On August 12, 2022, the Dutch Fiscal Information and Investigation Service disclosed that it had arrested an unnamed 29-year-old man in Amsterdam on August 10 over suspected involvement with Tornado Cash. The FIOD said the man was suspected of helping conceal criminal financial flows and facilitate money laundering through the Ethereum-based mixing service, and that he was being brought before an examining judge on August 12.
The disclosure mattered because it moved the scrutiny of cryptocurrency privacy infrastructure from sanctions against a service to a criminal investigation involving an individual described by the agency as a suspected developer. The surviving event-day records did not establish guilt, identify the suspect, or show that writing privacy software alone was the alleged offense.
What Dutch authorities said
The FIOD said its Financial Advanced Cyber Team had opened a criminal investigation into Tornado Cash in June 2022. The agency described Tornado Cash as a service that could obscure the origin or destination of cryptocurrency and said investigators suspected it had been used to hide large-scale criminal flows, including assets taken in crypto hacks and scams.
The agency also said additional arrests were possible and that the investigation was being led by the Dutch Public Prosecutor’s Office for serious fraud, environmental crime and asset confiscation. Reuters independently reported the August 12 disclosure and said Tornado Cash had not responded to its request for comment.
Chronology is important. The arrest occurred on August 10; the authoritative public notice and the examining-judge appearance were dated August 12. This reconstruction therefore treats August 12 as the date the enforcement action entered the public record, not as the arrest date.
The numbers were allegations, not an audit
The FIOD said Tornado Cash had processed at least $7 billion since starting in 2019 and that at least $1 billion in cryptocurrency of criminal origin had passed through it. Those were the Dutch agency’s contemporaneous findings and suspicions. Its notice did not publish transaction hashes, an address set, asset-by-asset conversion rates, valuation timestamps, or a reproducible methodology.
A separate U.S. Treasury statement on August 8, 2022 used broader language, saying Tornado Cash had been used to launder more than $7 billion in virtual currency since 2019. Treasury attributed more than $455 million to assets stolen by the North Korea-linked Lazarus Group, more than $96 million to the June 24 Harmony bridge theft, and at least $7.8 million to the August 2 Nomad theft.
The two agencies’ descriptions should not be collapsed into one measured total. FIOD distinguished aggregate turnover from the amount it considered criminal in origin, while Treasury characterized the larger cumulative amount as laundered. Neither release supplied a common price source or exact measurement cutoff beyond the period from Tornado Cash’s 2019 launch to the respective August 2022 statement. Coinburn did not independently calculate those figures.
Sanctions and prosecution were separate tracks
On August 8, 2022, the U.S. Office of Foreign Assets Control designated Tornado Cash under a cyber-related executive order. Treasury said the action generally blocked U.S.-held property and prohibited transactions by U.S. persons involving designated property or interests in property unless authorized or exempt.
The Dutch investigation was a separate national criminal process. The event-day sources did not establish that OFAC ordered the arrest, that the two actions were coordinated, or that the examining judge had reached a final determination. Sanctions are administrative restrictions; an arrest and judicial presentation are steps in a criminal investigation. Neither is a criminal conviction.
What remained uncertain on August 12
The public record did not specify the suspect’s alleged acts, his level of control over Tornado Cash, the relevant transactions, or the precise legal theory connecting software development to the suspected laundering. It also did not separate legitimate privacy-seeking use from criminal use on a transaction-by-transaction basis.
The defensible event-day conclusion is narrow: Dutch authorities publicly confirmed a developer-related Tornado Cash arrest and judicial appearance while advancing serious but unproven money-laundering suspicions. That development raised immediate questions for protocol developers and privacy-tool operators, but the August 12 record did not answer where Dutch law would ultimately draw the line between publishing code, operating a service, and knowingly facilitating crime.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

