TL;DR - Privacy Pools passes exchange compliance checks that Tornado Cash cannot, because its zero-knowledge proof lets a withdrawal show it never touched a flagged deposit.
A mixer's reputation follows every coin that ever passed through it. That's the problem Tornado Cash never solved, and it's exactly what a newer Ethereum privacy protocol called Privacy Pools was built to fix. Anyone screening a wallet before an exchange deposit, a DeFi frontend connection, or an OTC trade eventually runs into an address that touched one of these two contracts. Both solve the same underlying need - moving funds privately without becoming a laundering conduit - through almost opposite mechanisms, and compliance systems treat them very differently. Understanding which is which matters more now than it did a year ago, because Tornado Cash is legal to use again in the US and Privacy Pools has real backing behind it.
What actually makes Privacy Pools different from Tornado Cash?
Tornado Cash pools deposits from every user into one shared contract and breaks the on-chain link between deposit and withdrawal completely. Nobody, including Tornado Cash itself, can tell which deposit funded which withdrawal. That's the whole point. It's also why regulators treated it as a laundering tool: a stolen-fund deposit and a clean deposit come out looking identical. For background on how mixer contracts work in general, see Plastron's mixer explainer.
Privacy Pools, built by a team called 0xBow, keeps the zero-knowledge shuffling but adds one extra step. When a user withdraws, they generate a cryptographic proof that their deposit belongs to an "association set" of deposits an approved provider has screened as clean, without revealing which specific deposit is theirs. The privacy holds. But the withdrawal now carries mathematical evidence it didn't come from a sanctioned or stolen-fund deposit sitting in the same pool.
Tornado Cash withdrawals carry no proof of origin; Privacy Pools inserts a zero-knowledge check that a withdrawal belongs to a screened, clean association set before funds move.
Tornado Cash's sanctions history didn't go away quietly
OFAC added Tornado Cash's smart contract addresses to the SDN list on August 8, 2022, saying the protocol had laundered more than $7 billion in virtual currency since 2019, including over $455 million stolen by North Korea's Lazarus Group. It was the first time the US government sanctioned a piece of immutable code rather than a person or entity, and it triggered a legal fight that ran for two years. In November 2024, the Fifth Circuit ruled in Van Loon v. Treasury that OFAC had exceeded its authority sanctioning software nobody controls, and by March 2025 the agency formally removed Tornado Cash from the SDN list. Plastron covered what that delisting actually changes for a flagged wallet in a dedicated breakdown - the short version is that delisting removed the sanctions violation, not the risk flag most screening tools still apply to mixer interaction.
Checking whether a specific address ever touched Tornado Cash usually means pulling its full history on a block explorer like Etherscan and scanning every counterparty by hand, one transaction at a time. Screen a wallet with Plastron instead and mixer exposure, along with sanctions and stolen-funds links across seven chains, comes back in one pass.
How does Privacy Pools try to stay compliant by design?
The association-set-provider model traces back to a 2023 research paper co-authored by Ethereum co-founder Vitalik Buterin, proposing a way to keep transaction privacy while still letting users prove their funds are not tainted. 0xBow built that idea into a live protocol and launched it on Ethereum mainnet in March 2025. As of its most recent public figures, Privacy Pools has processed about $6 million in volume across more than 1,500 users - a fraction of the billions Tornado Cash moved at its peak, but the direction of adoption is what matters here.
That adoption picked up once the Ethereum Foundation integrated Privacy Pools into its Kohaku wallet, and 0xBow closed a $3.5 million seed round led by Starbloom Capital in November 2025 on the back of it. None of this makes Privacy Pools immune to scrutiny. Compliance teams still have to trust whoever curates the association set. A young pool with a few thousand users offers a thinner crowd to hide inside than a protocol that ran unopposed for five years.
Two years separate Tornado Cash's sanctions listing from its delisting - the same month Privacy Pools launched on mainnet with a compliance-first design.
There's also a gap most people miss: not every compliance vendor reads an association-set proof the same way, or reads it at all. Chainalysis, Elliptic, and other screening providers built their mixer-detection rules around Tornado Cash's flat anonymity set years before Privacy Pools existed, and a proof of clean association isn't the same thing as a green flag in every one of those systems yet. A wallet can do everything right on the Privacy Pools side and still get a manual review at deposit, simply because the exchange's risk engine hasn't caught up to what the proof means.
Head-to-head
Put the two side by side and the practical differences come down to compliance mechanism, track record, and what a screening tool actually does when it sees the interaction.
Criterion
Tornado Cash
Privacy Pools
Sanctions status
Sanctioned Aug 2022, delisted Mar 2025
Never sanctioned
Compliance mechanism
None - full anonymity, no proof of fund origin
Zero-knowledge proof of membership in a screened association set
Age and pool depth
Live since 2019, billions in historical volume
Live since March 2025, about $6M across 1,500+ users
Backing
No formal company or funding round
0xBow, $3.5M seed round (Nov 2025)
Ecosystem integration
Blocked by most major DeFi frontends
Integrated into Ethereum Foundation's Kohaku wallet
How a screening tool treats it
Flagged as mixer exposure regardless of sanctions status
Still flagged as a privacy-pool interaction; proof of clean association set is not visible to every screening tool
Verdict
For anyone whose main goal is passing an exchange's deposit screen without a manual review, Privacy Pools is the better technical answer. It's the only one of the two that can produce a proof of non-association on demand, and that's a real advance, not marketing.
But for someone who needs the largest possible anonymity set for a large transfer, Tornado Cash's five-year, multi-billion-dollar liquidity pool still buries a transaction deeper than Privacy Pools' few-thousand-user pool can. And using it again isn't a US federal crime the way it was between August 2022 and March 2025, though most exchanges still treat any mixer contract interaction as an automatic risk flag regardless of its current legal status. If a wallet has touched either contract, the safest move is running a full wallet risk score check before depositing anywhere - the exposure sits on the address whether or not the protocol it came from currently carries a sanctions designation.
An individual moving a few hundred dollars between two wallets they own is not the same case as an OTC desk about to accept a six-figure transfer from a new counterparty. The desk has more to lose from a frozen deposit and less tolerance for a thin anonymity set that draws extra scrutiny on its own, so a documented Privacy Pools proof is worth more to it than raw crowd size. The individual, with less at stake per transaction, usually cares more about not paying attention to any of this at all - which is exactly the wallet history that a screening check catches before an exchange does.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.