, tax records, and explanations of transfers in your own encrypted records. This gives you a way to substantiate legitimate activity later without publishing all your financial activity on-chain.
- Separate privacy from anonymity. A useful design is: public blockchain + minimized unnecessary disclosure + ability to prove ownership/source when legitimately requested. That's considerably safer than seeking an architecture where nobody can establish the origin or destination of funds.
- Be especially cautious with mixers. FinCEN has historically treated businesses that accept and retransmit convertible virtual currency for anonymization as potentially subject to money-transmitter/BSA obligations, and has taken enforcement action against mixer operators.
A practical rule of thumb
Before using a privacy-preserving protocol, ask:
“If my exchange, bank, tax authority, or lawyer asked me tomorrow to explain this transaction, could I demonstrate that the funds are mine, identify their legitimate source, and explain the transaction without relying on the privacy tool to conceal that information?”
If yes, you're generally approaching privacy from the safer direction. If the principal purpose of the setup is “make it impossible for a compliant intermediary or authority to determine where these funds came from,” that's a strong signal to stop and obtain legal advice rather than proceeding.
Because sanctions and AML rules vary by jurisdiction and change over time, a U.S. user should check the current OFAC rules and FinCEN requirements before a material transaction; users elsewhere need to check their own country's regime as well. This isn't individualized legal advice.