In the Southern District of New York, the criminal trial of Tornado Cash co-founder Roman Storm ended with a mixed jury verdict that immediately drew attention across the crypto industry. Storm was found guilty on the second count in his indictment, conspiracy to operate an unlicensed money transmitting business. However, the jury did not reach a unanimous verdict on the other two counts: conspiracy to commit money laundering and conspiracy to violate sanctions.
The verdict came after three and a half days of jury deliberation, following a trial that began in the middle of last month. Because the jury returned a conviction on the money transmission-related charge, Storm now faces a sentence of up to five years in prison. Even so, the outcome was not a clean sweep for prosecutors. One conviction alongside two unresolved counts means the legal and policy implications of the case are far from settled.
That is one reason the case has become so important well beyond Storm himself. Tornado Cash has long sat at the center of a broader argument in crypto: when a privacy-preserving or mixing service is used by criminals, how much liability should attach to the developers or operators behind it? The case touches not only on criminal law, but also on sanctions policy, anti-money laundering enforcement, software development, and the role of privacy on public blockchains.
The jury convicted Storm on one count and deadlocked on two others
The core legal outcome is narrow but significant. Jurors agreed that Storm was guilty of conspiracy to operate an unlicensed money transmitting business. In practical terms, that means the prosecution persuaded the jury that the activities tied to Tornado Cash crossed the line, at least in this respect, from publishing or maintaining software into conduct covered by U.S. rules governing money transmission.
At the same time, the jury did not unanimously agree on the two other charges. Those counts alleged conspiracy to commit money laundering and conspiracy to violate sanctions. A deadlock is not the same as an acquittal, but it is still meaningful. It shows that the prosecution did not convince the full jury on some of the most controversial parts of its theory, especially where criminal intent, sanctions liability, and the relationship between a tool and its users were concerned.
The timeline also matters. This was not an instant or superficial result. The jury heard the case after a trial that began in the middle of the previous month, then spent three and a half days deliberating before issuing its split decision. In crypto cases, that kind of deliberation often reflects the challenge of translating technical infrastructure, on-chain behavior, and software design into traditional legal categories that jurors can understand and apply.
As things stand, Storm’s exposure on the count of conviction is up to five years in prison. That maximum does not automatically indicate the sentence he will receive, but it does show the seriousness of the charge that stuck. The fact that only one of the three counts resulted in a conviction also ensures that the appellate process, and the debate over what this case really means, will remain active for some time.
Judge Failla refused to remand Storm into custody after the verdict
Immediately after the verdict, the prosecution asked the court to remand Storm into custody, arguing that he had become a flight risk. From the government’s perspective, the logic was straightforward: once a defendant has actually been convicted of a crime, the incentive to flee can increase materially because the prospect of sentencing is now real rather than hypothetical.
Storm’s defense attorney, Ms. Klein, pushed back strongly and did so with specific facts. She argued that Storm had little reason to flee the United States, especially because his home in Washington state was tied to a $2 million bail bond. She also pointed to his personal and family connections in the country. According to the defense, Storm’s daughter, over whom he has partial custody, and his girlfriend are based in the United States, and his parents are green card holders.
The defense added a community-based argument as well. Much of the crypto community that has publicly supported Storm is based in the U.S., and the expectation is that this support would continue as he appeals the verdict. That point was intended to show not only that Storm has social ties, but also that he has a reason to remain engaged with the legal process rather than abandon it.
Prosecutors replied that conviction itself changed the incentives. In their view, once Storm was no longer merely accused but formally convicted, his motivation to escape had increased. Judge Failla was not fully persuaded. She stated that the “stability of the verdict is still in play,” a phrase widely read as a reference to the likelihood of appeals and the fact that the case remains procedurally unsettled.
She also observed that Storm’s “incentives have shifted tremendously,” which suggests she did not dismiss the government’s concerns altogether. Still, she ultimately denied the motion to remand him. The result is that Storm was not taken into custody immediately after the verdict and will continue to face the next stage of the case without being remanded at that moment.
Jay Clayton framed the case as a crackdown on criminal use of crypto infrastructure
Shortly after the verdict, SDNY U.S. Attorney Jay Clayton — also a former chair of the U.S. Securities and Exchange Commission — issued a public statement that set out the government’s broader framing of the case. Clayton said that Roman Storm and Tornado Cash provided a service for North Korean hackers and other criminals to move and hide more than $1 billion in dirty money.
His statement emphasized that stablecoins and other digital assets offer major promise in terms of speed, efficiency, and functionality. But he argued that those strengths cannot serve as an excuse for criminal conduct. In his formulation, criminals who use new technology to commit old crimes, including concealing illicit proceeds, undermine public trust and cast a shadow over lawful innovators working in the same space.
Clayton then reinforced the enforcement message by saying that his office and partner agencies are committed to holding accountable those who exploit emerging technologies to commit crimes. For the crypto sector, this was a clear signal: federal prosecutors may acknowledge the innovative potential of blockchain-based systems while still aggressively pursuing cases where they believe such systems facilitate criminal behavior at scale.
The omissions in Clayton’s statement are part of the controversy
The original report also highlights what Clayton did not mention. First, he did not acknowledge a memo from U.S. Deputy Attorney General Todd Blanche. In that memo, Blanche said the Department of Justice would “stop participating in regulation by prosecution” in the crypto space and would no longer target virtual currency mixing services for the acts of their end users. That omission matters because it raises a tension between the formal policy signal from DOJ leadership and the prosecutorial framing used in this case.
Second, Clayton did not mention that the vast majority of funds that moved through Tornado Cash were not proven to have been illicitly obtained. This point is central to the ongoing dispute over how Tornado Cash should be understood. Was it primarily a criminal laundering tool, or was it a privacy service also used by many ordinary users who wanted transaction confidentiality on-chain? The answer to that question shapes how people assess both the fairness and the future consequences of the case.
Critics of the prosecution argue that if developer liability is extended too far, open-source software authors and builders of privacy tools could face legal exposure based on what users later do with the software. Supporters of the prosecution respond that when a service is repeatedly and materially used by sanctioned actors or criminal organizations, the people behind it cannot hide behind technical neutrality forever. That clash of principles has made Tornado Cash one of the defining crypto legal battles in the United States.
Why the case matters for developer liability, privacy tools, and crypto regulation
The split verdict itself may be the clearest sign of the case’s complexity. Jurors accepted the prosecution’s theory on the unlicensed money transmitting business count, but they did not unanimously endorse the money laundering and sanctions conspiracy counts. That mixed outcome suggests that while some forms of regulatory or operational liability may have resonated, the more aggressive claims about criminal agreement and sanctions responsibility were harder to prove to the satisfaction of all jurors.
For developers and crypto infrastructure teams, that distinction is significant. It implies that the law may treat business-operation issues differently from allegations tied to user intent, downstream misconduct, or sanctions evasion. It also means future cases may focus closely on what degree of control, knowledge, facilitation, or economic involvement developers had in relation to a protocol or service.
For the industry more broadly, the case intensifies a long-running question: how can blockchain privacy tools coexist with anti-money laundering enforcement, sanctions compliance, and licensing obligations? There is no easy answer. If liability is too broad, it may chill innovation in open-source infrastructure. If it is too narrow, authorities will argue that illicit actors can exploit privacy technologies with little resistance.
In the short term, Storm’s conviction on one count already sends a strong warning signal across crypto. In the longer term, the appeals process and the way courts, regulators, and prosecutors interpret this case may shape the legal boundaries for mixers, privacy protocols, and perhaps even other decentralized services. That is why the Roman Storm verdict is not just about one defendant. It is about the future legal treatment of privacy-preserving crypto infrastructure in the United States.

