TL;DR - Railgun screens shielded funds against a public OFAC list before letting them move, but wallet-screening tools still treat any address that touched its shield contract as elevated risk, the same as Tornado Cash.
Railgun's own documentation focuses on the zero-knowledge math behind shielding tokens. It says almost nothing about what happens after: what a wallet-screening report does when it sees your address touch a Railgun shield contract. Those are two separate questions: is the protocol compliant, and does using it get your wallet flagged. Most of the public debate blurs them together.
What Railgun Actually Does
Railgun is a smart-contract privacy layer built on top of Ethereum and a handful of other EVM chains, not a separate blockchain of its own. A wallet shields ERC-20 tokens into a zero-knowledge pool, transacts privately inside that pool, then unshields back out to a normal address whenever it wants funds visible again. By April 2024, cumulative volume through the protocol was closing in on $1 billion, according to Cointelegraph's reporting on Railgun's own usage data at the time.
Since January 2023, Railgun has run a screening layer called Private Proofs of Innocence. Before a wallet can shield funds, it generates a zero-knowledge proof that its tokens aren't tied to a blocklist, by default the OFAC-designated address list. The proof clears without exposing the wallet's balance or history to anyone outside the transaction.
The screening happens inside the protocol, invisibly, before the money ever moves.
Railgun also keeps a compliance escape hatch: any user can generate a read-only viewing key and hand it to a regulator, an auditor, or an exchange, exposing every shielded transaction tied to that key without giving up control of the funds. Nobody is required to use it. The wallet decides whether the key ever leaves the wallet.
Six dated events connect the Harmony Bridge hack, Railgun's laundering allegation, and Tornado Cash's sanctions history from 2022 to 2025.
Does Railgun Screen Transactions Before Shielding Funds?
Yes, but only against one list, and only where a relayer or wallet app chooses to enforce it. Private Proofs of Innocence checks incoming funds against the default OFAC list. Railgun's base contracts don't force this check for every path into the pool. Some relayers require a valid proof before processing a transaction, and others don't.
That's a narrower net than most compliance teams assume. A wallet can find a relayer that skips the proof entirely and still get funds shielded.
The Lazarus Group Allegation and What Happened After
On June 24, 2022, hackers drained roughly $100 million from Harmony's Horizon Bridge. The FBI confirmed on January 23, 2023 that Lazarus Group and APT38, both tied to North Korea, carried out the theft. Ten days earlier, on January 13, 2023, the same actors had already routed more than $60 million of the stolen ether through Railgun in an attempt to launder it.
Some of that ether was frozen in coordination with exchanges before it reached a cash-out point. Railgun disputed the framing in April 2024, calling the original report a mistaken allegation and pointing out that Private Proofs of Innocence, which had gone live in that same window, would have blocked a flagged actor from shielding funds at all.
Whichever account you believe, the timeline is tight enough to explain why Railgun still carries the association three years later.
Why Do Wallet-Screening Tools Still Flag Railgun Interactions?
Because Private Proofs of Innocence screens one narrow list, and a wallet-screening report's job is to catch everything that list misses. The report doesn't check whether Railgun's internal proof passed. It checks whether the wallet touched a known privacy-protocol contract at all, the same logic applied to Tornado Cash, Wasabi, or any CoinJoin implementation. Interaction with a shielding or mixing contract raises a risk score regardless of what compliance tooling the protocol wrapped around it.
Plastron's own screening corpus carries 28 labeled mixer and privacy-protocol addresses out of roughly 3,901 tracked wallets, cross-checked against 780 OFAC SDN-listed entries. A Railgun shield or unshield transaction sits in that same bucket: not sanctioned outright, but flagged as privacy-tool exposure that widens the overall risk picture.
Exchanges don't see Railgun's internal proof either way. A compliance analyst reviewing a deposit sees a wallet that interacted with a contract labeled "privacy protocol" and nothing about whether Private Proofs of Innocence cleared it. Most exchanges apply the same enhanced-review trigger to any privacy-tool contact, then ask for a source-of-funds explanation before releasing a hold. That's a manual process on their end, and it can add days to a withdrawal.
How Does Railgun's OFAC History Compare to Tornado Cash's?
Tornado Cash was sanctioned outright. Railgun never has been. OFAC added Tornado Cash's smart contracts to the SDN list in August 2022, making US persons' use of the mixer itself a sanctions violation. That held until the Fifth Circuit ruled on November 26, 2024 that immutable smart contracts aren't the property of a foreign national, so OFAC had overstepped its authority. Treasury delisted Tornado Cash on March 21, 2025.
Railgun avoided that fight entirely by shipping Private Proofs of Innocence before any sanction ever landed on it. But delisting didn't erase Tornado Cash's transaction history, and screening tools still flag wallets that used it before 2025. A clean sanctions record doesn't buy Railgun a clean bill from a screening report. It buys a different set of open questions.
Neither protocol is illegal to use in most jurisdictions. Sanctions law and screening policy are different things. OFAC's SDN list determines what US persons are legally barred from transacting with. An exchange's risk engine decides what it will hold, flag, or ask questions about, and it sets that bar wherever it wants, sanctioned or not.
Railgun was never OFAC-sanctioned and screens deposits against a blocklist, but wallet-screening tools still flag interactions with it in the same risk category as Tornado Cash.
What to Do If Your Wallet Touched Railgun
Check the transaction hash first. A single shield or unshield through Railgun does not tie you to Lazarus Group or any sanctioned entity by itself. The 2023 laundering moved through relayers your wallet almost certainly never touched. But it will show up as elevated risk on any report that checks privacy-protocol exposure, and most exchange compliance teams now run that check before releasing a large withdrawal.
Screen the wallet before you send it anywhere, not after support puts a hold on it. Etherscan will show the raw shield and unshield calls on a transaction, but it won't calculate exposure or check the destination against sanctions lists on its own. Screen your wallet with Plastron instead, and it checks mixer exposure, OFAC hits, and cross-chain history in one pass, for free.
A one-hop interaction with a screened privacy pool is not the same risk as ten hops from a sanctioned mixer. Treat it that way, and most flags resolve with an explanation, not a freeze.
Keep the paper trail ready before you need it. Save the shield and unshield transaction hashes, the approximate date, and the amount moved, then attach that to any source-of-funds request instead of waiting for the exchange to ask twice. A compliance analyst working through a queue of holds moves faster on a wallet that already explains itself than one that goes quiet after the first request.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.