# Introduction to Tornado Cash

Tornado Cash is a decentralized protocol for anonymous transactions on Ethereum and Binance Smart Chain, ensuring privacy with zk-SNARK technology

<div data-full-width="false"><figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FnqSTRZB5u10LuFn5zZeB%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-abd4d34155f9622c45ddda2c15d655a546b08610_image.png?alt=media&#x26;token=e14ebc01-4085-4b56-a287-3511c497fa56" alt=""><figcaption><p>TORNADO CASH</p></figcaption></figure></div>

[Tornado Cash](https://tornadoeth.cash) is a **fully decentralized** **non-custodial** **protocol** allowing private transactions in the crypto-space.As a decentralized protocol, Tornado.Cash smart contracts have been implemented within the Ethereum blockchain, making them immutable. They can neither be changed nor tampered with. Therefore, nobody - including the original developers - can modify or shut them down. All governance and mining smart contracts are deployed by the community in a decentralized manner.As a non-custodial protocol, users keep custody of their cryptocurrencies while operating Tornado.Cash. This means that at each deposit, they are provided with the private key enabling the access to the deposited funds, which gives users complete control over their assets.&#x20;

## How is privacy achieved? <a href="#how-is-privacy-achieved" id="how-is-privacy-achieved"></a>

Tornado Cash improves transaction privacy by breaking the on-chain link between source and destination addresses. It uses a smart contract that accepts ETH & other tokens deposits from one address and enables their withdrawal from a different address.To maximize privacy, several steps are recommended, such as the use of a relayer for gas payments to withdraw funds from an address with no pre-existing balance.More details are available in *Behind the scenes:* [*How does Tornado.Cash work?*](/generals/how-does-tornado-cash-work) & [Tips to remain anonymous](/generals/tips-to-remain-anonymous).

## Where does Tornado.cash operate? <a href="#where-does-tornado.cash-operate" id="where-does-tornado.cash-operate"></a>

Since its inception in 2019, Tornado Cash has been operating **on the Ethereum blockchain**. The protocol has been offering diversified fixed amount pools for six tokens (ETH, DAI, cDAI, USDC, USDT & WBTC) handled by the Ethereum blockchain.Since June 2021, in addition to the Ethereum blockchain, Tornado Cash smart contracts **have also been deployed on other side-chains & blockchains**. These deployments enabled the tool to either support new tokens or benefit from Layer-2 advantages, such as faster and cheaper transactions.As of today, Tornado Cash is operating on:

* **Ethereum Blockchain** : **ETH** (Ethereum),&#x20;
* **DAI** (Dai),&#x20;
* **cDAI** (Compound Dai),&#x20;
* **USDC** (USD Coin),&#x20;
* **USDT** (Tether) & **WBTC** (Wrapped Bitcoin),
* **Binance Smart Chain**: **BNB** (Binance Coin),
* **Polygon Network**: **MATIC** (Polygon),
* **Gnosis Chain (former xDAI Chain)**: **xDAI** (xDai),
* **Avalanche Mainnet**: **AVAX** (Avalanche),
* **Optimism**, as a Layer-2 for **ETH** (Ethereum),
* **Arbitrum One**, as a Layer-2 **ETH** (Ethereum).

Until December 2021, the protocol included an anonymity mining system for some of these tokens, allowing its users to earn a governance token ([**TORN**](/generals/torn)). Users were able to ultimately earn TORN on the Blockchain network by depositing in the ETH, DAI, cDAI & WBTC pools.*More information on* [*Anonymity mining*](/tornado-cash-classic/anonymity-mining) *&* [*Tornado.Cash token*](/generals/torn) is *available.***Thanks to the TORN token, Tornado Cash users can actively participate in shaping the protocol**. \
\
The community has a strong weight regarding the evolution of Tornado Cash and the improvement of its features. Indeed, protocol parameters & token distribution are completely under the community’s control through this governance.All pools mentioned above can be accessed on [tornadoeth.cash](https://tornadoeth.cash/). \
\
They operate **under the principle of fixed-amount deposits & withdrawals**. It means that each token has 2 to 4 different pools, allowing transactions of only 2 to 4 different fixed amounts *(e.g. ETH has four different pools, one for each of these amounts: 0.1, 1, 10 & 100 ETH)*.

<div><figure><img src="https://tornadocash.gitbook.io/docs/generals/introduction-to-tornado-cash" alt=""><figcaption></figcaption></figure> <figure><picture><source srcset="/files/dNIALYneZT2vhlrzkb05" media="(prefers-color-scheme: dark)"><img src="/files/A5h72GNeM1cbJWsu6xw6" alt=""></picture><figcaption><p>BLOCKCHAIN</p></figcaption></figure></div>

### Tornado Cash [Nova](/tornado-cash-nova/logging-in-tornado-cash-nova) <a href="#tornado-cash-nova" id="tornado-cash-nova"></a>

With the [**release of Tornado Cash Nova** (beta version) on December 2021](https://tornado-cash.medium.com/tornado-cash-introduces-arbitrary-amounts-shielded-transfers-8df92d93c37c), an **upgraded pool with unique new features** has been added to the protocol. Users are no longer constrained by fixed-amount transactions. With the addition of Tornado Cash Nova, they can benefit from the use of **an arbitrary amount pool & shielded transfers**.Tornado Cash Nova operates on the Gnosis Chain (former xDai Chain) as a Layer2 to optimize speed and cost. It allows **deposits and withdrawals of completely customized amounts in ETH**. This pool also enables shielded transactions where users can **transfer the custody of their token while remaining in the pool**.\
Tornado Cash Nova (beta version) can be accessed on [nova.tornadoeth.cash](https://nova.tornadoeth.cash). You can find further informations related to the functioning of Tornado Cash Nova in the dedicated section of our docs.

## How does Tornado.Cash run? <a href="#how-does-tornado.cash-run" id="how-does-tornado.cash-run"></a>

​[Codes behind Tornado.Cash functioning](https://github.com/tornadocashdev) - smart contacts, circuits & toolchain - are fully **open-sourced.** Working as a DAO (Decentralized Autonomous Organization), Tornado.Cash governance and mining smart contracts are deployed by its community.The protocol also functions with zk-SNARK, which enables zero-knowledge proofs allowing users to demonstrate possession of information without needing to reveal it. The use of this technology is based **on open-source research made by Zcash team with the help of the Ethereum community**. To set up zk-SNARK initial keys, Tornado.Cash [Trusted Setup Community](https://tornado-cash.medium.com/tornado-cash-trusted-setup-ceremony-b846e1e00be1) was launched in May 2020 & accounts [for 1114 contributions](https://tornado-cash.medium.com/the-biggest-trusted-setup-ceremony-in-the-world-3c6ab9c8fffa). This significant number of contributors makes it impossible to compromise the protocol by faking zero-knowledge proofs.User interface is hosted on **IPFS** (InterPlanetary File System) by the community, minimizing risks of data deletion. Indeed, the interface will work as long as at least one user is hosting it.


# How does Tornado Cash work?

Before diving into the tutorials explaining & easing the use of Tornado.Cash, here is an overall overview of the protocol's global functioning.

<figure><img src="/files/qiLOk55x8Lxa139IhcEP" alt="How does tornado cash work"><figcaption></figcaption></figure>

#### Global overview of Tornado.Cash functioning

To achieve privacy, [Tornado.Cash](https://tornadoeth.cash) **uses smart contracts that accept token deposits from one address and enable their withdrawal from a different address**. Those smart contracts work as pools that mix all deposited assets.Once the funds are withdrawn by a complete new address from those pools, the on-chain link between the source & the destination is broken. The withdrawn crypto-assets are therefore anonymized.While tokens are in a Tornado Cash pool, the custody remains in users’ hands. Users, therefore, have complete control over their tokens.**For traditional Tornado Cash fixed-amount pools**:

* When a user puts funds into a pool (a.k.a. the deposit), a private note is generated. This private note works as a private key for the user to access those funds later. To withdraw them, the same user can use a different address - an old or a new one - and recover his/her funds thanks to this private key.

**For Tornado Cash Nova, the new ETH pool with arbitrary amounts & shielded transfers**:

* Funds are directly linked to a given wallet address. There is no private note or key. Users can access their funds by connecting to the pool with the appropriate address.
* Custody is either acquired by the act of depositing tokens into the pool or by registering in the pool & receiving shielded transfers from another address.

The strength of such protocol is linked directly to its number of users and the size of its pool. The more users deposit into the pool the merrier. However, to preserve privacy & anonymity, the user must keep in mind some basic rules, such as:

* Using a relayer to pay gas at withdrawal;
* Allowing time to lapse between the deposit & the withdrawal action;
* Mixing its funds with the crowd by waiting for several transactions before recovering its assets.

*More recommendations are provided in:* [*Tips to remain anonymous*](/generals/tips-to-remain-anonymous)*.*

#### Contribution of zk-SNARK & hashing process

Tornado.Cash uses Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (also called zk-SNARK) to verify & allow transactions.To process a deposit, Tornado.Cash generates a random area of bytes, computes it through the [Pedersen Hash](https://iden3-docs.readthedocs.io/en/latest/iden3_repos/research/publications/zkproof-standards-workshop-2/pedersen-hash/pedersen.html) (as it is friendlier with zk-SNARKs), then sends the token & the 20 MiMC hash to the smart contract. The contract will then insert it into the Merkle tree.To process a withdrawal, the same area of bytes is split into two separate parts: the **secret** on one side & the **nullifier** on the other side. The nullifier is hashed. This nullifier is a public input that is sent on-chain to be checked with the smart contract & the Merkle tree data. It avoids double-spending for instance.Thanks to zk-SNARK, it is possible to prove the 20 MiMC hash of the initial commitment and of the nullifier without revealing any information. Even if the nullifier is public, privacy is sustained as there is no way to link the hashed nullifier to the initial commitment. Besides, even if the information about the transaction is present in the Merkle root, the information about the exact Merkle path, and subsequently the location of the transaction, is still kept private.Deposits are simple from a technical point of view, but expensive in terms of gas as they need to compute the 20 MiMC hash & update the Merkle tree. On the other hand, the withdrawal process is complex but cheaper as gas is only needed for the nullifier hash and the zero-knowledge proof.


# Tips to remain anonymous

Learn practical tips to maintain anonymity when using Tornado Cash, including how to protect your privacy and avoid common mistakes. Essential for safeguarding your identity in decentralized finance

Tips to remain anonymous The Tornado Cash tool allows you to remain anonymous on-chain. However, if the tool is used without protecting oneself upstream and downstream, there is no point and the anonymity would only be partial. There are practices to avoid this.

### Use TOR and/or a VPN <a href="#use-tor-and-or-a-vpn" id="use-tor-and-or-a-vpn"></a>

Your internet service provider (ISP) identifies you with an IP address. To prevent third parties from knowing that you are using Tornado.cash, you should consider [using TOR](/generals/how-to-use-tornado-cash-with-tor) and/or a VPN for your transfers. Avoid using free VPNs, they tend to keep or even sell your data. There are several VPNs on the market boasting a "no-log policy".

### Save your note in a safe place <a href="#save-your-note-in-a-safe-place" id="save-your-note-in-a-safe-place"></a>

Your note provides a record of your original transaction. Anyone who has it can withdraw the funds deposited, but also know the deposit address. Be sure to keep this note away from prying eyes and store it in a secure environment.

### Delete data <a href="#delete-data" id="delete-data"></a>

Your browser is a real source of information for the extensions you use. Delete your data after each deposit or withdrawal. If two transfers are made with the same cookies, the extension you are using will be able to link these two transactions.

### Be patient <a href="#be-patient" id="be-patient"></a>

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FYCwUZyEDah0tC5Jtk9Hr%2Fozxj.png?alt=media&#x26;token=8ff24e80-3c8f-4b7e-99a4-ee1acef0be23" alt=""><figcaption><p>DEPOSIT</p></figcaption></figure>

Your anonymity also depends on the number of transactions after your deposit (cf. Statistics tab above). If you withdraw your funds immediately after depositing them, it is possible to link your deposit to your transfer using correlation probabilities. The longer you wait, the greater your anonymity set will be.

### Use multiple addresses <a href="#use-multiple-addresses" id="use-multiple-addresses"></a>

A 7 x 10eth deposit from one address and a 7 x 10eth withdrawal to a single address can also be linked. Remember to multiply your withdrawal addresses.

​


# How to use Tornado Cash with TOR

Learn how to use Tornado Cash with Tor for enhanced privacy and anonymity in your transactions

On-chain confidentiality is ensured by the [Tornado Cash](https://tornadoeth.cash) tool.However, before and after your transactions are executed, your privacy may not be ensured. That's why we advise you to use TOR when you use Tornado Cash.Here is a quick and easy tutorial to ensure your anonymity.

### Step **#1 - Install** TOR <a href="#step-1-install-tor" id="step-1-install-tor"></a>

First, go there: <https://www.torproject.org/download/>​ Choose the appropriate operator system and click on Download.Then, run it.

### Step **#2 - Configure** TOR <a href="#step-2-configure-tor" id="step-2-configure-tor"></a>

First, search for `about:config` on your URL navigation bar.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F02TpCn9NcLmrBrkW7d0u%2Faboutconfig2.png?alt=media&#x26;token=87b3e88e-6ca1-4835-8f2a-7f82f664cea9" alt=""><figcaption></figcaption></figure>

Search for `wasm` and turn `javascript.options.wasm` on true.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FfAwiETxEqbDJeyWamqME%2Fwasm.png?alt=media&#x26;token=75ef1e67-f229-4704-8056-73683a4bebe5" alt=""><figcaption></figcaption></figure>

Search for `indexedDB` and turn `dom.indexedDB.logging.details` and `dom.indexedDB.logging.enabled` on true

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F6okPjnyr2LQol1xy7uYx%2Findexeddb.png?alt=media&#x26;token=b709f39b-147b-444c-89dc-5adf6672ab86" alt=""><figcaption></figcaption></figure>

### Step **#3 -** Install Metamask <a href="#step-3-install-metamask" id="step-3-install-metamask"></a>

Go there: <https://metamask.io/>

First, click on `Install Metamask for Firefox`.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F9XW6t3XxikpYeIQtTjSW%2Fmetamaskhome.png?alt=media&#x26;token=8690a21e-6b36-4f4c-a3d7-53bfd0e05469" alt=""><figcaption><p>METAMASK</p></figcaption></figure>

Click on `Add`.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FXvHr96hUnuz3qRHKnm70%2Faddmetamask.png?alt=media&#x26;token=1e7b9edb-3dbd-4bca-8017-69bf20e5e007" alt=""><figcaption></figcaption></figure>

Allow addons.mozilla.org to install an add-on by clicking on `Continue to Installation`.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2Fqr3H4NCCsWJlyaTuLM1A%2Fdownloadinstall.png?alt=media&#x26;token=08d55058-9333-4537-8f59-405e47a98562" alt=""><figcaption></figcaption></figure>

Confirm that you allow this extention to run in Private Windows, then click on `Okay`.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FyDboDiIdPt4xtjeDhkMb%2Fallowprivateclickokay.png?alt=media&#x26;token=ab4503f1-e0a7-49be-963d-2481f24d04b5" alt=""><figcaption></figcaption></figure>

Then, you can add Metamask to your toolbar, by doing a right click on it and dragging Metamask icon to your toolbar.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FlXqzMCMUJOZW8KgumogJ%2Fmetamaskicon(1).gif?alt=media&#x26;token=3b605bd9-6922-4334-8b02-7fdc01580127" alt=""><figcaption></figcaption></figure>

### Step **#4 - Enjoy your privacy**😎\*\*\*\* <a href="#step-4-enjoy-your-privacy" id="step-4-enjoy-your-privacy"></a>

You can now use [Tornado Cash Classic](https://tornadoeth.cash) or [Tornado Cash Nova](https://nova.tornadoeth.cash) with TOR.


# TORN

Learn about TORN, the governance token of Tornado Cash, which enables decentralized decision-making and ensures the protocol remains secure, private, and censorship-resistant

## Token <a href="#token" id="token"></a>

TORN is an ERC20-compatible token with a fixed supply that governs [Tornado.Cash](https://tornadoeth.cash). TORN holders can make proposals and vote to change the protocol via governance.**TORN is not a fundraising device or investment opportunity.Here’s how the initial distribution of TORN would break down:**

* **5% (500,000 TORN):** Airdrop to early users of Tornado Cash ETH pools
* **10% (1,000,000 TORN):** Anonymity mining for Tornado Cash ETH pools, distributed linearly over 1 year
* **55% (5,500,000 TORN):** DAO treasury, will be unlocked linearly over 5 years with 3 month cliff
* **30% (3,000,000 TORN):** Founding developers and early supporters, will be unlocked linearly over 3 years with 1 year cliff
*

```
<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FI6zLsSGfusdeoLSpqPQQ%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-7de58389d8e9121a83513feab63a38244902a55b_1_BjggJu1rN4_QOXgcLJFNEQ.png?alt=media&#x26;token=ef48ca5d-b3c8-41b9-9bce-1ff01ab621e7" alt=""><figcaption></figcaption></figure>
```

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FaxPRJm1VPxN5sjc8XAGw%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-93cd07beeeb3ec603fce1d2cda0dfe700ded0763_1_gmC0Jw8zr5xFvRK5zyQMyA.png?alt=media&#x26;token=91ff7fe9-5110-43a0-865e-ba4c3c543acb" alt=""><figcaption></figcaption></figure>

## Airdrop <a href="#f04d" id="f04d"></a>

Users who have believed in TornadoCash from early on should have a say in governing the protocol. For this reason, early adopters of the protocol did receive an airdrop of TORN.&#x20;

TORN has been airdropped to [all addresses](https://github.com/tornadocash/airdrop/blob/master/airdrop.csv) that made deposits into [tornadoeth.cash](https://tornadoeth.cash) ETH pools before block `11400000`. TORN were airdropped in the form of a non-transferable TORN voucher (vTORN) that can be redeemed 1:1 to TORN within 1 year, from December 18, 2020, to December 18, 2021. TORN that aren’t redeemed will be swept into the governance contract after 1 year and become part of the DAO Treasury. Redeemed TORN will be available immediately.The airdropped amount depends on users’ deposit size and age — larger deposits and older deposits will receive more TORN. Multipliers for deposit size are logarithmic:

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F4NIYs7OUi6KREBNnuWlY%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-3f5a349c1b8e82cc6dc888275e556dfb0e5b7e37_1_OgFrAd8p3GEZ14ZH4JnDiQ%402x.png?alt=media&#x26;token=30bc4727-ed44-4c7b-a69b-3b6c24772c30" alt=""><figcaption></figcaption></figure>

So a 100 ETH deposit get twice as many tokens as a 1 ETH deposit. The multiplier allows large and small users of tornadoeth.cash to both have a say in governance.The exact curve for the time multiplier looks like this:

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FnsfbdAKyX0lixznqoXsv%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-3f16fbf976cecfbe4f4b509b974d8d21b108d92e_1_bjE88NLnkBe29-Zcs5AGkw%402x.png?alt=media&#x26;token=6b065836-95a5-4dce-ac8f-e89a04961b8a" alt=""><figcaption></figcaption></figure>

The exact airdrop formula is the following:

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F3Hi4B1ywdE811cKpVHXy%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-9142ba0925432305806aa132dd754390e1498ced_1_mEGM4aMqrrKx0QXVa9IsKA%402x.png?alt=media&#x26;token=f8d24aa1-2700-4db6-9c41-471d23d63943" alt=""><figcaption></figcaption></figure>


# Governance

Explore Tornado Cash governance: key proposals, community decisions, and how you can participate in shaping the future of decentralized finance

### How to suggest a proposal ? <a href="#how-to-suggest-a-proposal" id="how-to-suggest-a-proposal"></a>

In order to participate in Tornado.Cash governance, users first need to lock tokens in the governance contract. If a user votes or creates a proposal, the tokens cannot be unlocked before the proposal execution period ends (8.25 days from proposal creation). The locked tokens can also be delegated to another address.To create a proposal, a user needs to have at least `1,000 TORN`.&#x20;

All proposals must be smart contracts with verified code that are executed from the [governance contract](https://etherscan.io/address/0x5efda50f22d34F262c29268506C5Fa42cB56A1Ce) (using `delegatecall`). This way, it’s easy to audit and test any governance changes.The voting period for a proposal is 5 days. A proposal will succeed if it receives a simple majority of votes and there are at least `25,000 TORN` total votes (if turnout is too low, the proposal automatically fails).After a proposal succeeds, it is subject for a timelock of 2 days. After the timelock, any user is able to execute the proposal (which initiates the changes). If proposal is not executed for 3 days after that, it is considered *expired* and can no longer be executed.All of these initial parameters are relatively small, since there won’t be many TORN tokens in circulation early on. But as the circulating supply increases, governance may adjust these thresholds.A proposal can be of the following nature:

* Adding a new Tornado Cash pool in the proxy
* Changing the AP reward rates parameters
* Unpause/Pause the TORN token
* Change some core mining contracts such as the `TornadoTrees` contract
* A combination of all of the above

<figure><img src="https://miro.medium.com/v2/resize:fit:1400/format:webp/1*Ana1sjgUbvscgYJZRDQD2g.png" alt=""><figcaption></figcaption></figure>

And many more can be done. To find out exactly what can be changed through governance in the protocol, look for the functions with the modifier `onlyGovernance` in the smart contracts.The governance functions are represented by a red arrow in [this architecture diagram](https://viewer.diagrams.net/?highlight=0000ff\&edit=_blank\&layers=1\&nav=1\&title=tornado-cash-contract-overview.drawio#Uhttps%3A%2F%2Fraw.githubusercontent.com%2FRezan-vm%2Ftornado-cash-edu%2Fmain%2Ftornado-cash-contract-overview.drawio).​

NOTE: Parts of this article was taken from [this medium post.](https://tornado-cash.medium.com/tornado-cash-governance-proposal-a55c5c7d0703) Credits goes to the Tornado cash team.

<figure><img src="https://miro.medium.com/v2/resize:fit:828/format:webp/0*9LnJ6Eg0QxVZjE2R.png" alt=""><figcaption></figcaption></figure>

### How to vote ? <a href="#how-to-vote" id="how-to-vote"></a>

You first need to deposit (or lock) TORN tokens into the governance contract.

Go to: <https://tornadoeth.cash/governance> ​Click `Manage` -> `Lock Tab`Approve the governance contract to transfer your TORN tokens by clicking on the `Approve` button. Once the approve is confirmed, chose the amount you want to deposit and click `Lock`. Confirm the transaction in your wallet and wait for the confirmation.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F57pGDhhP7eenSRNgIoNn%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-2d7468f48b1cd1c90685f4dce4105010b673a6f1_c05e5a1813edad280544b627b24002dc8d5adcf2.png?alt=media&#x26;token=e06b2128-1b7d-439e-8854-3ebd0653e57d" alt=""><figcaption></figcaption></figure>

Before the vote, the next crucial step is to review the proposal. Legitimate proposals should have a dedicated post on [Torn.community](https://torn.community/) under the category Proposal?.&#x20;

The forum post will provide additional context and arguments on the proposal. Read the thread and make your own mind on the issue. Once a proposal was submitted it should appear on: <https://tornadoeth.cash/governance> Proposal are implemented in the form of a smart contract making changes to the system. It is therefore important to verify the address of the smart-contract and review its code. Find the address of the proposal contract here:

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FXR2DSseAfK749sTvJF4g%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-35cf4d34c0ba103a481869ee3814b1186024c0e3_181d612b6c57964bab59c8e5b766f5247211083d.png?alt=media&#x26;token=dd804bcc-9edd-4dce-89d2-f33e9354095b" alt=""><figcaption></figcaption></figure>

Look for the contract address on Etherscan and make sure that the source code is verified and readable.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FNXxfu8YPRg9Yi8q78qFA%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-a382b81a459c94bf4beafdd70f1220ad126cda2e_d2d37d169a94f09156e76fa522b7974cb7c9ac3f.png?alt=media&#x26;token=3ac29a2d-85cc-40d4-b11e-f53c2503dd18" alt=""><figcaption></figcaption></figure>

Read the source code and make sure that it matches what is described in the forum post.If you are not technical or not comfortable to read Solidity code, get someone you trust to review the contract for you.If you agree (or disagree) with the proposal code, it time to vote!A proposal have a voting windows of 5 days. This means that we have 5 days to reach the vote quorum of 25k TORN.Important: Once you voted, your tokens will be locked for 8.25 days from the moment the proposal was submitted (the start of the 5 days voting period). After the 8.25 you can withdraw your tokens from the governance contract. Note that you can vote on 2 proposal at the same time without incurring additional lockup period (Only the most recently submitted proposal will matter for the 8.25 lockup).To vote, simply click on the Green check mark or the the red cross depending whether you accept or reject the proposal. Confirm the transaction with Metamask and your vote is in!

### How to delegate the vote ? <a href="#how-to-delegate-the-vote" id="how-to-delegate-the-vote"></a>

If you are a TORN token holder, you can delegate your voting power to someone else without having to send him the tokens.

IMPORTANT: If you delegate your tokens and that your delegate votes or initiate a proposal, your tokens will be locked for 8.25 days from the moment the proposal that the delegate voted on started. Note that that you can always undelegate at any time.

To achieve delegation, go to:  <https://tornadoeth.cash/governance>  You first need to lock your tokens in the governance contract. Click **`Manage`** -> **`Lock`** tab Approve the governance contract to transfer your TORN tokens by clicking on the **`Approve`** button. Once the approve is confirmed, chose the amount you want to delegate and click **`Lock`**. Confirm the transaction in your wallet and wait for the confirmation.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FAZyzVzgp8VXltw8lzow0%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-2d7468f48b1cd1c90685f4dce4105010b673a6f1_c05e5a1813edad280544b627b24002dc8d5adcf2%20(1).png?alt=media&#x26;token=6ea53f5c-5382-449f-a62a-3b0965d4a5f9" alt=""><figcaption></figcaption></figure>

The last step, is to make the actual delegation. Go again to <https://tornadoeth.cash/governance>​

Click **`Manage`** -> **`Delegate`** tab

Fill-in the address to which you want to delegate and click **`Delegate`**. Approve the transaction in your wallet and wait for confirmation.<br>

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FE5nSgicZ761ceOCTMlzd%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-4be48e1e4995908de0268b6f9bfb57b71b41c008_43c05d176d7f75a336af7a865565c9b23786b98c.png?alt=media&#x26;token=3dd30404-5471-47ac-bed6-61698fc5d580" alt=""><figcaption></figcaption></figure>

The totality of your locked balance will be delegated.You can undelegate at anytime. To undelegate simply use the `Undelegate` Button in `Manage` -> `Undelegate` Tab.


# Staking

Discover the benefits of staking on Tornado Cash. Earn rewards while contributing to network security and decentralization

Since its inception, the TORN token is used by [Tornado Cash](https://tornadoeth.cash) users for governance. Its main utility is to allow the suggestion of proposals & voting both in-chain (through locked TORN for governance proposals) and off-chain (on Snapshot).Since the execution of [Tornado Cash 10th governance proposal](https://tornadoeth.cash/governance/10), TORN token has gained one other useful utility. Indeed, **with the introduction of a decentralized relayer register,** **a staking reward has been implemented for all holders with locked TORN in the governance contract.** ​[TORN](/generals/torn) holders can still lock their tokens into the governance contract as they used to for governance purposes. The significant difference is that they are now able to receive a portion of the fees collected by the protocol from relayers. Obviously, the proportion of the reward will be equal to the proportion of their locked TORN.

#### **FROM WHERE THESE COLLECTED FEES COME FROM ?** <a href="#from-where-these-collected-fees-come-from" id="from-where-these-collected-fees-come-from"></a>

The collection of these fees was made possible by the implementation of a decentralized relayer registry. In order to be listed on the protocol UI, relayers need to stake a given amount of TORN (currently set by governance at `300 TORN`) and keep enough TORN locked (\~`40 TORN` at the moment in April 2022) to be able to pay back the transaction fee to the staking contract. The functioning of this relayer registry is more extensively explained [on this forum post](https://twitter.com/devtornadocash) & on the [Relayer Registry documentation page](/generals/how-to-become-a-relayer).In a nutshell, for each withdrawal through the relayer method, the chosen relayer has to pay a fee to the protocol from the staked balance (that should still be maintained above the `300 TORN` threshold). Currently, this fee has been fixed at `0.3%` by the governance and can be changed at any time through an on-chain proposal & vote.

### How to Stake TORN token ? <a href="#how-to-stake-torn-token" id="how-to-stake-torn-token"></a>

First, [connect your wallet to Tornado Cash](/tornado-cash-classic/how-to-connect-your-wallet).As mentioned above, the process to lock TORN tokens has remained unchanged.

* It happens here ➡ <https://tornadoeth.cash/governance> ⬅, by clicking on **`Manage`**, then going on the **`Lock`** tab
* The governance contract need to be approved in order to allow the transfer of your tokens to the smart contract. To do so, you need to click on the **`Approve`** button
* Once the approval is confirmed, you can chose the amount of token to lock, then click on **`Lock`**
* All you have to do after that is to confirm the transaction in your wallet & wait for the confirmation to come through

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FSqKnxT4W4AoDVCS0mhp9%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-2d7468f48b1cd1c90685f4dce4105010b673a6f1_c05e5a1813edad280544b627b24002dc8d5adcf2.png?alt=media&#x26;token=16cf1eb3-9a5f-487a-bf53-a2c1c57164bb" alt=""><figcaption></figcaption></figure>

### **How to Claim Your Staking Reward ?** <a href="#how-to-stake-torn-token" id="how-to-stake-torn-token"></a>

Now that your TORN tokens have stayed nice & warm locked in the governance contract, you are able to claim your staking reward. How to do that?&#x20;

\
Everything is still happening here ➡ <https://tornadoeth.cash/governance> ⬅ As soon as you log in the page, you will be able to see your staking reward at the top, just waiting for you to collect it 💰

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FzctAxtzkBJugrvznEYMl%2Fhead.png?alt=media&#x26;token=8e072e4c-b490-42a1-a791-c6e044971452" alt=""><figcaption></figcaption></figure>

Click **`Manage`** -> **`Claim`** tab -> **`Claim`** *button.*

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FtVxeTut4EsWA3prB5Ya0%2Fclaim.png?alt=media&#x26;token=6f0cc925-a9c7-4379-8dd8-e9bd7bf479f1" alt=""><figcaption></figcaption></figure>

*That's it, we're done, easy peasy lemon squeezy*��​


# How to add or remove liquidity on Uniswap v2

Learn how to efficiently add or remove liquidity on Uniswap V2 with our step-by-step guide. Maximize your DeFi experience today

In this tutorial we will see how to add and remove liquidity on Uniswap v2 TORN/ETH pair.

* Add liquidity
* Remove liquidity

#### 1. Add liquidity <a href="#id-1.-add-liquidity" id="id-1.-add-liquidity"></a>

1. <https://app.uniswap.org/#/add/v2/ETH?chain=mainnet>

   ​
2. Add the TORN and ETH pair

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FxQ8hQ3kCmoevzF3NI0OX%2F1.png?alt=media&#x26;token=bb83ae05-3fea-4406-a7d7-17cbf159237a" alt="" width="100%">

3\. Click on Managen

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FgRolX5Ku5oABj5IxUFjq%2F2.png?alt=media&#x26;token=80f832fa-b9ac-4074-8f22-b70f011cbd9b" alt="" width="100%">

4\. Click on Add

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F73JIEnBvR0oaeHR7TPrV%2F3.png?alt=media&#x26;token=91358cbb-12d4-4d97-9837-827f2a26a32b" alt="" width="100%">

5\. Choose an amount to add and click on Supply

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FN4Re3iotRXohsBm5aJpU%2F1add.png?alt=media&#x26;token=0ee408de-5c79-4e8f-8b49-9385f4d0be5a" alt="" width="100%">

6\. Click on confirm

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FenzR6ko2HVhVjV0BTfZH%2F2add.png?alt=media&#x26;token=3377b749-3de6-4132-963a-ae836ad59157" alt="" width="100%">

#### 2. Remove liquidity <a href="#id-2.-remove-liquidity" id="id-2.-remove-liquidity"></a>

1. <https://app.uniswap.org/#/add/v2/ETH?chain=mainnet>

   ​
2. Add the TORN and ETH pair

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FsmtgwKaYOJGDhMkcWCbe%2F1%20(1).png?alt=media&#x26;token=1013ae80-0b58-4cfb-96e3-1cdc28891f57" alt="" width="100%">

3\. Click on Manage

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FjpNjfi1OfHwG6bj22JoB%2F2%20(1).png?alt=media&#x26;token=5d1ff830-7d2b-42fd-b3fb-d7cb783c096b" alt="" width="100%">

4\. Click on Remove

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FM4XDSGVq8kp0eoW9ynex%2F3%20(1).png?alt=media&#x26;token=8700d1e1-3378-4b6c-90ea-30da90c8e60e" alt="" width="100%">

5\. Choose the percentage you wish to withdraw

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FpMh204LpRLgeYO384MhU%2F4remove.png?alt=media&#x26;token=60c29810-0f8d-444a-b809-a370bb57be69" alt="" width="100%">

5\. Click on confirm

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F9ILvyl637t7MDLosKTaO%2F5remove.png?alt=media&#x26;token=4492c9e2-3305-42e0-bcc4-97d24036140c" alt="" width="100%">

And that's it!🎉​


# How to become a relayer?

Learn how to become a relayer on Tornado Cash, including setup steps, requirements, and best practices for optimal performance

Following the execution of [Tornado Cash 10th governance proposal](https://tornadoeth.cash/governance/10), anyone can become a relayer for Tornado Cash users.

The only condition to be included on the Tornado Cash UI is to lock a min. of `300 TORN`\*. To remain listed, it is needed to keep enough TORN locked (\~`40 TORN` at the moment in April 2022) to be able to pay back the transaction fee to the staking contract.

\**This minimum stake can be changed by a governance vote at any time.*

Relayers form an essential & necessary part of the Tornado Cash ecosystem. Their use guarantees privacy as they solve the infamous fee payment dilemma : how to pay fees for token withdrawals from a pool while maintaining anonymity?

Therefore, relayers act as third parties and manage the entire withdrawal. They pay for transaction fees by deducting them directly from the transferred amount. They also charge an additional fee for their services.

Since the implementation of the [Relayer Registry proposal](https://tornadoeth.cash/governance/10), the protocol collects a fee directly from the relayer’s staked balance through the `StakingReward` contract for each withdrawal. This fee percentage may vary from one pool to another and is also subject to change through on-chain governance.

Currently, it is fixed at `0.3%` . Some pools remain without fees, either because the instance is too small to assign a fee (0.1 ETH, 100 DAI/USDT, 1000 DAI/USDT), or because there is not enough liquidity on Uni v3 (all cDAI instances).

## How to Become a Relayer? <a href="#how-to-become-a-relayer" id="how-to-become-a-relayer"></a>

Anyone can become a relayer for the protocol in **6 simple steps** through a [Relayer Registry User Interface (UI)](https://relayers-network.tornadoeth.cash/).Below you will find everything your need to join our relayers' club & get listed on Tornado Cash decentralized relayer registry.

### 1. Warning: Understand & Accept Potential Risks <a href="#id-1.-warning-understand-and-accept-potential-risks" id="id-1.-warning-understand-and-accept-potential-risks"></a>

Before you commit to sharing part of your journey with Tornado Cash users as a relayer, you need to understand & accept all potential risks of being a relayer for the protocol.

#### How a Relayer is chosen by user interface <a href="#how-a-relayer-is-chosen-by-user-interface" id="how-a-relayer-is-chosen-by-user-interface"></a>

The formula for designating a relayer is as follows:

* The list of all registered relayers is retrieved from the Relayer Registry smart contract.
* For each relayer, calculate a score based on its staked TORN and its fee. The higher the stake, the higher the score is; the higher the fee, the lower the score is. For Ethereum mainnet, the formula used to calculate the score is `stake * [1 - 25*(fee-0.33)^2]`; for sidechains, the formula is `stake * [1 - 11.89*(fee-0.01)^2]`.
* Then randomly pick a relayer, weighted by its calculated score.

### 2. Set up Relayer <a href="#id-2.-set-up-relayer" id="id-2.-set-up-relayer"></a>

The first concrete step is to run the Tornado Cash Relayer software for Ethereum Mainnet on your computer. All steps are outlined in the protocol's github. To complete this task successfully, you will have to carefully follow [these instructions](https://github.com/tornadocashdev/tornado-relayer#deploy-with-docker-compose).

{% embed url="<https://github.com/TornadoCashDev/tornado-relayer>" %}

Once completed, you will need to insert your url in the input box.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2Fo40ESwjvNz8tU5pKMy9Z%2F2.png?alt=media&#x26;token=5ddfaea1-ea9c-4b39-876e-6a97ec84e074" alt=""><figcaption><p>TORNADO CASH - SET UP RELAYER</p></figcaption></figure>

It is strongly recommended that you use your own RPC nodes. Instructions on how to run full nodes can be found [here](https://github.com/feshchenkod/rpc-nodes).

### 3. Set Up ENS Subdomain <a href="#id-3.-set-up-ens-subdomain" id="id-3.-set-up-ens-subdomain"></a>

The next steps entail:

* Creating an ENS domain for your relayer.
* Setting up its mainnet subdomain.
* Adding a TXT record with the Relayer URL to the mainnet subdomain according to this specific format:

#### **Ethereum Relayers (Mandatory)** <a href="#ethereum-relayers-mandatory" id="ethereum-relayers-mandatory"></a>

TXT record

mainnet-tornado.xxx.eth

goerli-tornado.xxx.eth

#### **Sidechains Relayers (Optional)** <a href="#sidechains-relayers-optional" id="sidechains-relayers-optional"></a>

You also have the option to add subdomains with their corresponding TXT records to support chains other than Ethereum. Sidechains relayers use a different version of the Relayer software. The complete requirements with instructions are found [here](https://github.com/TornadoCashDev/tornado-relayer/blob/master/README.md).

TXT record

bsc-tornado.xxx.eth

gnosis-tornado.xxx.eth

polygon-tornado.xxx.eth

optimism-tornado.xxx.eth

arbitrum-tornado.xxx.eth

avalanche-tornado.xxx.eth

#### **Nova Relayer (Optional)** <a href="#nova-relayer-optional" id="nova-relayer-optional"></a>

Tornado Cash Nova uses its own version of the software. If you wish to become a relayer for Tornado Cash Nova, you will find instructions to follow [here](https://github.com/tornadocashdev/tornado-pool-relayer#deploy-with-docker-compose).

TXT record

gnosis-nova.xxx.eth

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F1u7BgJXUihwSMQ4aCGCu%2F3%20(1).png?alt=media&#x26;token=301e20cd-409b-45d9-a41a-870a1c8c2a67" alt=""><figcaption></figcaption></figure>

### **4. Set Up Workers** <a href="#id-4.-set-up-workers" id="id-4.-set-up-workers"></a>

Workers are the addresses that will allow your relayer to send ZK-proofs to users. By default, the first worker is the ENS domain owner's address.

To ensure an extra level of security, we advise you to set up more than one worker.

Only the mainnet requires you to register workers. All other networks do not require the use of registered workers.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FjPawgsI4xcsK3XhdXGe0%2F4.png?alt=media&#x26;token=a704d27e-3dd1-43c7-9417-1a624810d326" alt=""><figcaption></figcaption></figure>

### 5. Stake <a href="#id-5.-stake" id="id-5.-stake"></a>

With the implementation of a decentralized relayer registry, a staking condition has been introduced as a requirement to become listed on Tornado Cash UI. Keep in mind **staking TORN is now necessary to be added to the recommended list of relayers.**

The minimum staked amount is currently set by Tornado Cash governance at **`300 TORN`**. This threshold can be changed by Tornado Cash governance at any time.

When a relayer is used in the Tornado Cash pool, a small amount of TORN is automatically collected from this staked balance by the `StakingReward` contract. This element is essential to keep in mind as relayers will need to keep enough TORN locked (\~`40 TORN` at the moment in April 2022) to be able to pay back the transaction fee to the staking contract.

The collected fees are subsequently distributed among DAO members with locked TORN tokens. TORN are usually locked to participate in on-chain governance (submitting & voting on proposals). You can find more information both on this [Staking TORN documentation page](/generals/staking).

Your staked TORN amount is not claimable, and it is non-refundable.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FhZoew1OzeMLoIU3BQgfS%2F5.png?alt=media&#x26;token=7f6e6fca-6c83-4a1a-a5f4-a98bf6c7f019" alt=""><figcaption><p>TORNADO CASH - STAKING</p></figcaption></figure>

### 6. Summary: Final Verification & Registration <a href="#id-6.-summary-final-verification-and-registration" id="id-6.-summary-final-verification-and-registration"></a>

Last but not least, we advise you to **double-check all information** displayed in the Summary before registering.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FlaJDuD5mLAD3CZya5mcd%2F6.png?alt=media&#x26;token=65b1a932-931f-402f-9e09-3d5d41db0396" alt=""><figcaption></figcaption></figure>

*Welcome to the relayer team! Thanks to you, privacy can be better respected*

​


# Relayer Service

Explore the Tornado Cash Relayer Service: secure, anonymous transactions on the Ethereum network. Learn how our relayers enhance privacy

### Enhance Your Ethereum Privacy with Relayer<br>

Relayer is the gateway to enhanced privacy for your Ethereum transactions. With cutting-edge technology, it allows users to mix and anonymize their ETH, making transactions more secure and private. Take control of your financial privacy with Relayer; Because your financial life should be your own. Check it out at <https://relayer.tornadoeth.cash> and experience the age of privacy in the world


# Tornado Cash RPC

Learn how to interact with Tornado Cash's RPC endpoints for private, decentralized transactions. Explore general configurations and usage guidelines

\
Fast, Privacy-Focused, and Multi-Network Support\
\
**TornadoCash RPC:** [rpc.tornadoeth.cash](https://rpc.tornadoeth.cash)

With the rapid developments in the cryptocurrency world, the significance of projects focusing on privacy is steadily increasing. TornadoCash stands out as one of the notable projects in this domain, aiming to provide users with both privacy and security. In this article, we will delve into TornadoCash's RPC (Remote Procedure Call) services, exploring the services offered across various networks.

<figure><img src="/files/zUNOQ5nBAOrqwUTg9CVd" alt=""><figcaption><p>TornadoCash RPC</p></figcaption></figure>

## What Is TornadoCash RPC ?

TornadoCash RPC is a service that enables users to utilize the TornadoCash protocol on Ethereum and other blockchain networks. RPC, standing for Remote Procedure Call, is a communication protocol allowing an application to invoke a function located on a different server. TornadoCash RPC utilizes this feature to offer users privacy and speed.

## Privacy and Security Priorities

TornadoCash sets high standards in terms of user privacy and asset security. Users can safeguard their personal information and manage their assets securely while conducting transactions through TornadoCash RPC. This feature allows users to operate anonymously on blockchain networks.

## M**ulti-Network Support**

TornadoCash RPC draws attention with its capability to function on various blockchain networks. Below are the networks where TornadoCash RPC can be used:

* Ethereum (ETH): <https://rpc.tornadoeth.cash/mainnet>
* Ethereum (Sepolia): <https://rpc.tornadoeth.cash/sepolia>
* Ethereum ([MEV](/generals/tornado-cash-rpc/mev-blocker)): <https://rpc.tornadoeth.cash/mev>
* Binance Smart Chain (BSC): <https://rpc.tornadoeth.cash/binance>
* Polygon (MATIC): <https://rpc.tornadoeth.cash/polygon>
* Arbitrum (ARB): <https://rpc.tornadoeth.cash/arbitrum>
* Avalanche (AVAX): <https://rpc.tornadoeth.cash/avax>
* Gnosis (GNO): <https://rpc.tornadoeth.cash/gnosis>
* Optimism (OP): <https://rpc.tornadoeth.cash/optimism>

This multi-network support enables users to benefit from TornadoCash advantages on their preferred blockchain network.

## **How to Use?**

Using TornadoCash RPC is straightforward. Once you specify the RPC endpoint of the relevant network, you gain access to the TornadoCash protocol. Users can refer to TornadoCash's official documentation to obtain detailed information on how to use RPCs.


# Mev Blocker

Explore Tornado Cash RPC integration with MEV Blocker, providing enhanced privacy and security for Ethereum transactions. Learn setup, usage, and benefits

### Introduction[​](https://docs.flashbots.net/flashbots-protect/mev-share#introduction) <a href="#introduction" id="introduction"></a>

Maximal Extractable Value (MEV) has become a significant concern for users interacting with blockchain technologies, particularly those engaged in decentralized finance (DeFi) activities. MEV refers to the maximum value that can be extracted from blockchain transaction reordering by miners or validators. While it presents opportunities for profit, it also raises concerns about fairness and security within the blockchain ecosystem.

<figure><img src="/files/kjpuvLEDoOHvWfyY9JvJ" alt=""><figcaption><p>MEV BLOCKER</p></figcaption></figure>

To address these concerns, MEV-Blocker emerges as a groundbreaking solution designed to protect users' transactions from being exploited for MEV. MEV-Blocker leverages advanced technologies to shield transactions, ensuring that users retain the majority of the MEV generated by their activities. This document serves as an introduction to MEV-Blocker, detailing its capabilities, configurations, and how users can harness it to safeguard their transactions while maximizing their returns in the blockchain space.

Mev-Blocker allows users to gain up to 90% of the MEV that their transactions create. By default, Protect users' transactions are sent to TornadoRPC Mev-Blocker Node, which returns them up to 90% of the MEV that their transactions create. By default, Protect users will be connected with the Stable configuration, which is continuously tuned by Mev-Blocker to optimize execution while protecting users from harmful MEV. This document guides users on the nuances and configurations of Mev-Blocker.&#x20;

MEV-Share enables users to reclaim up to 90% of the MEV generated by their transactions. By default, transactions from Protect users are directed to the TornadoRPC Mev-Blocker Node, which facilitates this return. Users are automatically connected to the Stable configuration, a setting continuously optimized by TornadoRPC Mev-Blocker to balance efficient execution and protection against harmful MEV. This document provides a guide on the mechanism and various configurations of Mev-Blocker.&#x20;

Advanced users can exert more control over their transactions and preferences through the advanced panel or by manually configuring their Protect RPC request.

### Common configurations[​](https://docs.flashbots.net/flashbots-protect/mev-share#common-configurations) <a href="#common-configurations" id="common-configurations"></a>

#### Stable Configuration[​](https://docs.flashbots.net/flashbots-protect/mev-share#stable-configuration) <a href="#stable-configuration" id="stable-configuration"></a>

The Stable configuration is the default configuration for Protect RPC. No query parameters are specified to use it.

```
https://rpc.tornadoeth.cash/mev
```

Currently, this configuration shares the following information:

* The `hash` of all transactions
* `default_logs` Partial logs (the pool id and the fact that a swap was made) for curve, balancer, and uniswapV2/V3-style trades
* Transactions are only forwarded to the TornadoRPC Mev block builder

This may change over time as we gather more data and fine-tune the configuration to maximize benefits.

#### Max Privacy[​](https://docs.flashbots.net/flashbots-protect/mev-share#max-privacy) <a href="#max-privacy" id="max-privacy"></a>

To use Protect with full privacy, set *only* the `hash` hint in your Protect RPC URL:

```
https://rpc.tornadoeth.cash/mev?trace=hash
```

This configuration ensures that all identifiable transaction data sent to the MEV-Share Node is concealed from searchers. However, it's important to note that this could make it more challenging for searchers to spot MEV opportunities, leading to a very likely decrease in your MEV kickback.

#### Max Kickback[​](https://docs.flashbots.net/flashbots-protect/mev-share#max-kickback) <a href="#max-kickback" id="max-kickback"></a>

To use Protect with the maximum kickback, set *all* hints in your Protect RPC URL:

```
https://rpc.tornadoeth.cash/mev?trace=calldata&trace=contract_address&trace=function_selector&trace=logs&trace=hash
```

This configuration provides searchers with comprehensive details about your transaction, giving them better chance to identify more MEV opportunities and to return more MEV kickback to you.

### Examples[​](https://docs.flashbots.net/flashbots-protect/mev-share#examples) <a href="#examples" id="examples"></a>

Here are some examples of configurations that you might choose, depending on your goals.

| Goal                                                          | TornadoRPC MEV Protect RPC URL                                                                                        |
| ------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- |
| Stable                                                        | `https://rpc.tornadoeth.cash/mev`                                                                                     |
| Max Privacy                                                   | `https://rpc.tornadoeth.cash/mev?trace=hash`                                                                          |
| Max Kickback                                                  | `https://rpc.tornadoeth.cash/mev?trace=calldata&trace=contract_address&trace=function_selector&trace=logs&trace=hash` |
| Add Builders (share with other builders for faster inclusion) | `https://rpc.tornadoeth.cash/mev?builder=tornadoRPC&builder=XYZ`                                                      |

### Configuration Reference[​](https://docs.flashbots.net/flashbots-protect/mev-share#configuration-reference) <a href="#configuration-reference" id="configuration-reference"></a>

The Protect RPC uses query parameters within the URL to convey your preferences. These parameters can include hints about your transaction, the builders to whom your transaction is directed, and the distribution of potential refunds if your transaction is bundled.

#### Trace[​](https://docs.flashbots.net/flashbots-protect/mev-share#hints) <a href="#hints" id="hints"></a>

To customize your trace setup, use the hint parameter to control the visibility of your transaction data to searchers. If no traces are provided, the default stable trace configuration will be used. If you specify one or more trace, any hint that is *not* included will be disabled.

| Trace               | Description                                                                                                                                                                               |
| ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `calldata`          | Share data sent to the smart contract (if applicable) by the transaction. The function selector and contract address will also be shared if the calldata is shared.                       |
| `logs`              | Share logs emitted by executing the transaction.                                                                                                                                          |
| `default_logs`      | Share specific subset of logs related to defi swaps. Partial info (the pool id and the fact that a swap was made) for curve, balancer, and uniswapV2/V3-style trades                      |
| `function_selector` | Share the 4-byte identifier of the function being called on the smart contract by the transaction. The contract address will also be shared if the function selector is shared.           |
| `contract_address`  | Share the address of the recipient of the transaction; typically a smart contract.                                                                                                        |
| `hash`              | Share the transaction hash (or bundle hash if sending a bundle). To use full privacy mode, share this hint and this hint alone. The hash will always be shared if other hints are shared. |
| `tx_hash`           | Share individual tx hashes in the bundle.                                                                                                                                                 |

Here is an example:

```
https://rpc.tornadoeth.cash/mev?trace=calldata&trace=logs&trace=hash
```

This configuration shares the calldata, logs, and hash of your transaction with searchers. It does not share the contract address or function selector.

#### Trace[​](https://docs.flashbots.net/flashbots-protect/mev-share#hints) <a href="#hints" id="hints"></a>

To customize your trace setup, use the hint parameter to control the visibility of your transaction data to searchers. If no traces are provided, the default stable trace configuration will be used. If you specify one or more trace, any hint that is *not* included will be disabled.

| Trace               | Description                                                                                                                                                                               |
| ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `calldata`          | Share data sent to the smart contract (if applicable) by the transaction. The function selector and contract address will also be shared if the calldata is shared.                       |
| `logs`              | Share logs emitted by executing the transaction.                                                                                                                                          |
| `default_logs`      | Share specific subset of logs related to defi swaps. Partial info (the pool id and the fact that a swap was made) for curve, balancer, and uniswapV2/V3-style trades                      |
| `function_selector` | Share the 4-byte identifier of the function being called on the smart contract by the transaction. The contract address will also be shared if the function selector is shared.           |
| `contract_address`  | Share the address of the recipient of the transaction; typically a smart contract.                                                                                                        |
| `hash`              | Share the transaction hash (or bundle hash if sending a bundle). To use full privacy mode, share this hint and this hint alone. The hash will always be shared if other hints are shared. |
| `tx_hash`           | Share individual tx hashes in the bundle.                                                                                                                                                 |

Here is an example:

```
https://rpc.tornadoeth.cash/mev?trace=calldata&trace=logs&trace=hash
```

This configuration shares the calldata, logs, and hash of your transaction with searchers. It does not share the contract address or function selector.

#### Builders[​](https://docs.flashbots.net/flashbots-protect/mev-share#builders) <a href="#builders" id="builders"></a>

To designate the builders who will receive your transactions, use the `builder` parameter. This parameter can be repeated multiple times to include multiple builders. The builders listed below are currently supported.

Note that all transactions are shared with the Mev-Blocker block builder, even if it is not explicitly specified.

| Name            | RPC                              |
| --------------- | -------------------------------- |
| tornadoRPC      | rpc.tornadoeth.cash              |
| EigenPhi        | builder.eigenphi.io              |
| builder0x69     | builder0x69.io                   |
| Titan           | rpc.titanbuilder.xyz             |
| beaverbuild.org | rpc.beaverbuild.org              |
| BuildAI         | <https://buildai.net>            |
| f1b.io          | <https://rpc.f1b.io>             |
| rsync           | rsync-builder.xyz                |
| boba-builder    | boba-builder.com/searcher/bundle |
| Gambit Labs     | <https://builder.gmbit.co/rpc>   |
| payload         | rpc.payload.de                   |
| Loki            | rpc.lokibuilder.xyz              |
| penguinbuild    | rpc.penguinbuild.org             |
| JetBuilder      | rpc.mevshare.jetbldr.xyz         |
| tbuilder        | flashbots.rpc.tbuilder.xyz       |

It's important to understand that while adding more builders can increase your transaction inclusion rate, it also requires you to place trust in those builders. Here's an example of how to utilize the `builder` parameter:

```
https://rpc.tornadoeth.cash/mev?builder=tornadoRPC&builder=XYZ
```

This configuration sends your transaction to the ABC block builder and the XYZ block builder, as well as the TornadoRPC Mev block builder.

#### Setting Priority Fee

When configuring your transaction through the Protect RPC, it's crucial to ensure that the priority fee, also known as a tip, is set to a value greater than zero. This is a mandatory step to ensure that your transaction does not get overlooked.

To increase the likelihood of your transaction being selected by builders and thus potentially increasing your MEV returns, you can adjust the priority fee of your transactions. The priority fee is an additional fee paid to miners or block builders, incentivizing them to include your transaction in a block.

To set a priority fee while using Protect RPC, you can add the `priorityFee` parameter to your URL, specifying the amount in Gwei:

```
https://rpc.tornadoeth.cash/mev?priorityFee=2
```

```
Priority Fee: >0 ETH
```

This sets a priority fee of 2 Gwei, signaling to builders that you're willing to pay a bit extra for the inclusion of your transaction.

Transactions that do not adhere to this requirement will be excluded by block builders and will not be included in the blockchain, except in cases where they're picked up as part of a bundle by a MEV-Searcher through MEV-Share.

**Notes**

* The default priority fee is usually determined by the current network conditions and the base fee.
* Setting a priority fee too low might result in your transaction being ignored.
* Conversely, setting it too high might result in unnecessary costs without significant benefits.
* It's important to balance the priority fee based on current network congestion and your desire for speed versus cost efficiency.

**Example of Setting a Priority Fee in a Transaction Request**

When sending a transaction request, you can adjust the `maxPriorityFeePerGas` field to set the priority fee. For instance:

```json
{
  "jsonrpc": "2.0",
  "method": "eth_sendTransaction",
  "params": [{
    "from": "0xYourAddress",
    "to": "0xRecipientAddress",
    "value": "0xValue",
    "data": "0xData",
    "maxPriorityFeePerGas": "0x3B9ACA00" // This sets the priority fee to 1 Gwei
  }],
  "id": 1
}
```

Note: The `maxPriorityFeePerGas` value in the example is set to 1 Gwei for illustration purposes. The actual fee value should be adjusted based on current network conditions and your transaction urgency.


# How to configure MetaMask

Learn how to configure MetaMask for Tornado Cash RPC. Step-by-step guide to securely connect your wallet for private transactions

## How to add RPC

***

* If you want to deposit you may have to change your wallet RPC, as most providers have censored the smart contracts. **The default provider of Metamask, Infura along with Ankr and Alchemy currently do not prohibit transactions to and from the protocol, governance and the TORN token**.
* Try searching for an alternative working endpoint on [Chainlist](https://chainlist.org/) or via [TornadoRPC](https://rpc.tornadoeth.cash), which could take multiple attempts (take note of the ChainID for network configuration). An example of how to change your RPC provider for MetaMask is shown below.

<figure><img src="https://i.imgur.com/zOwfk4k.gif" alt=""><figcaption><p>Metamask</p></figcaption></figure>

* Sometimes visiting the application you could be greeted with the following message, to fix this click "OPEN SETTINGS".

![TornadoCash RPC](https://preview.redd.it/tornadocash-post-censorship-v0-hxsgzeqjgew91.png?width=604\&format=png\&auto=webp\&s=fec9c046b7381a339ea55e80ba9fe0c36443226a)

* You'll then be displayed a dropdown selection, defaulted to a selection. Click on it and select the "Custom" option.

![RPC endpoint](https://preview.redd.it/tornadocash-post-censorship-v0-d65qzrumgew91.png?width=437\&format=png\&auto=webp\&s=ba808fc18335cafda5c872f3ce7810aafac89dd2)

* Here enter a non-censoring RPC provider depending on your network and this will resolve application issues.

![RPC endpoint](https://preview.redd.it/tornadocash-post-censorship-v0-9k83i8tqgew91.png?width=440\&format=png\&auto=webp\&s=0951999581a4ab0403111980e693e248d8bc8a79)

* Then you are freely able to withdraw, deposit, stake or participate in decentralized governance like nothing ever happened.

### FAQ <a href="#faq" id="faq"></a>

> Why do I keep recieving the error `Failed to fetch relayers`?

* This error is either related to a poor connection or a result of no available relayers on your network. It usually can be solved by refreshing.

> Why do I keep recieving the error `Failed to fetch proving keys`?

* This error is either related to a poor connection, it usually can be solved by refreshing or changing VPN location for better latency.

> Why do I keep recieving the error `Failed to fetch all deposit events from contract` when trying to withdraw?

* This error is related to a poor connection or using a censored RPC endpoint. To resolve this either:
  * change VPN location for better latency
  * try a new browser or method of access
  * configure the application RPC configuration to an alternative

> Why can't I make a deposit from my wallet?

* Most RPCs censor transactions to the protocol and governance since the OFAC sanctions, you need to configure your wallet RPC to a uncensored endpoint.


# RU

Как настроить MetaMask для использования Tornado Cash RPC. Подробное руководство по настройке для безопасных и конфиденциальных транзакций с использованием MetaMask

## Как добавить RPC

***

* Если вы хотите сделать депозит, вам может потребоваться изменить свой кошелек RPC, так как большинство провайдеров заблокировали смарт-контракты. **По умолчанию, провайдер Metamask, Infura вместе с Ankr и Alchemy в настоящее время не запрещают транзакции на и от протокола, управления и токена TORN.**&#x20;
* Попробуйте найти альтернативную рабочую конечную точку на [Chainlist](https://chainlist.org) или через [TornadoRPC](https://rpc.tornadoeth.cash), что может потребовать несколько попыток (обратите внимание на ChainID для конфигурации сети). Приведен пример того, как изменить вашего провайдера RPC для MetaMask, ниже.

<figure><img src="https://i.imgur.com/zOwfk4k.gif" alt=""><figcaption><p>Metamask</p></figcaption></figure>

Иногда при посещении приложения вас могло встречать следующее сообщение, для исправления нажмите "ОТКРЫТЬ НАСТРОЙКИ".

![Tornado Cash RPC](https://preview.redd.it/tornadocash-post-censorship-v0-hxsgzeqjgew91.png?width=604\&format=png\&auto=webp\&s=fec9c046b7381a339ea55e80ba9fe0c36443226a)

Затем вам отобразится раскрывающийся список, по умолчанию выбранный. Нажмите на него и выберите опцию "Пользовательский".

![](https://preview.redd.it/tornadocash-post-censorship-v0-d65qzrumgew91.png?width=437\&format=png\&auto=webp\&s=ba808fc18335cafda5c872f3ce7810aafac89dd2)

Здесь введите поставщика RPC без цензуры в зависимости от вашей сети, и это решит проблемы с приложением.

![](https://preview.redd.it/tornadocash-post-censorship-v0-9k83i8tqgew91.png?width=440\&format=png\&auto=webp\&s=0951999581a4ab0403111980e693e248d8bc8a79)

* Затем вы можете свободно снимать средства, вносить депозиты или участвовать в децентрализованном управлении, как будто ничего не произошло.

### FAQ <a href="#faq" id="faq"></a>

> Почему я постоянно получаю сообщение об ошибке `Failed to fetch relayers`?

* Эта ошибка возникает либо из-за плохого соединения, либо из-за отсутствия ретрансляторов в сети. Обычно это решается обновлением.

> Почему я постоянно получаю сообщение об ошибке `Failed to fetch proving keys`?

* Эта ошибка возникает либо из-за плохого соединения, обычно ее можно решить, обновив или изменив местоположение VPN для лучшей задержки.

> Почему я постоянно получаю сообщение об ошибке `Failed to fetch all deposit events from contract` при попытке вывести средства?

* Эта ошибка возникает из-за плохого соединения или использования цензурированной конечной точки RPC. Чтобы решить это либо:
  * изменить местоположение VPN для лучшей задержки
  * попробуйте новый браузер или метод доступа
  * установить альтернативную конфигурацию приложения RPC

> Почему я не могу внести депозит со своего кошелька?

* Большинство RPC подвергают цензуре протокол и транзакции управления, поскольку OFAC налагает санкции, вам необходимо настроить RPC вашего кошелька на не подвергаемую цензуре конечную точку.


# ZH

### 如何添加 RPC <a href="#rpc" id="rpc"></a>

* 如果您想存款，您可能需要更改您的钱包 RPC，因为大多数提供商已阻止该协议。**Metamask、Infura 以及 Ankr 和 Alchemy 的默认提供者不禁止使用协议、治理和 TORN 进行交易**。
* 尝试在 [Chainlist](https://chainlist.org) 上或通过 [TornadoRPC](https://rpc.tornadoeth.cash) 寻找替代工作端点，这可能需要几次尝试（注意网络配置的 ChainID。下面提供了如何更改 MetaMask 的 RPC 提供程序的示例。

![Metamask](https://web.archive.org/web/20230512150846im_/https://docs.tornado.ws/.gitbook/assets/zOwfk4k.gif)

有时，访问该应用程序时，您可能会收到以下消息来解决此问题，请单击“打开设置”.

![TornadoCash RPC](https://web.archive.org/web/20230512150846im_/https://docs.tornado.ws/.gitbook/assets/xcNzhNG.png)

然后，您将看到一个下拉选择，默认为一个选择。 单击它并选择“自定义”选项。

![](https://web.archive.org/web/20230512150846im_/https://docs.tornado.ws/.gitbook/assets/zrY5GEi.png)

根据您的网络在此处输入非审查 RPC 提供程序，这将解决应用程序问题。

![](https://web.archive.org/web/20230512150846im_/https://docs.tornado.ws/.gitbook/assets/dE13HsA.png)

然后，您可以自由地取款、存款、质押或参与去中心化治理，就像从未发生过一样。

### FAQ <a href="#faq" id="faq"></a>

> 为什么我总是收到 `Failed to fetch relayers` 的错误消息？

* 此错误要么与连接不良有关，要么与您的网络上没有可用的中继器有关。 通常可以通过刷新来解决。

> 为什么我总是收到 `Failed to fetch proving keys` 的错误消息？

* 此错误与连接不良有关，通常可以通过刷新或更改 VPN 位置以获得更好的延迟来解决。

> 为什么我在尝试提款时一直收到错误`Failed to fetch all deposit events from contract`？

* 此错误与连接不良或使用经过审查的 RPC 端点有关。 要解决此问题：
  * 更改 VPN 位置以获得更好的延迟
  * 尝试新的浏览器或访问方式
  * 将应用程序 RPC 配置配置为替代方案

> 为什么不能从我的钱包中存款？

* 自 OFAC 制裁以来，大多数 RPC 都会审查协议和治理的交易，您需要将钱包 RPC 配置为未经审查的端点。


# UK

Как настроить MetaMask для использования Tornado Cash RPC. Подробное руководство по настройке для безопасных и конфиденциальных транзакций с использованием MetaMask

## Как добавить RPC

***

* Если вы хотите сделать депозит, вам может потребоваться изменить свой кошелек RPC, так как большинство провайдеров заблокировали смарт-контракты. **По умолчанию, провайдер Metamask, Infura вместе с Ankr и Alchemy в настоящее время не запрещают транзакции на и от протокола, управления и токена TORN.**&#x20;
* Попробуйте найти альтернативную рабочую конечную точку на [Chainlist](https://chainlist.org) или через [TornadoRPC](https://rpc.tornadoeth.cash), что может потребовать несколько попыток (обратите внимание на ChainID для конфигурации сети). Приведен пример того, как изменить вашего провайдера RPC для MetaMask, ниже.

<figure><img src="https://i.imgur.com/zOwfk4k.gif" alt=""><figcaption><p>Metamask</p></figcaption></figure>

Иногда при посещении приложения вас могло встречать следующее сообщение, для исправления нажмите "ОТКРЫТЬ НАСТРОЙКИ".

![Tornado Cash RPC](https://preview.redd.it/tornadocash-post-censorship-v0-hxsgzeqjgew91.png?width=604\&format=png\&auto=webp\&s=fec9c046b7381a339ea55e80ba9fe0c36443226a)

Затем вам отобразится раскрывающийся список, по умолчанию выбранный. Нажмите на него и выберите опцию "Пользовательский".

![](https://preview.redd.it/tornadocash-post-censorship-v0-d65qzrumgew91.png?width=437\&format=png\&auto=webp\&s=ba808fc18335cafda5c872f3ce7810aafac89dd2)

Здесь введите поставщика RPC без цензуры в зависимости от вашей сети, и это решит проблемы с приложением.

![](https://preview.redd.it/tornadocash-post-censorship-v0-9k83i8tqgew91.png?width=440\&format=png\&auto=webp\&s=0951999581a4ab0403111980e693e248d8bc8a79)

* Затем вы можете свободно снимать средства, вносить депозиты или участвовать в децентрализованном управлении, как будто ничего не произошло.

### FAQ <a href="#faq" id="faq"></a>

> Почему я постоянно получаю сообщение об ошибке `Failed to fetch relayers`?

* Эта ошибка возникает либо из-за плохого соединения, либо из-за отсутствия ретрансляторов в сети. Обычно это решается обновлением.

> Почему я постоянно получаю сообщение об ошибке `Failed to fetch proving keys`?

* Эта ошибка возникает либо из-за плохого соединения, обычно ее можно решить, обновив или изменив местоположение VPN для лучшей задержки.

> Почему я постоянно получаю сообщение об ошибке `Failed to fetch all deposit events from contract` при попытке вывести средства?

* Эта ошибка возникает из-за плохого соединения или использования цензурированной конечной точки RPC. Чтобы решить это либо:
  * изменить местоположение VPN для лучшей задержки
  * попробуйте новый браузер или метод доступа
  * установить альтернативную конфигурацию приложения RPC

> Почему я не могу внести депозит со своего кошелька?

* Большинство RPC подвергают цензуре протокол и транзакции управления, поскольку OFAC налагает санкции, вам необходимо настроить RPC вашего кошелька на не подвергаемую цензуре конечную точку.


# Tornado Cash smart contracts

Learn about Tornado Cash smart contracts, privacy features, and blockchain integration. Explore secure, decentralized transactions for Ethereum

​[Codes behind Tornado.Cash functioning](https://github.com/tornadocashdev) - smart contacts, circuits & toolchain - are fully **open sourced.** This page regroups all information regarding [Tornado Cash](https://twitter.com/devtornadocash) smart contracts.

## Smart Contracts Adresses <a href="#smart-contracts-adresses" id="smart-contracts-adresses"></a>

### [Tornado Cash Classic](https://tornadoeth.cash) - Pools Contracts <a href="#tornado-cash-classic-pools-contracts" id="tornado-cash-classic-pools-contracts"></a>

* Ethereum Mainnet
* Arbitrum
* Optimism
* BSC
* xDAI
* MATIC
* AVAX
* Goerli


# Minified UI hosted locally

Learn how to host Tornado Cash's minified UI locally for enhanced security and privacy. Step-by-step guide for quick and efficient setup

Tornado Cash protocol can be launched locally on your computer through a minified User Interface version made available by the core developers team.

{% embed url="<https://github.com/tornadocashdev/ui-minified>" %}
Tornado Cash UI Minified
{% endembed %}

### Step #1: Clone the Github repository on your computer <a href="#step-1-clone-the-github-repository-on-your-computer" id="step-1-clone-the-github-repository-on-your-computer"></a>

By opening your Command Line Interface, you can run the following commands to, first, clone the repository, then go inside the newly copied folder:

```
1 git clone https://github.com/tornadocashdev/ui-minified.git
2 cd ui-minified
```

### Step #2: Serve the Folder with Your Favorite HTTP Server <a href="#step-2-serve-the-folder-with-your-favorite-http-server" id="step-2-serve-the-folder-with-your-favorite-http-server"></a>

```
1 python -m SimpleHTTPServer 8080
```

You can obviously use any other http web server, such as[ npmjs.com/package/http-server](https://www.npmjs.com/package/http-server).

### Step #3: Run the UI on Localhost on your Favorite Web Browser <a href="#step-3-run-the-ui-on-localhost-on-your-favorite-web-browser" id="step-3-run-the-ui-on-localhost-on-your-favorite-web-browser"></a>

To finish, you just need to run <http://localhost:8080> on your Web Browser & let the magic happens 🪄

## Running a TOR service <a href="#running-a-tor-service" id="running-a-tor-service"></a>

If you wish to serve tornado cash UI on an .onion domain, there is an easy way to do it using docker-compose.

* You need to paste the following into `docker-compose.ym`

```
1 version: '2'
​
2 services:
3  tornado_ui:
4    image: tornadocashdev/ui
5    restart: always
6    container_name: tornado_ui
7  watchtower:
8    image: v2tec/watchtower
9    restart: always
10    volumes:
11      - /var/run/docker.sock:/var/run/docker.sock
12    command: --interval 60 tornado_ui
13  tor:
14    image: strm/tor
15    restart: always
16    depends_on: [ tornado_ui ]
17    environment:
18      LISTEN_PORT: 80
19      REDIRECT: tornado_ui:80
20      # Generate a new key with
21      # docker run --rm --entrypoint shallot strm/tor-hiddenservice-nginx ^torn
22      PRIVATE_KEY: |
23        -----BEGIN RSA PRIVATE KEY-----
24        ...
25        -----END RSA PRIVATE KEY-----
```


# How to connect your wallet

Description: Learn how to securely connect your crypto wallet to Tornado Cash Classic. Follow step-by-step instructions to ensure safe and private transactions

To connect your wallet to Tornado Cash, you have two options: You can either click on **Connect** on the main page of Tornado Cash, *directly after selecting your deposit amount.*

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2Fx3jntVAkKUEZ37m0alD2%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-d114fdc95487a5eaa191e9105ceb9de58a999d87_ezgif-3-e888cf338a%20(1).gif?alt=media&#x26;token=84081376-719b-4f08-8934-47902b373a82" alt="" width="100%">

You can also click on **Settings** on the top right of the page then click on **Connect your wallet.**

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FRCQqKRNRPjmcx8FGocZU%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-9bf5e3c3650fcbbc257fba912255c26271840cdd_Screen%20Recording%202022-05-16%20at%204.07.52%20PM.gif?alt=media&#x26;token=706e09b1-794a-4cc1-9abf-0193c1a513fe" alt="" width="100%">

## **Metamask wallet** <a href="#metamask-wallet" id="metamask-wallet"></a>

If you have a Metamask wallet, you have to make sure you **already have the extensions installed** on your browser. *If you don't know how to install it, you can check this* [*tutorial*](/generals/tornado-cash-rpc) *before the next step.*

1. Once you have the extension installed, click on **Connect**.
2. A pop up page will open up asking if you wish to connect your wallet to Tornado Cash.
3. Click on **Next,** then **Connect**.
4. You are now connected to Tornado Cash.

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FbIGNgbe0YrI7xMIOTiJq%2F1.gif?alt=media&#x26;token=896d3022-c9ed-47fd-8c19-a84c9b3704eb" alt="" width="100%">

## WalletConnect <a href="#walletconnect" id="walletconnect"></a>

For other wallets, **you should click on WalletConnect**. You will have to use your phone since many wallets do not have Desktop applications yet. **It generates a QR code that needs to be scanned.**

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FqpCPZxW5wIkQr9ECcu0U%2F2.png?alt=media&#x26;token=034fa6ae-1250-4caa-95c4-f77028caf30e" alt="" width="100%">

### **Trustwallet** <a href="#trustwallet" id="trustwallet"></a>

To connect your wallet, you will need your phone. If you have a TrustWallet wallet, you should open the application on your smartphone then follow the next steps:

1. Click on **Settings**.
2. Click on **WalletConnect**.
3. Scan the QRCode on Tornado Cash's page.
4. Click on **Connect**.
5. You are now connected with Tornado Cash.

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2Fxq1GMbVZnS1Wu5wiurHb%2F3.gif?alt=media&#x26;token=9b3dff4a-f112-4ee2-83c2-195fede412f8" alt="" width="100%">

**ImToken**

To connect your wallet, you will need your phone. If you have a ImToken wallet, you should open the application then follow the next steps:

1. **Click** on the icon (top right).
2. **Scan** the QRCode on Tornado Cash's page.
3. **Click** on Connect.
4. You are now connected with Tornado Cash.

​

<img src="https://web.archive.org/web/20220617060938im_/https://1653446256-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MXflGk4w5pDjjlmPCuF-1972196547%2Fuploads%2Fgit-blob-ab2ef8495f71d08d4be99e6419dcf8b78f437a0c%2Fimtoken%20(1)%20(1).gif?alt=media" alt="" width="100%">

### **Argent Wallet** <a href="#argent-wallet" id="argent-wallet"></a>

To connect your wallet, you will need your phone. If you have a Argent wallet, you should open the application then follow the next steps:

1. **Click** on the Send (bottom right).
2. **Click** on the scan icon (top right).
3. Scan the QRCode on Tornado Cash's page.
4. You are now connected with Tornado Cash.

<img src="https://web.archive.org/web/20220617060938im_/https://1653446256-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MXflGk4w5pDjjlmPCuF-1972196547%2Fuploads%2Fgit-blob-0a6f020e2f9ebbb5943b562d3611939ff162c7ac%2Fargent%20(2).gif?alt=media" alt="" width="100%">

### **Other wallets** <a href="#other-wallets" id="other-wallets"></a>

For others wallets, steps might be really similar: **WalletConnect's QR code needs to be scanned in order to link your wallet to Tornado Cash.** Make sure to always check for a scanning icon (often located on the landing page or the settings section on your wallet's application).


# Deposit & Withdraw

Learn how to deposit and withdraw securely with Tornado Cash Classic. A step-by-step guide to ensure private, anonymous transactions on Ethereum

This tutorial is a step-by-step explanation of how to deposit & withdraw your funds. If you want to understand how the internal system of Tornado.cash works, please refer to this [tutorial](/tornado-cash-classic/how-to-connect-your-wallet).

<figure><img src="/files/MbP39dDJYtbGlhFO6abX" alt="Tornadocash - Deposit &#x26; Withdraw"><figcaption></figcaption></figure>

## **Deposit** <a href="#deposit" id="deposit"></a>

### Choose a chain <a href="#choose-a-chain" id="choose-a-chain"></a>

​[Tornado cash](https://tornadoeth.cash) is available on several blockchains, so you will have to choose among 4 chains:

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FDLOnYoROvGDvT1D0FD2e%2F4.gif?alt=media&#x26;token=d5c4fc62-665c-4b24-a4ce-1b70af551b0f" alt="" width="100%">

### Select a token <a href="#select-a-token" id="select-a-token"></a>

Choose the token you want to deposit and its amount:

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FGDzstfexn0c05DblQqIc%2F5.gif?alt=media&#x26;token=4e254e90-7a60-46be-814c-d802d01886ef" alt="" width="100%">

### Connect your wallet <a href="#connect-your-wallet" id="connect-your-wallet"></a>

Click on `Connect` and choose between wallet providers such as Metamask or WalletConnect.

### Save your note <a href="#save-your-note" id="save-your-note"></a>

Click on `Deposit` and store your note on a secure place before clicking on `I backed up the note`. You can also save encrypted notes on-chain by setting up a Note Account, by clicking on `Settings` (top-right corner).

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FWpwGXCn0zskt5FG6j2jB%2F6.gif?alt=media&#x26;token=3a9fc4d5-1ae7-4202-b1c4-e6456dcbbf24" alt="" width="100%">

### Be patient <a href="#be-patient" id="be-patient"></a>

As explained [here](https://tornadoeth.cash), the longer you wait, the greater your anonymity set will be.Congrats ! You did it. Now your tokens are on the Tornado.Cash pool.

## Withdraw <a href="#withdraw" id="withdraw"></a>

### Choose a chain <a href="#choose-a-chain-1" id="choose-a-chain-1"></a>

​[Tornado cash](https://tornadoeth.cash) is available on several blockchains, so you will have to choose among 4 chains:

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F5vdV9hF76FadrK3rgxHP%2F7.gif?alt=media&#x26;token=7dce650e-d16e-4c7a-881e-f50c5443754a" alt="" width="100%">

### Paste your note <a href="#paste-your-note" id="paste-your-note"></a>

Use your deposit note by pasting it in the corresponding box. Click on `Withdraw` and wait for the zk-Snark proof to be generated.

### Confirm the withdrawal <a href="#confirm-the-withdrawal" id="confirm-the-withdrawal"></a>

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FtNFO6ayP6zBlJY1VITNJ%2Fspaces_-MXflGk4w5pDjjlmPCuF-1972196547_uploads_git-blob-0347e76af7a41f12274bc8a38625aa0f71295531_abdaaaa.png?alt=media&#x26;token=1c8fd7aa-d7dd-4161-afba-6ba5eb168c1c" alt="" width="100%">

Done !


# Anonymity Mining

Discover how Tornado Cash Classic enables Anonymity Mining for private transactions. Learn the key steps and benefits of preserving financial privacy

<figure><img src="/files/IvcBHrdlbYT5XrHH1z13" alt=""><figcaption></figcaption></figure>

Anonymity mining is an incentive to increase the level of privacy in any coin-joining or coin-mixing protocols by rewarding participants anonymity points (AP) dependent on how long they hedge their assets in a pool.

*Tornado Cash anonymity mining program began on December 18, 2020 and has ended on December 18, 2021.*

Individuals deposit to any one of the anonymity pools that are supported (ETH, WBTC, DAI or cDAI) and are rewarded a fixed amount of AP per block, over the period their deposit remains in the pool. These points can then be exchanged for TORN once claimed.

<figure><img src="https://miro.medium.com/v2/resize:fit:720/format:webp/0*MmSDS1FXo6QEJTix" alt=""><figcaption></figcaption></figure>

### Anonymity points (AP) <a href="#anonymity-points-ap" id="anonymity-points-ap"></a>

*Readers should be aware some lower denomination deposits at the time of writing, do not produce a positive return due to the gas costs required to withdraw, redeem and exchange anonymity points*

One of the community members created the resource of a mining spreadsheet 13 that helps calculate annual percentage yield’s (APY’s) for each pool and each denomination set within, through estimating the fees required to claim a reward. **It is highly recommended to view this resource and plan one’s course of action before expecting to earn yield.** At the bottom of the spreadsheet, you can view each pool by selecting the associated tab.

### How to earn AP <a href="#how-to-earn-ap" id="how-to-earn-ap"></a>

1\. Decide what amount and asset to deposit by selecting it through the dropdown menu, before clicking on "Connect" and "Deposit".

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FAC8cbypPZumvqVfJgQH8%2F1.png?alt=media&#x26;token=c91cca3b-ca09-4d1d-94d3-a7939a2d7617" alt=""><figcaption></figcaption></figure>

2\. Take a record of your depositing note and back it up safely, **do not share this with anyone or risk losing your deposit and reward.**

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2Flh94x8fpe1ObanyFdUKn%2F2.png?alt=media&#x26;token=2e075ca4-29c0-4627-ae39-9836c766ff52" alt=""><figcaption></figcaption></figure>

3\. Generate the proof and submit the transaction.

4\. Your deposit should now be viewable on the bottom of the page, you can track how much AP it earns here; remember the longer your deposit remains active, the more AP you earn.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F2CKpIFa37h8tVt9MT1a2%2F4.png?alt=media&#x26;token=e7937ae9-79d9-4937-a6c5-645bdf836c3a" alt=""><figcaption></figcaption></figure>

*Notes that are active (not withdraw) are known as unspent notes.*

### How to claim AP <a href="#how-to-claim-ap" id="how-to-claim-ap"></a>

1\. First you must create a mining account and store those credentials on-chain for easy recovery (requires a transaction), **like depositing notes, you should never share your mining recovery key with anyone** and ensure to back it up in a safe place. This feature is not supported by hardware wallets so it’s encouraged to store the information as presented\_.\_

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F6eNNRnymk3kziBfCKkvz%2F11.png?alt=media&#x26;token=e0a38a23-5265-4953-9835-d1d325b4cbe3" alt=""><figcaption></figcaption></figure>

2\. Take an active deposit through providing an unspent note and withdraw to an address of preference and decide whether to use a relayer or not (*to maintain a deposit’s anonymity it is always advised to use a relayer*), this will bring the note into a spent state.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F6HKIef6GJgbNBp1IgCK9%2F22.png?alt=media&#x26;token=ffe4dee5-4a47-4c17-a6e5-5448d84ecbaf" alt=""><figcaption></figcaption></figure>

**Remember to still keep your depositing notes a secret even after withdrawing, as they still retain the ability to redeem AP.**

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FZhfCHxTBJpmzMNSDw1O5%2F23.png?alt=media&#x26;token=38f6f396-3795-4ec9-b883-2391b376f7a9" alt=""><figcaption></figcaption></figure>

3\. Visit the mining route of the application and enter your spent note, you may be faced with one of the following situations.

* **The ability to claim your spent note**: click the Claim reward button and submitting the transaction either by using a relayer or not, once confirmed your AP balance should update to reflect the action.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2Fy98KbLnkKJRy1oWIdNBz%2F33.png?alt=media&#x26;token=6b4b3577-8015-4c61-bd2d-934bd0e0ee1a" alt=""><figcaption></figcaption></figure>

* **The inability to claim a spent note:** *“Warning: The note is not yet ready for anonymity mining. You can wait few days before trying again"* - This means the Merkle trees are out of sync and require a transaction to be updated.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2Fq6hfUskw1H2imuckS2hI%2F1.png?alt=media&#x26;token=ec052abe-d81e-4ff2-af17-24dacc840598" alt=""><figcaption></figcaption></figure>

Updating the trees can be an expensive process, **it is recommended that users with small deposits wait for the larger miners to update the trees, this could take anywhere from a few days to a week**. If you want to view your event relative to the current pending batches. Click the *“Show mining note information"* hyperlink, here you can also pay the transaction fees to sync the tree relative to your withdrawal through the Update trees button.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FZrqfHsemSI8rGl4HRFLf%2F2.png?alt=media&#x26;token=10aa8762-b78d-4244-8aad-233619958f03" alt=""><figcaption></figcaption></figure>

### How to exchange AP <a href="#how-to-exchange-ap" id="how-to-exchange-ap"></a>

1\. Navigate over to the Swap tab on the mining page which can be accessed through the second navigation bar from the top of the page.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FyEQqfglqFx8vEWNuSj4P%2F1.png?alt=media&#x26;token=c9573183-fe89-4f4a-b368-d03e73aaede2" alt=""><figcaption></figcaption></figure>

2\. Enter the amount of AP requested to exchange or select the Maximum option to convert your active balance. Below this input, information regarding the current AP/TORN rate and reward output will be displayed. Provide an address of preference to receive the reward, finalise by generating the proof and submitting the transaction through a relayer or not.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FDvTy8f4WOS1O86veh5DG%2F2.png?alt=media&#x26;token=647946a0-6c79-49ab-9013-e349bbd3f96f" alt=""><figcaption></figcaption></figure>

3\. If all steps were followed correctly, TORN will be transferred to the address of preference provided in step 2 of this section.

### Closing remarks <a href="#closing-remarks" id="closing-remarks"></a>

Congratulations, you have successfully participated in anonymity mining!It is always recommended to plan when deciding to mine any of the anonymity sets, users should also be aware that the [AP/TORN rate](https://duneanalytics.com/luckyallocator/Daily-AP-TORN-Rate-v2) is dependent on supply and demand, therefore, **the more people that claim the higher the rate becomes, and the less people that claim the lower it becomes**.For more information on anonymity mining, seek the following resources:

* ​[Tornado.Cash governance proposal article](https://tornado-cash.medium.com/tornado-cash-governance-proposal-a55c5c7d0703)​
* ​[Tornado.Cash anonymity mining optimisation article](https://tornado-cash.medium.com/gas-price-claimed-anonymity-mining-a-victim-but-now-everyone-can-claim-ap-5441aaa32a1a)​​


# Compliance Tool

Discover the Tornado Cash Classic Compliance Tool. Ensure your transactions meet regulatory standards with our user-friendly interface

By design, everything is public on the blockchain, which can deprive users from their right to privacy. Anyone can have access to everyone’s whole transaction history. In response to this core problem,Tornado.Cash protocol allows cryptocurrency holders to earn back their privacy and gain anonymity. Indeed, it enables users to break the on-chain link between a source and a destination address.

However, maintaining privacy and preserving financial freedom should never come at the expense of non-compliance. The right of privacy lies in the ability to have control over the information we provide and to whom we provide it.

To this extent, **Tornado.Cash Compliance Tool enables users to prove the origin of their funds.** Thanks to the Note generated after each deposit, **this tool will issue a cryptographically verified proof of transactional history** using the Ethereum addresses used to deposit & withdraw assets.

You can visit the Medium post related to this tool to learn more about its development and launch: [**Tornado.Cash compliance Medium Post**](https://tornado-cash.medium.com/tornado-cash-compliance-9abbf254a370).

Therefore, if you are ever in need to prove the origin of held assets withdrawn from one of Tornado.Cash pools, we invite you to use the following [Compliance Tool](https://tornadoeth.cash/compliance):thumbsup:

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FdOVBJ85cOYMitWLWr3EK%2F3.png?alt=media&#x26;token=722c5168-9513-48da-942e-0436989ffb01" alt="https://tornadoeth.cash/compliance" width="100%">

## How To Use the Compliance Tool? <a href="#how-to-use-the-compliance-tool" id="how-to-use-the-compliance-tool"></a>

With each deposit made through the [Tornado.Cash app](https://tornadoeth.cash/), a new Note is generated by the protocol. This Note is necessary to withdraw the deposited assets later on any withdrawal address. It is this same Note that, if needed, allow users to generate a Compliance Report to prove the origin of their assets.

*More information about how to deposit & withdraw assets on Tornado.Cash are available on:* [*Deposit & Withdraw*](/tornado-cash-classic/deposit-and-withdraw)*.*

To get a Compliance Report, the user solely need to copy the Note, generated after the deposit, in the dedicated box.

### Before Withdrawal <a href="#before-withdrawal" id="before-withdrawal"></a>

If the Note wasn't spent yet (i.e. assets have still not been withdrawn), the Compliance tool will only provide you with information about the deposit:

* Transaction hash of the deposit;
* The source address;
* The Commitment hash.

The commitment is the hashed random area of bytes generated at each deposit that is sent to Tornado.Cash smart contract to characterize the transaction.

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FYwIojp071RibDIu0VYIW%2F4.png?alt=media&#x26;token=0ff903e0-6b06-408f-a964-b7d40d74158d" alt="https://tornadoeth.cash/compliance" width="100%">

*You can find more information about how Tornado.Cash achieve to provide privacy by reading* [*How does Tornado.Cash work?*](/generals/how-does-tornado-cash-work)*.*

### After Withdrawal <a href="#after-withdrawal" id="after-withdrawal"></a>

If the Note was spent (i.e. assets were withdrawn to a given address using the Note), the Compliance Tool will complete the information above by adding:

* Transaction hash of the withdrawal;
* The destination address;
* The Nullifier Hash.

The nullifier hash is a public input that is sent on-chain to get checked with the smart contract & the Merkle tree data to allow the withdrawal.

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F6jQ2sniNTJnxgDV7KvAn%2F5.png?alt=media&#x26;token=417e51dc-647e-4e05-bfb0-8da9d3b69599" alt="https://tornadoeth.cash/compliance" width="100%">

Therefore, the tool allows users to re-link source & destination addresses in order to prove transaction history for assets used on Tornado.Cash.

This information can also be downloaded under a PDF format, making it is easier to get sent to any desired third part:

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2F83kltt64T9gniFtaznSM%2F6.png?alt=media&#x26;token=f16cf280-6342-4c8a-b768-a0f35cb868b1" alt="https://tornadoeth.cash/compliance" width="100%">


# Circuits

Explore Tornado Cash Classic circuits to enhance your privacy and security in transactions. Learn how to use and configure with ease

Behind the Tornado.cash front-end sits a number of [Circom](https://docs.circom.io/) circuits, which enable the fundamental privacy guarantees that Tornado.cash users enjoy. These circuits implement the [Zero Knowledge protocol](https://en.wikipedia.org/wiki/Zero-knowledge_proof) that Tornado.cash's smart contracts interface with to prove claims about a user's deposit, such as that it is valid, that is hasn't already been withdrawn, and in the context of Anonymity Mining, the number of blocks that exist between a note's deposit transaction and its withdrawal.

### How ZK Circuits Work <a href="#how-zk-circuits-work" id="how-zk-circuits-work"></a>

#### SNARKs and GROTH16 <a href="#snarks-and-groth16" id="snarks-and-groth16"></a>

Before trying to understand how Tornado.cash works under the hood, you first need to understand Zero Knowledge circuits, how they're constructed, and how proofs are generated client-side, then verified on-chain. While there are a [few different types](https://en.wikipedia.org/wiki/Zero-knowledge_proof#Zero_knowledge_types) of ZK systems, Tornado.cash relies upon a variant known as "succinct non-interactive arguments of knowledge" (SNARK), specifically a variant called GROTH16.

#### Circom and snarkjs <a href="#circom-and-snarkjs" id="circom-and-snarkjs"></a>

Because we're not all Vitalik, it's best if we have some simple tools that will abstract away the generation and execution of these complicated polynomial commitments. This is where [Circom](https://docs.circom.io/) and [snarkjs](https://github.com/iden3/snarkjs) come in.

Circom is easiest to think of as a compiler for a circuit language which acts very much like the kind of [hardware description language](https://en.wikipedia.org/wiki/Hardware_description_language) that electrical engineers would use to describe an electrical circuit. Except instead of an electrical circuit, we're describing an **arithmetic circuit**, which contains components, and the way that they connect together.

When you compile a Circom circuit, the resulting output is an [R1CS constraint system](https://docs.circom.io/background/background/) and a [Wasm](https://en.wikipedia.org/wiki/WebAssembly) executable that will be used to generate a [witness](https://docs.circom.io/background/background/).

**R1CS**

To understand R1CS (Rank-1 constraint system), there is of course more math. And where there's important cryptosystem math, there's a [post by Vitalik](https://medium.com/@VitalikButerin/quadratic-arithmetic-programs-from-zero-to-hero-f6d558cea649#5539).

> An R1CS is a sequence of groups of three vectors(a, b, c)(a,b,c), and the solution to an R1CS is a vectorss, wheressmust satisfy the equations . a \* s . b - s . c = 0s.a∗s.b−s.c=0, where..represents the dot product - in simpler terms, if we "zip together"aaandss, multiplying the two values in the same positions, and then take the sum of these products, then do the same tobbandssand thenccandss, then the third result equals the product of the first two results.The next step is taking this R1CS and converting it into QAP form, which implements the exact same logic except using polynomials instead of dot products ... instead of checking the constraints in the R1CS individually, we can now check all of the constraints at the same time by doing the dot product check on the polynomials.If we try to falsify any of the variables in the R1CS solution that we are deriving this QAP solution from - say, set the last one to 31 instead of 30, then we get attpolynomial that fails one of the checks.

In short, the R1CS is a set of polynomial constraints which any proof generated by the circuit must satisfy. These constraints are [generated by Circom](https://docs.circom.io/circom-language/constraint-generation/) based on the relationship between various "signals" and operations in your circuit design.

**Witnesses**

Now, depending on what you're using Tornado.cash for, you might not want any witnesses. However, don't worry, if everything is working correctly, all of the witnesses to your interactions with Tornado.cash will be aggressively compacted, and their bodies disposed of as you please.

In the context of a SNARK circuit, a witness is the set of values that need to be generated from the inputs to the circuit, based on the circuit design, to satisfy all of the constraints imposed by the circuit. You can think of the witness generator produced by Circom as a circuit-specific decompression function which runs your inputs through the circuit, and snapshots all of the various intermediate values that are produced along the way.

With this expanded form generated from your inputs, you know which values must be assigned to the constraints specified by the R1CS in order to construct a valid proof.

**Proof**

When you think of a "proof", you probably imagine that it's an incontrovertible guarantee that something is true. However, in the context of a SNARK, a "proof" actually represents an *argument* that something is *almost certainly* true. If we were to try to transmit the solution to every single polynomial constraint imposed by a circuit, we would end up with proofs that were orders of magnitude larger than if we simply show that certain sorts of relationships hold true between the intermediate state values within the circuit.

It's possible that for any given circuit, someone with sufficient computing power could generate a proof that satisfies the circuit's constraints in a malformed way, but this would be roughly equivalent in difficulty to [factoring large primes](https://en.wikipedia.org/wiki/RSA_Factoring_Challenge).

So, when generating a proof for a SNARK circuit, you're calculating the intermediate states of your circuit for a given input (witness generation), and then calculating the relationships between your inputs, the intermediate states, and the circuit's outputs.

Once you have the proof that you've satisfied the necessary set of constraints, you can then publish that proof and some subset of your inputs and outputs (a.k.a. public signals). Knowing the R1CS, your public signals, your proof, and the circuit's proving key, anyone can then verify that your proof satisfies the R1CS, and that your public signals are what would be expected to correspond to your proof.

### Circuits <a href="#circuits" id="circuits"></a>

With that understanding of ZK proving circuits well-in-hand, let's delve into how Tornado.cash uses some relatively simple circuits to enable you to privately and permissionlessly obscure the relationship between your deposit and withdrawal transactions on a public blockchain network, and then to later prove things *about* the relationship between your deposit and withdrawal (e.g. how long you waited before withdrawing).

[Tornado.cash](https://tornadoeth.cash) is best understood as having two separate major components.

#### Core Deposit Circuit <a href="#core-deposit-circuit" id="core-deposit-circuit"></a>

The core deposit circuit is what most users interact with, proving that a user has created a commitment representing the deposit of some corresponding asset denomination, that they haven't yet withdrawn that asset, and that they know the secret that they supplied when generating the initial commitment.

[Core Deposit Circuit](#core-deposit-circuit)

#### Anonymity Mining <a href="#anonymity-mining" id="anonymity-mining"></a>

The anonymity mining circuits form the basis for the Anonymity Mining program, which incentivizes users to leave their deposits in the contract for longer periods of time, so as to ensure that the Tornado.cash deposit pools maintain a large number of active deposits (thus increasing [k-anonymity](https://en.wikipedia.org/wiki/K-anonymity) for other users).


# Core Deposit Circuit

Discover the Core Deposit Circuit of Tornado Cash Classic. Learn how it enhances privacy and security in decentralized finance

The core deposit circuit is what most users interact with, proving that a user has created a commitment representing the deposit of some corresponding asset denomination, that they haven't yet withdrawn that asset, and that they know the secret that they supplied when generating the initial commitment.

## Making a Deposit <a href="#making-a-deposit" id="making-a-deposit"></a>

A deposit into Tornado.cash is a very simple operation, which doesn't actually involve any ZK proofs. At least not yet. To make a deposit, you invoke the `deposit` method of a [Tornado contract](https://github.com/tornadocashdev/tornado-core/blob/master/contracts/Tornado.sol) instance, supplying a Pedersen Commitment, along with the asset denomination that you're depositing. This commitment is inserted into a specialized Merkle Tree, where the structure of the Merkle Tree is aligned to an elliptic curve associated with a prime in the order of the BN128 elliptic curve, and the labels of the tree are computed using MiMC hashing.

### Commitment Scheme <a href="#commitment-scheme" id="commitment-scheme"></a>

When you make a "commitment" in the context of cryptography, what you're doing is taking a secret value - often large and random - and running it through some cryptographic function (e.g. a hash function), then disclosing the result. Later, when you need to make good on the commitment, you prove that you know the original secret value.

### Pedersen Hash <a href="#pedersen-hash" id="pedersen-hash"></a>

A Pedersen Hash is an extremely specialized hashing function that is particularly well-suited for use in applications leveraging Zero Knowledge proving circuits. Where other hashing functions like SHA-256 are designed to exhibit properties such as producing very different outputs for even slightly different inputs (the avalanche effect), Pedersen hashing instead prioritizes the ability to compute the hash extremely efficiently in Zero Knowledge circuits.

Hashing a message with Pedersen compresses the bits of the message down to a point along an elliptic curve called Baby Jubjub. Baby Jubjub is in the order of the BN128 elliptic curve that is supported by precompiled operations on the Ethereum network which were added in EIP-196. This means that operations that use the Baby Jubjub curve, such as Pedersen Hashing, are highly gas-efficient.

When you compute the Pedersen hash of a message, the resulting point along the its elliptic curve is very efficient to verify, but infeasible to reverse back into the original message.

### Tornado Commitment <a href="#tornado-commitment" id="tornado-commitment"></a>

To generate a commitment for a Tornado.cash deposit, you first generate two large random integers, each 31 bytes in length. The first value is a nullifier that you will later disclose in order to withdraw your deposit, and the second is a secret that secures the confidential relationship between your deposit and withdrawal.

The preimage of your deposit note is the concatenation of these two values (`nullifier` + `secret`), resulting in a message 62 bytes in length. This message is Pedersen hashed, resulting in an output representing an element of the Baby Jubjub elliptic curve encoded as a 32-byte big-endian integer.

If you want to see this in code form, you can reference the [tornado-cli deposit function](https://github.com/tornadocashdev/tornado-cli/blob/master/cli.js#L53-L112).

### MiMC Merkle Tree <a href="#mimc-merkle-tree" id="mimc-merkle-tree"></a>

The [Tornado contract](https://github.com/tornadocashdev/tornado-core/blob/master/contracts/Tornado.sol) is a specialized Merkle Tree which labels its nodes using MiMC hashes.

For those not familiar with Merkle Trees, they are binary trees where each non-leaf node is labelled with the hash of the labels of its child nodes, and the leaf nodes are labelled with the hash of their data. Ordinarily, Merkle Trees use a one-way cryptographic hashing function like SHA-2, but in this case, we're using MiMC, which has some useful properties.

One of the useful properties of MiMC is that it's well-suited to operating over prime fields, which is important to us because Zero Knowledge proofs are fundamentally based on prime fields, and Pedersen Hashes are points within a prime field defined by the Baby Jubjub elliptic curve - which is in turn within the order of the BN128 curve supported natively on Ethereum. Because Zero Knowledge proofs are operationally expensive, and each operation in an Ethereum transaction has a corresponding gas cost, the specific types of operations we design around need to be as gas-efficient as possible.

The other particularly useful properties of MiMC are that it's non-parallelizable, and difficult to compute but easy to verify. These properties add to the security of the contract by making it computationally infeasible to calculate a forged "commitment" which has a colliding path within the merkle tree.

### Zero Nodes <a href="#zero-nodes" id="zero-nodes"></a>

During the initialization of the Tornado Merkle Tree, a single path spanning the height of the tree is preallocated starting with a "zero leaf" node with a label of `keccak256("tornado") % FIELD_SIZE`. Each subsequent non-leaf node toward the root is then labelled as if the entire bottom of the tree were populated by that same same leaf node.

The purpose of these "zero nodes" is to ensure that all paths within the merkle tree are invalid until they terminate in a valid commitment.

### Inserting a Commitment <a href="#inserting-a-commitment" id="inserting-a-commitment"></a>

When you insert a commitment into the Tornado contract's merkle tree, you are replacing a "zero leaf" with a new leaf whose label is the MiMC hash of your Pedersen commitment, and then traversing up the tree updating each subsequent parent node with a new label based on the label updates that your new leaf introduces below.

Commitments are inserted from left to right within the tree, with every two commitment insertions filling a "subtree". Each insertion increments the "index" of the tree, determining whether the next commitment will be inserted on the left or right side of the entry to its merkle path.

Once your deposit has updated the tree, the label of the top-most node becomes the tree's new "root", and is added to a rolling history containing the labels of the last 100 roots, for later use in processing withdrawal transactions.

The Tornado.cash deposit contracts are deployed with 20 "levels", with each level increasing the number of potential leaves by a power of 2. That means that the contract's merkle tree supports up to 2^20 leaves, allowing for up to 1,048,576 deposits to be made into the contract before it needs to be replaced.

The reason behind this seemingly-low number of levels is that every deposit has to perform as many updates to the tree as there are levels. A tree with more levels would require more gas per deposit, as well as correspondingly larger proof sizes when withdrawing notes.

## Making a Withdrawal <a href="#making-a-withdrawal" id="making-a-withdrawal"></a>

Having made a deposit, you now have a set of truth claims that you can generate a proof based upon. Generally speaking, Zero Knowledge proofs are anchored to some value(s) known by both the prover and the verifier, to which a relationship is going to be proven to a set of values known only by the prover. The circuit verifier can confirm that the prover has used the value(s) that are known, and that the proof that they computed satisfies the constraints imposed by the circuit.

### Inputs to a Withdrawal Proof <a href="#inputs-to-a-withdrawal-proof" id="inputs-to-a-withdrawal-proof"></a>

In the case of Tornado.cash deposits, the prover (the person submitting a withdrawal transaction), and the verifier (the deposit contract's withdrawal method) both know a recent merkle root. The prover also supplies a set of other public inputs that they used for the generation of their proof.

#### The total set of public inputs for a withdrawal proof are: <a href="#the-total-set-of-public-inputs-for-a-withdrawal-proof-are" id="the-total-set-of-public-inputs-for-a-withdrawal-proof-are"></a>

1. 1.A recent merkle root
2. 2.The Pedersen hash of the nullifier component from their deposit commitment
3. 3.The address of the recipient of their withdrawal
4. 4.The address of the relayer that they've selected (or their own address)
5. 5.The fee that they're paying the relayer (or zero)
6. 6.The refund that they're paying the relayer (or zero)

#### The additional private inputs for a withdrawal proof are: <a href="#the-additional-private-inputs-for-a-withdrawal-proof-are" id="the-additional-private-inputs-for-a-withdrawal-proof-are"></a>

1. 1.The nullifier component from their deposit commitment
2. 2.The secret component from their deposit commitment
3. 3.The set of node labels that exist in the path between the root and the leaf nodes of the merkle tree
4. 4.An array of `0/1` values indicating whether each specified path element is on the left or right side of its parent node

### Proven Claims <a href="#proven-claims" id="proven-claims"></a>

It would be easy to miss the clever new piece of knowledge we created when we constructed and inserted our commitment into the merkle tree. You might be inclined to think that to make a withdrawal, we're simply going to prove that we know the components of the Pedersen commitment, and that the merkle tree is just an efficient way to store those commitment hashes.

What's special about this construction is that it enables us to prove not just that we know the components of a deposited commitment, but rather it enables us to prove simply that we **know the path to a commitment within the tree**, and **how to get there** starting with a commitment preimage.

If we were only to prove that we knew the preimage to a deposited hash, we would risk revealing which commitment is ours. Instead, we're not disclosing the commitment preimage, but instead we're simply proving that we have knowledge of a preimage to a commitment within the tree. Which commitment is ours remains completely indistinguishable on the withdrawal side of the circuit protocol.

### Computing the Witness <a href="#computing-the-witness" id="computing-the-witness"></a>

**Nullifier Hash Check**

In order to compute the witness for the withdrawal proof, our circuit first takes the private deposit commitment inputs (`nullifier` + `secret`), and runs them through a circuit component which simultaneously computes the Pedersen hash of the full commitment message, and the Pedersen hash of the nullifier alone. The circuit then compares the resulting nullifier hash to the one you supplied as a public input, and asserts their equality.

**This proves that the nullifier hash that you supplied publicly is in fact a component of your original commitment.**

**Merkle Tree Check**

Next, the circuit takes the commitment hash it has computed, the merkle root you have specified publicly, and the path elements and left/right selectors that you specified privately, as inputs to a component which checks your merkle tree path claim.

The Merkle Tree Checker starts from the bottom of the path, inputting your commitment hash and the first element of your proposed path into a Muxer. The Muxer takes a third input, which is an element from your supplied left/right directions. The Muxer component uses these directions to inform an MiMC hashing component as to the order of its inputs. If the supplied direction is 0, then the supplied path element is on the left, and your commitment hash is on the right. If the direction is 1, then the order is reversed.

The MiMC hasher outputs the resulting hash, and the Merkle Tree Checker proceeds to the next level. It repeats the last process, except this time, instead of using your commitment hash, it uses the hash of the last level. It continues to run through each level of the proposed path, until it ends up with a final hash output.

The Merkle Tree Checker compares the hash that it has computed to the public merkle root input that you supplied, and asserts their equality.

**This proves that your commitment exists within some path beneath the specified merkle root.**

**Extra Withdrawal Parameter Check**

Before finishing, the circuit takes each of the remaining four public inputs, and squares them into a public output. While this isn't strictly necessary, it creates a set of constraints within your proof that ensure that your transaction parameters can't be tampered with before your withdrawal transaction is processed. If any of those parameters were to change, your proof would no longer be valid.

### Computing the Proof <a href="#computing-the-proof" id="computing-the-proof"></a>

Now that we have a witness for our proof, we take those witnessed state values and input them into the R1CS corresponding to the Withdrawal circuit, and run the prover over it. Out of the prover comes two proof artifacts. The first is the proof itself, according to the SNARK protocol we're using, and the second is the set of public inputs and outputs corresponding to that proof.

### Completing a Withdrawal Transaction <a href="#completing-a-withdrawal-transaction" id="completing-a-withdrawal-transaction"></a>

With the withdrawal proof now generated, you supply that proof, along with its public inputs, to the `withdraw` method of the deposit contract. This method verifies that:

1. 1.The specified relayer fee does not exceed the value of the denomination of asset being withdrawn
2. 2.The supplied nullifier hash has not been spent before
3. 3.The supplied merkle root is known, using the 100-root historical record
4. 4.The supplied proof is valid

One of the artifacts deployed as a dependency of the deposit contract is a Solidity contract that is generated using the proving key of the Withdrawal circuit as an input. This Verifier contract is an optimized proof verifier with a single public view function, which accepts a proof and the array of six public inputs as `uint256` values.

This function returns `TRUE` if the proof is valid according to the public inputs.

If the above preconditions are met, the supplied nullifier hash is inserted into the set of spent nullifiers, and then the value of the deposit is distributed amongst the recipient and relayer, according to the specified fee parameters.


# Logging in Tornado Cash Nova

Discover how to easily log in to Tornado Cash Nova. Step-by-step guide for secure access and optimal privacy on the platform

Launched in December 2021, Tornado Cash Nova offers the freedom to choose customized amounts for transactions, as well as the ability to transfer tokens without leaving the anonymity pool. With such unique features, this new pool requires its own set of instructions.

Tornado Cash Nova can be accessed through its own decentralized app at [nova.tornadoeth.cash](https://nova.tornadoeth.cash)

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FylJnwoz13CfwgWe1X1SX%2F1.png?alt=media&#x26;token=cafe866a-b992-4d7d-bba4-82e9be2405ea" alt="TORNADO CASH - NOVA" width="100%">

First of all, welcome to Tornado Cash Nova pool & let’s discover how this brand new tool functions 🌪

## Log In <a href="#log-in-nova" id="log-in-nova"></a>

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FaLsLN842moAeRQUgZwxF%2F2.png?alt=media&#x26;token=4532648f-25a6-4171-aed1-b9e5c2d37026" alt="TORNADO CASH - NOVA" width="100%">

You can log into your Tornado Cash Nova account either by:

* **connecting the MetaMask Wallet** with the address linked to your Nova account,
* **using the Shielded Key** that was generated alongside the creation of your account.

Each account is connected to a unique **shielded address** (as well as a unique **shielded key**) that can both be used to log in & manage your balance within the Nova pool.

### Tornado Cash Nova Account <a href="#tornado-cash-nova-account" id="tornado-cash-nova-account"></a>

Logging into the Nova pool will allow you to:

* **check your shielded balance** which represents the amount of tokens currently owned in the [Nova](https://nova.tornadoeth.cash) pool,
* **fund your balance** with further tokens,
* **transfer the custody of tokens** to another shielded address registered to the pool,
* **withdraw any desired amount of tokens** through the destination address of your chosing.

Only those who have access to your Metamask wallet or to your Shielded key will be able to access these informations regarding your account (i.e. your shielded balance).  ⚠ Be aware of which information you share with whom.

### MetaMask Wallet <a href="#metamask-wallet" id="metamask-wallet"></a>

Each Tornado Cash Nova account is linked to a shielded address. As mentionned above, users have two ways to access their account & its balance. One of these ways is **through a MetaMask wallet connected to the appropriate shielded address**.

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FTCfOev02KXD9sWlwKjw2%2F3.png?alt=media&#x26;token=e71c3154-9086-402a-84e0-3e6833fe19a9" alt="TORNADO CASH - NOVA" width="100%">

A shielded address is automatically created when users log in a given address, then deposit tokens to funds this address’ pool balance.

*More information about the Funding action is availaible on* [*Fund & Withdraw on Nova*](/tornado-cash-nova/fund-and-withdraw-on-nova)

However, shielded addresses can also be created from scratch as a separate action by logging in a new address with no prior link to Tornado Cash Nova, then by clicking on `Set up account`.

By confirming this action through your Metamask account, your shielded address will be crypted & created with the generation of a shielded key.

Once the account set, you will be able to receive shielded transfers of tokens from any another address registered to the pool. You will also be able to fund, transfer & withdraw tokens as you wish.

### Shielded Key <a href="#shielded-key" id="shielded-key"></a>

As seen above, the other way to log in is **through the generated Shielded Key** that is created when an account is created through the set up of a new shielded address.

Once you are logged in with your address & your account is set up, you can download this shielded key at any time by accessing your account data (by clicking on your address, next to your shielded balance).

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FTK9d5HVf981o5qK3idCX%2F4.png?alt=media&#x26;token=8710822c-9fd0-44c7-905d-9ca85cb8b0df" alt="TORNADO CASH - NOVA" width="100%">

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FwwVjvrfQcz2BdDMyDVbB%2F5.png?alt=media&#x26;token=6804a995-f265-4d02-bb9b-4a6f82e3f356" alt="TORNADO CASH - NOVA" width="100%">

To obtain full privacy, the same good practices that were recommended for traditional Tornado Cash pools are still required. *You can find guidelines to maintain privacy in the protocol’s documentation:* [*Tips to remain anonymous*](/generals/tips-to-remain-anonymous) *&* [*More anonymity tips*](/tornado-cash-nova/more-anonymity-tips)*.*


# Fund & withdraw on Nova

Learn how to fund and withdraw on Tornado Cash Nova. Step-by-step guide to secure transactions and privacy protection

Tornado Cash works by breaking the on-chain link between source & destination addresses. To do so, the protocol needs tokens to be deposited in a pool from one address, then to be withdrawn through another address.This principle remains the same for Tornado Cash Nova. As for traditional fixed amount pools, these two actions are core to the efficiency of the tool:

* The Funding process,
* The Withdrawing process.

## Funding Process <a href="#funding-process" id="funding-process"></a>

The great novelty compared to traditional Tornado Cash pools is that **deposited amounts are no longer predefined.** Users can choose a customized amount within the capacity of their wallet balance.

Therefore, if you want to put 0.4 ETH in the pool, you can do it all at once rather than making four separate transactions with the traditional 0.1 ETH pool.

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FkUAXOLh6R2FYbDk2Pjtv%2F6.gif?alt=media&#x26;token=eab20095-248d-4add-b226-3dca2b3bb703" alt="TORNADO CASH - NOVA" width="100%">

### How Does It Work? <a href="#how-does-it-work" id="how-does-it-work"></a>

#### **The First Deposit 💰** <a href="#the-first-deposit" id="the-first-deposit"></a>

* The first step is to log in Tornado Cash Nova through a Metamask account.
* Your account is not set yet (button `Set up account` available on the top right corner). To set up your account, you can either:
  * **Click on `Set up account`**: your logged-in address will be registered to Nova without needing to deposit any tokens. This action will enable you to receive transfers or deposits within the pool from any another address.
  * **Choose your logged-in address as a recepient address**: by depositing tokens into the pool, your account (with its shielded address & shielded key) will be automatically created. The deposited funds will come top up your shielded balance.
  * **Choose another registered address:** tokens will be added to the shielded balance of the chosen recipient address. This recipient address needs to be a shielded address that was formerly registered to the pool.

When you log in, the `Recipient address` is filled by default with your logged-in address. You can change it depending on how you want to use the tool.

If you set a new account, you will be able to log into the pool later, check your Tornado shielded balance or receive shielded transfers by using either your shielded address or shielded key.

*All information about how to use these elements to log in or where to find your shielded key are available on* [Logging in Tornado Cash Nov&#x61;*.*](https://nova.tornadoeth.cash)

#### **The following deposits 💸** <a href="#the-following-deposits" id="the-following-deposits"></a>

The following deposits answer to the same rules that the first one, except that the account is already set.

By logging into the pool with your shielded address / key, you can deposit your chosen amounts to your chosen shielded address as you wish to.

Since it is a beta version, deposits are currently limited to 1 ETH/transaction. However, if the community wishes to increase this limit, the 1 ETH cap amount can always be changed through a governance proposal.

## Withdrawing Process <a href="#withdrawing-process" id="withdrawing-process"></a>

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FCJHLOilVJPtY1zmmxBBE%2F7.gif?alt=media&#x26;token=d87addee-7989-4121-b7b7-e7b404507e1d" alt="TORNADO CASH - NOVA" width="100%">

To withdraw funds from the Nova pool, you can either:

* choose from a set of four predetermined amounts (0.1, 0.3, 0.5 & 1 ETH),
* choose a completely customized amount by going through the button `Set custom`.

### Custom Option For Withdrawal <a href="#custom-option-for-withdrawal" id="custom-option-for-withdrawal"></a>

**The custom option should only be chosen with full knowledge of the following facts and in complete confidence in your actions.**

To maintain your privacy, choosing one of the four suggested amounts is strongly recommended as it will allow your withdrawal to blend with the crowd.

Indeed, ddepending on the chosen amount, a connection might be deduced between your initial fund transaction and your withdrawal if:

* the initially funded amount & the withdrawn amount are exactly the same,
* the funded & withdrawn amounts can be easily linked through a sum.

*For instance, a deposit of 0.42 ETH can be linked to a withdrawal of exactly 0.42 ETH or two times 0.21 ETH, which might compromise anonymity. However, with a withdrawal of 0.391 ETH, privacy is better preserved as there is no obvious link between the 0.42 & 0.391 amounts.*

### Transctions through Gnosis Chain (L2) <a href="#transctions-through-gnosis-chain-l2" id="transctions-through-gnosis-chain-l2"></a>

For cheaper transactions, Gnosis Chain (former xDAI Chain) is used as a Layer-2. To this end, a bridge is used between ETH from the Mainnet & WETH from Gnosis Chain.

Therefore, to prevent spam attacks that will overload the bridge, the withdrawal amount has to be larger than 0.05 ETH.


# Shielded transfers on Nova

Learn how to perform shielded transfers on Tornado Cash Nova for enhanced privacy and security in your transactions

One of the specificity of Tornado Cash Nova is the introduction of shielded transfers. It allows shielded transactions of deposited tokens while staying within the pool.

So far, to transfer the custody of deposited funds, tokens needed to be withdrawn first. With Nova, you will be able to transfer a chosen amount of your shielded balance (not necessarily all of it) to another address without needing to withdraw them from the pool.

<figure><img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FO630zrse5dPVwaUDXXHk%2F8.gif?alt=media&#x26;token=56c68aff-6c04-4b58-a94b-0c8f4b89e4a9" alt=""><figcaption><p>TORNADO CASH - NOVA</p></figcaption></figure>

These shielded transfers can be made to any address of your choice, as long as this address is shielded (i.e. already registered to Tornado Cash Nova pool).

As a reminder, a shielded address is registered either through the `Set up account` action or alongside an initial deposit from a wallet address.

We advise you to double-check the shielded address to which you transfer tokens as this action is irreversible.


# More anonymity tips

Discover essential tips to enhance your anonymity while using Tornado Cash Nova. Boost your privacy and stay secure in the crypto world

For this section, we refer you to the [Tips to remain anonymous](/generals/tips-to-remain-anonymous) tutorial as a first step. All points mentioned in this tutorial still apply to Tornado Cash Nova.As a quick reminder, these tips include:

* Using of a VPN,
* Not sharing the shielded key or the access to this shielded address
* If downloaded, keeping this shielded key in a safe place,
* Deleting data after use,
* Avoiding the use of the same API token for all transactions,
* Being patient between the moment of deposit & withdrawal,
* Using multiple addresses for withdrawal.

However, with its new features, Tornado Cash Nova requires further precautions to maintain anonymity.

## Use of Relayers <a href="#use-of-relayers" id="use-of-relayers"></a>

Gas fees payments are necessary for transactions. For shielded transfers & withdrawals, two payment methods are available to provide ETH for gas fee. You can either **connect your wallet or use a Relayer**.

Going through your wallet for this gas fee can compromise the anonymity of the transaction if used ETH are linkable to your identity. Therefore, **it is recommended to use a Relayer to preserve privacy**

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FXgP01FOIUi0ofO4L54OI%2F9.png?alt=media&#x26;token=76e7569c-3831-4ca4-98ab-a7533eed0e78" alt="TORNADO CASH - NOVA" width="100%">

## Choice of Withdrawal Amounts <a href="#choice-of-withdrawal-amounts" id="choice-of-withdrawal-amounts"></a>

The customized amounts feature offers more flexibility & freedom of usage. However, it can compromise your privacy if used carelessly.

### Choosing predefined amounts for withdrawals <a href="#choosing-predefined-amounts-for-withdrawals" id="choosing-predefined-amounts-for-withdrawals"></a>

<img src="https://2754767501-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FW3U990Qef6L7w7eSM7Iw%2Fuploads%2FzjlLxXkO9g688aDYw4Wr%2F10.png?alt=media&#x26;token=b05ee109-6895-4178-bc15-0b9abc870870" alt="TORNADO CASH - NOVA" width="100%">

Choosing one of the four predefined amounts is strongly recommended as it will allow your withdrawal to blend with the crowd and remain anonymous.

You still have the freedom to `Set custom` to withdraw a customized amount of you choice. However, depending on the chosen amount, a connection might be deduced between your initial fund transaction and your withdrawal if:

* the initially funded amount & the withdrawn amount are exactly the same,
* the funded & withdrawn amounts can easily be linked through a sum.

For instance, a deposit of 0.42 ETH can be linked to a withdrawal of exactly 0.42 ETH or two times 0.21 ETH, which might compromise anonymity. However, with a withdrawal of 0.391 ETH, privacy is better preserved as there is no obvious link between the 0.42 & 0.391 amounts.

The custom option should only be chosen with full knowledge of these facts and in complete confidence in your actions.


# Articles

Library of articles, videos, news report and tutorials about Tornado Cash


# Videos

Library of articles, videos, news report and tutorials about Tornado Cash


