Tornado Cash · interactive mechanism simulation

Depositors lock a fixed denomination and add a secret commitment to an on-chain Merkle tree. Later, a withdrawer proves — via zkSNARK, without revealing which leaf — that they know a secret behind some commitment, and a relayer submits the withdrawal to a fresh address. The bigger the unspent commitment set, the stronger the anonymity.
Depositors lock fixed amount Pool contract 0.1 ETH pool · Merkle tree (depth 20) anonymity set: 0 commitments nullifiers spent: 0 Withdrawers secret + nullifier, zk proof Relayer network submits tx, takes fee Fresh address no on-chain link to depositor OFAC sanctions inactive — core pool immutable
Deposits (commitments)
0
Anonymity set
0
Withdrawals (nullifiers spent)
0
Relayer fees earned
0.0 ETH
Parameters — edit me
1 ETH
1.2/s
0.8/s
1.0%
80
Controls

Illustrative simulation. Reflects the researched mechanism (fixed-denomination pools, commitment/nullifier Merkle tree, zkSNARK withdrawal proofs, relayer fees, anonymity mining), but trade sizes and timing are randomized for visualization — not live onchain data. The "trigger sanctions" button models the Aug 2022 OFAC action: it froze relayers and front-ends and cut usage ~90%+, but per the Fifth Circuit's Van Loon ruling, the immutable core pool contracts kept running regardless. Drag the sliders to explore the anonymity-set dynamics. Part of The Onchain Experiment Atlas.