Tornadocash: Who Can Recover a Deposit Note—and Who Cannot

A Tornado Cash deposit can only be proven for withdrawal with the correct private note and a matching, unspent pool record. Wallet access, a transaction hash, screenshots, and a remembered deposit amount do not replace that note. This distinction explains most apparent “stuck funds” cases before anyone searches for a recovery service.

A valid note is the recovery credential

The important distinction is between evidence that a deposit happened and the secret that authorizes a withdrawal. In the fixed-amount pools, the private note contains the material used to create a zero-knowledge proof. The contract checks that proof against its Merkle tree and checks a nullifier so the same deposit cannot be spent twice.

The protocol documentation describes the role plainly:

“This private note works as a private key for the user to access those funds later.”

That is why the note must be treated like a signing credential, not like a receipt. Anyone who possesses it may be able to produce the required proof; someone without it cannot recreate the secret from public blockchain data.

3 records that look useful but cannot replace the note

What remainsWhat it establishesCan it authorize a withdrawal?Who it helps
Private deposit noteControl of the deposit secretPotentially, if it matches an unspent supported poolA person assessing a genuine recovery path
Wallet seed phraseControl of the depositing addressNoA person recovering their wallet, not the pool secret
Transaction hashThat an on-chain transaction occurredNoA person verifying the deposit details
Screenshot or deposit amountPossibly a memory aidNoRecord-keeping only

The first option fits a person who retained the full note exactly. A transaction hash fits someone who needs to identify the chain, contract, asset, denomination, and transaction status, but it does not expose the secret preimage required by the proof system. A seed phrase may recover the original wallet, yet fixed-pool withdrawal is designed to be made to a different address, so wallet control is not the deciding credential.

An unspent matching pool is the second condition

Even a correctly saved note is not a universal key. It corresponds to a particular deployment, network, asset type, and—in fixed pools—denomination. A note from one pool cannot be applied to another merely because the amounts look similar. A prior successful withdrawal also leaves a nullifier on-chain, making a second claim fail as already spent.

Before assuming a technical problem, the person should compare the note’s chain and pool details with the original deposit transaction. They should also check whether the transaction actually succeeded rather than relying on a wallet’s pending or failed display. Those checks narrow the issue without disclosing the note to anyone.

4 failure states that require stopping, not improvising

  • The note is missing: there is no cryptographic substitute. Treat offers to “rebuild” it from a hash or wallet address as suspect.
  • The note was shared: control may already be compromised. Do not paste it into support chats, forms, or browser extensions.
  • The chain or pool does not match: re-check the original transaction before using any interface.
  • The note appears spent: inspect the transaction history and seek qualified legal or technical help before taking further action.

Legal restrictions, sanctions rules, exchange policies, and interface availability can also change what actions are permitted or practical in a person’s jurisdiction. A cryptographic capability is not legal clearance, and no general article can determine that question for a particular person.

One careful next step when the note still exists

Someone who still holds an unshared note should first preserve it offline, verify the original transaction independently, and avoid entering it into unfamiliar tools. A practical reference point is Tornadocash, where the relevant pool and note-handling information can be reviewed before any decision is made.

If the note is absent, the honest conclusion is usually not “try another interface.” It is that the secret needed to prove control is unavailable. Keeping that boundary clear prevents wasted fees, false recovery claims, and accidental disclosure of the one record that matters.

2 short questions people still ask

Can a deposit be recovered from the wallet that made it?

No. The wallet may prove ownership of the depositing address, but it does not replace the private note for a fixed-pool withdrawal.

Does a transaction hash reveal the private note?

No. The hash can identify the public deposit transaction, while the secret used for the withdrawal proof remains private.

Leave a Reply

Your email address will not be published. Required fields are marked *