Privacy protocol Umbra shuts down its front-end UI after detecting $800,000 in stolen Kelp funds routed through the platform; Tornado Cash's Roman Storm doubts the measure will satisfy US authorities.
Security & Exploits ·
Privacy protocol Umbra disabled its front-end interface after $800,000 in funds stolen from Kelp were traced through its system. The protocol noted that its design protects recipient privacy rather than sender anonymity, making it unsuitable for obscuring illicit flows. Umbra stated that all stolen assets routed through the platform remain identifiable and that the team has coordinated with security researchers on the matter.
However, the measure may prove insufficient to shield Umbra from regulatory scrutiny. Roman Storm, co-founder of mixer Tornado Cash, warned that disabling a user interface is unlikely to satisfy authorities, arguing that prosecutors view interface control as equivalent to protocol control. Storm was convicted in August on charges related to operating an unlicensed money transmitting business and noted that changing a front end, including updates via IPFS, signals full command over the system. Umbra acknowledged it cannot prevent users from accessing its smart contracts directly or running self-hosted or local versions of its open-source front end, leaving the underlying infrastructure intact.
Whether regulators will accept the shutdown as meaningful cooperation or pursue enforcement against Umbra remains unclear. The incident underscores tensions between protocol-level decentralization and operator-level liability in privacy-focused infrastructure.