Federal prosecutors in Manhattan are asking for another chance to convict Tornado Cash developer Roman Storm, seeking to revive one of the most closely watched legal battles in the cryptocurrency industry. Their request, filed in the U.S. District Court for the Southern District of New York, asks the judge to schedule a retrial in early or mid-October 2026 on two criminal counts that jurors could not unanimously resolve during Storm’s first trial.
The case matters far beyond one defendant. At its core is a question that has become increasingly urgent across crypto: when does building open-source software turn into criminal exposure? Prosecutors say Tornado Cash enabled major illicit finance by obscuring the origin and destination of blockchain transactions. Storm and many of his supporters counter that the government is trying to stretch criminal law so far that publishing or maintaining decentralized code could itself become prosecutable conduct.
Storm’s first trial, which ended in August of last year, produced a split result. A Manhattan jury convicted him of conspiracy to operate an unlicensed money-transmitting business. But it deadlocked on the two most serious remaining counts: conspiracy to commit money laundering and conspiracy to violate sanctions. Those unresolved charges now form the basis of the government’s new push for another trial.
The stakes are high. If Storm were ultimately convicted on both outstanding counts, he could face as much as 40 years in federal prison. Prosecutors told Judge Katherine Polk Failla that a retrial date should be fixed now to avoid further scheduling delays, and they estimated that a new proceeding would likely last about three weeks. For now, Storm remains free on bail while the case continues.
A shifting but inconsistent policy environment in Washington
The retrial request arrives at a moment when the U.S. federal government’s public posture toward digital assets appears to be changing, but not in a fully consistent direction. Different agencies have recently used different language when discussing digital asset infrastructure, privacy tools, and the responsibilities of developers. That makes the Storm case not only a criminal proceeding, but also a practical test of how the United States may define liability across the broader crypto stack.
Last year, Deputy Attorney General Todd Blanche circulated a memo stating that the Department of Justice “is not a digital assets regulator.” That guidance told prosecutors to avoid cases that effectively impose regulatory frameworks through criminal charges against platforms, wallets, and similar infrastructure. In plain terms, the memo suggested that federal criminal law should not become a substitute for writing and enforcing financial rules.
The same memo also cautioned against targeting developers for the conduct of users interacting with decentralized tools. That point is especially important in cases involving smart contracts and permissionless protocols. Once decentralized software is deployed, developers may not control who uses it, how it is integrated, or whether third parties later use it for lawful or unlawful purposes. For many in the industry, this distinction lies at the heart of the Tornado Cash debate.
At the same time, the U.S. Treasury Department has softened its language around blockchain privacy tools. In a report to Congress submitted in March 2026 under the GENIUS Act, Treasury acknowledged that digital asset mixers can serve legitimate functions. That does not erase enforcement concerns, but it does mark a more nuanced position than treating all mixing activity as inherently suspicious or criminal.
According to that report, lawful users may rely on such privacy tools to shield sensitive financial information. Treasury specifically referenced several legitimate use cases, including:
- protecting information about personal wealth,
- keeping business payments confidential,
- preserving privacy for charitable donations, and
- preventing exposure of consumer spending patterns.
These statements matter because they complicate the simple narrative that mixers exist only to assist crime. Yet federal law enforcement continues to press the Storm case aggressively. That tension reveals the current policy contradiction in Washington: one arm of government acknowledges lawful privacy interests on public blockchains, while another still seeks to hold a developer criminally responsible for a protocol allegedly used at scale for unlawful finance.
What Tornado Cash is and why prosecutors say it matters
Roman Storm helped create Tornado Cash in 2019 as a privacy protocol for the Ethereum network. The protocol was designed to make blockchain transactions harder to trace by obscuring links between deposit and withdrawal addresses. On a fully transparent public ledger, that kind of privacy tooling can appeal to users who do not want all wallet activity to remain easily visible to anyone monitoring the chain.
One of the central defense points is structural. Unlike a custodial mixer operated by a centralized service provider, Tornado Cash functions through smart contracts rather than a single operator manually controlling user funds. That distinction is not just technical; it is legal. The defense argues that decentralized architecture limits the kind of direct operational control that regulators and prosecutors often assume in traditional financial crime cases.
Prosecutors, however, focus less on the protocol’s architecture than on its alleged real-world use. Federal authorities have argued that Tornado Cash facilitated more than $1 billion in illicit transactions. They have also linked some of that activity to the North Korean hacking group known as the Lazarus Group. In the government’s view, those facts demonstrate that the protocol became an important conduit for laundering or concealing criminal proceeds.
That is why the dispute is not merely about whether privacy has legitimate value. It is also about whether developers can escape liability simply because their system is decentralized. If a team creates or promotes a tool that they know is being used extensively for illegal transfers, how should courts assess intent, responsibility, and causation? Crypto has forced those questions into legal settings where traditional categories do not fit neatly.
For the wider industry, the importance of this case is difficult to overstate. Its outcome could influence how U.S. authorities approach not only privacy protocols, but also wallet software, front-end interfaces, smart contract deployment, and other pieces of decentralized infrastructure. A broad theory of developer liability could raise legal risk across open-source crypto development. A narrower theory could help preserve space for software builders while still leaving room to prosecute direct participation in criminal schemes.
Storm’s argument: this is about criminalizing code
Storm’s defense has consistently maintained that developers cannot control how decentralized software is used once it has been deployed. In that view, creating or publishing open-source code is not the same as directing every user action that follows. If bad actors later rely on a protocol, the defense argues, that alone should not automatically convert the original developers into criminal conspirators.
After news of the retrial request became public, Storm responded on X and emphasized what happened in the first trial. He noted that a jury of 12 Americans heard four weeks of evidence and still failed to reach a consensus on the two most serious charges. By stressing that point, Storm sought to show that the prosecution did not persuade jurors on the counts tied to money laundering and sanctions violations.
His language was direct: “A jury of 12 Americans heard four weeks of evidence and deadlocked. No verdict on money laundering. No verdict on sanctions violations.” In context, Storm was arguing that the government’s narrative is far less clear-cut than prosecutors suggest. If the evidence had been overwhelming, his supporters argue, the first jury likely would not have split so sharply.
Storm then framed the retrial effort as something larger than one case. In his words, the government’s answer is to “try again to make writing code a crime.” That phrase captures the broader concern shared by many developers, privacy advocates, and crypto legal commentators: if authorities succeed with an expansive theory here, future prosecutions may target software creation itself whenever downstream users commit wrongdoing.
Prosecutors, of course, reject that framing. Their position is not that coding itself is illegal, but that a developer can be criminally liable if he knowingly participates in a system that enables unlawful activity at scale. Because both sides define the nature of the case so differently, any retrial beginning in October 2026 would likely carry consequences well beyond Storm personally. It could shape how American courts and regulators think about open-source development, blockchain privacy, sanctions compliance, and the future legal status of decentralized infrastructure.

