The freedom that isn't on the parchment
Every Fourth of July the country recites a list of freedoms — speech, press, assembly, the right not to have soldiers quartered in your house. There is one that is not on the parchment, because in 1776 it did not need to be: the freedom to build the tools of your own privacy. To forge a lock. To seal a letter with wax that shows if it was opened. To write, in the language a machine understands, an instruction that keeps a conversation between two people and no one else.
In 1776 that freedom was a craftsman's, and it was assumed. In 2026 the tools of privacy are software, software is written by developers, and developers can be arrested. So the freedom that used to be assumed is now the one on trial — not the freedom to have a private conversation, which a decade of encryption work has largely secured, but the freedom to make the thing that lets you have one, and to give it away, without being answerable for a stranger's crime.
Start with the victory: the country already answered this question once.
The precedent that won — and how narrowly
In the early 1990s the United States government classified strong encryption as a weapon. To publish the source code of a cipher was, in the government's view, to export a munition; it sat on the United States Munitions List alongside rifles and warheads. A mathematics graduate student at Berkeley named Daniel Bernstein wrote an encryption system he called Snuffle, and when he tried to publish the source code and a paper explaining it, he was told he would first have to register as an arms dealer and obtain a State Department export license. With the Electronic Frontier Foundation behind him and Cindy Cohn as lead counsel, Bernstein sued.
He won, and the language is worth keeping. In 1999 a panel of the Ninth Circuit Court of Appeals held that source code is speech protected by the First Amendment, writing that "cryptographers use source code to express their scientific ideas in much the same way that mathematicians use equations or economists use graphs." The district judge, Marilyn Hall Patel, had put it even more simply: "like music and mathematical equations, computer language is just that, language, and it communicates information." Together with the sibling ruling in Junger v. Daley, where the Sixth Circuit held in 2000 that source code is "an expressive means for the exchange of information and ideas," and the quiet collapse of the government's three-year grand-jury investigation of Phil Zimmermann for releasing PGP, the cases won the first Crypto Wars. They are the legal foundation of civilian strong cryptography — of HTTPS, of PGP, of Signal, of the encryption the European Union's Chat Control campaign failed to break when the Council pulled its vote last autumn.
But be honest about the win, because its exact shape is the whole story. The celebrated Ninth Circuit opinion was vacated: the government sought rehearing before the full court, which withdrew the panel decision, and then the administration relaxed the export rules and mooted the case. The most-quoted sentence in the history of the code-is-speech doctrine lives in a withdrawn opinion. The durable precedent is Junger. And the freedom itself came as much from a policy choice — the Commerce Department's rewrite of the export rules in January 2000 — as from any court order. What one administration relaxed, another can re-tighten.
More important still: the courts protected the freedom to publish code as expression. They never held that every act performed with software is speech. You may write the cipher and post it and teach it; that is protected. Whether you may run the service, operate the tool, or take a fee while strangers move value through it — that question the Crypto Wars never answered. And that unanswered question is precisely the seam the government has spent 2026 working.
Two freedoms in one tool
A privacy tool needs two freedoms, and the movement spent its decade defending one.
The first is the freedom to publish — to write the algorithm and release it as expression. Bernstein and Junger won that, and it is largely secure. No American court is going to hold that posting the source of a cipher is a crime.
The second is the freedom to run — to deploy the tool, operate the service, and let people use it without the author being on the hook for what they do with it. That freedom was never squarely won, and in 2026 it is being lost. Because the government learned the lesson of the Crypto Wars: do not try to ban the math, which is expression and which the courts protect. Prosecute the human being who deployed it, under a law written for banks. Recast conduct with code as the crime, and Bernstein never enters the courtroom.
Watch the move happen three times.
They could not stop the contract
Tornado Cash is not a company. It is a set of autonomous, immutable smart contracts running on Ethereum — code that holds no user funds, has no operator, and, once deployed, cannot be altered or switched off by the people who wrote it, any more than the author of a lockpicking manual can reach into a burglary. That fact is not decoration; a federal appeals court has ruled on it. In November 2024, in Van Loon v. Department of the Treasury, the Fifth Circuit held that Tornado Cash's immutable contracts are not "property" that anyone can own or control, and that the Treasury had therefore overstepped its authority when it sanctioned them. Treasury delisted the protocol in March 2025.
And yet, in the same window, the Justice Department put the protocol's co-founder on trial. In August 2025 a Manhattan jury convicted Roman Storm of conspiracy to operate an unlicensed money-transmitting business — a five-year count — while deadlocking on the two grave charges, conspiracy to launder money and to violate sanctions, that each carry up to twenty years. Storm moved to be acquitted. In March 2026 the government asked to retry the hung counts, proposing a start in October. At the April hearing, Judge Katherine Polk Failla pressed the government hard: when its lawyer argued that even serving law-abiding users could be money laundering — because clean money makes a mixer better at hiding dirty money — she cut in, "You were doing better before you started talking." As of this Fourth of July she has not ruled, no retrial date is set, and Storm is free on bail.
The First Amendment defense — that Storm published protected code — was raised before trial and rejected. Judge Failla held that code's functional capacity is not protected expression, and she barred both sides from arguing the First Amendment to the jury at all. That is the seam: not "you may not publish this," which the state would lose, but "you ran this, you transmitted value," which sidesteps Bernstein entirely.
Honesty requires the hard part, because this is not a clean martyr. The government alleges more than a billion dollars in criminal proceeds moved through Tornado Cash; the forensic firm Elliptic put identified illicit funds at about $1.5 billion out of some $7 billion total — roughly a fifth. North Korea's Lazarus Group ran the $455 million it stole from the Ronin bridge through the mixer. Storm and his co-founders cashed out more than $12 million. A mixer concentrates crime more than a browser does — that is the honest part, and it should be conceded plainly. But concentration is a fact about users, not a reason to jail the author. The theory that convicts Storm does not stop at bad actors: it holds a developer criminally liable for the functional use of general-purpose code he could not switch off. By that logic the maker of any dual-use technology answers for its worst user. The question is never whether a privacy tool is ever used for crime; every useful tool is. The question is whether we prosecute the maker for it. For two hundred years the answer was no.
The memo the prosecutors ignored
If Storm is the contested case, Samourai is the cleaner one.
Samourai Wallet was designed to be non-custodial — users held their own keys, and the software was built so it never took custody of anyone's coins. Its two contested features were Whirlpool, which mixed users' coins to break the chain of traceability, and Ricochet, which added hops to obscure a trail. Its founders, Keonne Rodriguez and William Hill, were arrested in April 2024, pleaded guilty in July 2025 to a single count of conspiracy to run an unlicensed money-transmitting business, and were sentenced last November: Rodriguez to five years — the statutory maximum — and Hill to four. The government's theory is that Whirlpool's coordinator functionally controlled and re-transmitted value, and that the two men knowingly courted criminal users; the defense says the wallet was strictly non-custodial and squarely legal. Because both pleaded, no court ever ruled which is right. Two developers who wrote and shipped privacy software are in prison, and the central legal question never got an answer.
They are in prison despite the Justice Department's own written policy. In April 2025 the Deputy Attorney General, Todd Blanche, issued a memo titled "Ending Regulation By Prosecution," disbanded the crypto-enforcement team, and stated in plain words that the Department "will no longer target virtual currency exchanges, mixing and tumbling services, and offline wallets for the acts of their end users." Then it kept targeting them. The Storm and Samourai prosecutions rolled on; the government told a court it would pursue Storm regardless. And they are in prison despite Treasury's own guidance, on the books since 2019, that a non-custodial software wallet provider is not a money transmitter at all. The government reached past its own memo and its own rulebook by leaning on a single word — willful — and arguing that these particular developers knew who was using their tool. A safe harbor that evaporates whenever a prosecutor decides it should was never a safe harbor.
That so many in Congress now think the law needs rewriting is the measure of how far the ground has shifted. In February 2026 a bipartisan bill, the Promoting Innovation in Blockchain Development Act, was introduced to amend the money-transmission statute so it reaches only those who actually "exercise control over" customer funds — which is to say, to restore the distinction between building a tool and operating a bank that prosecutors had read out of the law. It takes a bipartisan act of Congress, in 2026, to re-state the thing the Crypto Wars supposedly settled: that writing code is not running a money-transmitting business.
Legality is not availability
The third instance of the move is financial, and it does not require a courtroom at all.
No one has banned the mathematics of Monero or Zcash. What regulators did instead was quieter and more effective: they cut off the on-ramps. Under the Financial Action Task Force's "travel rule," now law in more than fifty jurisdictions, a regulated exchange must attach verified sender-and-recipient identity to every transfer — which a coin engineered for privacy makes technically impossible. So the exchanges walked. By one industry tally, roughly seventy-three of them delisted a privacy coin during 2025; OKX, Binance, and Kraken had already dropped Monero in 2024. The European Union's new Anti-Money-Laundering Regulation goes further, forbidding regulated institutions from touching "anonymity-enhancing coins" at all as of July 1, 2027. The coins remain perfectly legal to own — a private, self-hosted transfer between two individuals is explicitly outside the ban. But the venues where a normal person could buy or sell one are closing, one compliance decision at a time.
This is the market-access version of prosecuting the tool, and it produces a right that survives on paper and dies in practice. You may lawfully hold Monero and be unable to lawfully acquire it anywhere you also keep a bank account. Legality is not availability. And the instructive coda is Zcash, the privacy coin now rising precisely because it built in a door: its "view keys" let a holder selectively disclose a transaction to an auditor. The privacy tool that survives the squeeze is the one that comes with a way for the authorities to look inside — which is to say, the compliant version of privacy is, by construction, less private. That is the bargain now on offer everywhere: privacy you may keep, so long as it is not private from the state.
Prosecute the tool, excuse the hoard
This is not about ideology. It is about where a government points its power.
While the state spent the last twelve months prosecuting the builders of tools designed so that data need never be collected, the custodians who collect everything have been losing it at a scale with no modern parallel — and not one of them sits in a defendant's chair.
The instrument was a single vendor. Since August 2025, the extortion group Clop has exploited a critical flaw in Oracle's E-Business Suite software, ransacking the organizations that run it: Harvard, the University of Pennsylvania, the University of Phoenix (nearly 3.5 million people), Dartmouth (Social Security numbers and bank details), the Washington Post, Logitech, Schneider Electric, and dozens more. This spring a second group, ShinyHunters, exploited a different critical flaw in Oracle's PeopleSoft software and, by Google's count, compromised more than three hundred systems across a hundred-plus organizations, most of them universities. Then, in late June, a third critical Oracle flaw began to be exploited in the wild, and by July 2 researchers were tracking more than nine hundred exposed Oracle systems still open to attack. The wreckage in a single week's breach roundup: 14.22 million email logins at six Japanese carriers; Nissan employees' Social Security and bank details across four countries; more than nine million medical records — names, birth dates, Social Security numbers, health information — from the device maker Medtronic.
Now set the two ledgers side by side. On one, a developer who built a tool that holds nothing — no custody, no honeypot, no database to lose — faces five to forty-five years. On the other, institutions that hoarded everything and secured none of it lost the identity records of hundreds of millions of people. Those custodians will face breach lawsuits and regulatory fines, as they always do — but no executive faces the personal criminal exposure that a non-custodial-wallet developer does. No one has been charged so far. And the obvious objection — that the custodians are victims of a third-party crime, and the law does not jail you for being robbed — is fair, and answerable: negligence that spills a hundred million identities is itself conduct, and we criminalize far less dangerous negligence every day. The point is not that a breach equals running a mixer. It is that only one side of this ledger carries any personal criminal risk at all.
A relayer fee on an autonomous contract is conduct — fine. But so is warehousing a hundred million Social Security numbers on an unpatched server. The functional-versus-expressive line the government draws against privacy developers is real; the courts have drawn it since the DVD-decryption cases of 2001. The scandal is not that the line exists. It is that the line falls only on the privacy side of the ledger.
The domestic mirror
You can watch the same logic operate, more gently, inside the "protective" laws that took effect on this very July 1.
Some are genuine gains, and honesty credits them: Connecticut's amended privacy act now treats your brainwave data and your government-ID numbers as sensitive and, in a first, makes companies disclose whether they train large language models on your data; the Supreme Court, in Chatrie on June 29, held that pulling your phone's location history is a Fourth Amendment search. Those are statute and constitution doing what user-side tools cannot.
But look at the mechanism of the age-verification wave, and the pattern reappears. The interest is real — protecting minors is a serious concern, and the Supreme Court blessed age checks 6–3 in last June's Free Speech Coalition v. Paxton. What it did not bless is the mechanism: to keep minors off a platform you must check the age of everyone, which means every adult proving who they are to reach lawful speech — anonymity itself recast as a compliance failure. It is telling where the pushback lands. Two days before Nebraska's social-media age-verification law was to take effect, a federal judge enjoined it, holding it likely violates the First Amendment rights of users and platforms. The same doctrine that made code speech in Bernstein is now protecting the reader's right to arrive unidentified. And in a Manhattan courtroom the opposite instinct is on display: a judge has ordered OpenAI to preserve chats its users had deleted and to hand twenty million de-identified conversations to litigants — data minimization run in reverse, the hoard enlarged by court order. When the custodian invoked its users' privacy, it lost. When the developer invoked "code is speech," he lost too. The through-line holds: the small actors who build and read get policed; the megahoards get subpoenaed into growing.
The developers who left
There is a cost to all this that shows up in no docket: the quiet emigration of a field.
Last November, GrapheneOS — the hardened mobile operating system that is one of the open-source world's crown jewels — pulled its servers out of France and told its developers not to travel to or work in the country. "France isn't a safe country for open source privacy projects," the project wrote. "They expect backdoors in encryption and for device access too." The precise facts matter, and they cut deeper than a ban would: France did not outlaw GrapheneOS, and in March 2025 the French National Assembly actually rejected a proposed encryption backdoor. GrapheneOS left anyway — precautionarily, because the climate around it had become frightening enough that leaving seemed prudent. That is the tell. You do not need to outlaw a privacy project to drive it out. You only need to make its developers fear travel and its infrastructure fear its host. The chilling effect is not a side effect of prosecuting toolmakers; it is the effect. A country that treats the authorship of privacy software as presumptively suspect loses the authors — to anonymity, to other jurisdictions, to silence — and it loses them before it ever wins a case.
The counter, layer by layer
So what actually holds on July 4, 2026? The honest accounting splits cleanly.
Where the open-source stack wins — confidentiality and routing. The content layer is strong and getting stronger. Signal ships end-to-end encryption by default to tens of millions and has hardened its ratchet against tomorrow's quantum decryption; Tor and the hardened mobile baselines keep the device and the transport sound; GrapheneOS is expanding beyond Pixel hardware onto Motorola phones; URnetwork's peer-to-peer overlay carries traffic across a censorship-resistant, DPI-resistant path that binds no transport to a registered identity; Zcash's shielded pool keeps growing. Against an adversary who wants to read your message or block your route, these work — and they are exactly the tools that minimize what any custodian can hoard. The Oracle cascade is the argument for them: you cannot lose the Social Security number you were never asked to collect.
Where it runs out — the developer and the on-ramp. Against an adversary who wants to prosecute the person who wrote or ran the tool, or to delist the exchange that would let you use it, the same stack thins to almost nothing. There is no client-side primitive that defeats a money-transmission indictment; encryption does not un-charge a developer; a peer-to-peer overlay routes around a network block but cannot route around a courtroom or a compliance department. This frontier is not defended by code, because it is not a technical problem. It is defended — if at all — by the argument that publishing a tool is protected expression, by a statute like the blockchain-development bill that restores the line between building and operating, and by a public that refuses to accept that the authorship of privacy is a crime. We are strong exactly where we organized — the math, the protocols, the confidentiality of the message — and weak exactly where we did not.
Written, not committed
The distinction the whole edition defends is old, and the country used to understand it. The person who forges a key is a criminal; the locksmith who taught the class is not. The person who launders money is a criminal; the mathematician who published the cipher is not. The person who robs the bank is a criminal; the maker of the getaway car's tires is not. Writing and publishing a tool is not the same as committing the crimes someone might commit with it — and every dual-use technology in history, from the printing press to the pocketknife to end-to-end encryption, depends on that line holding.
On July 4, 2026, the line is where the fight is. Confidentiality we know how to defend; we proved it again this year. The freedom to build the defenses — to write the code, run the tool, and not answer for a stranger's crime — is the one now on trial, and it is the freedom the Fourth Amendment cannot protect on its own, because it is not about what the government may search. It is about what a citizen may make.
A tool was written. A crime, if there was one, was committed by someone else. A country that can no longer tell those two acts apart will keep the encryption and lose the encryptors — and then, soon enough, lose the freedom the encryptors were building: the freedom to speak, to read, to associate, and to transact without first asking permission. That freedom is not on the parchment. It has to be defended anyway, and this is the year.
Writing a tool is not committing a crime. Privacy is not a crime. That distinction is the whole of it — and the freedom to write the tools of a free society is the freedom the next decade will be spent winning back.
URnetwork is a peer-to-peer overlay for censorship-resistant transport, designed to resist network-layer Deep Packet Inspection; its February 2026 MCP server release lets agentic clients establish VPN sessions over the peer-to-peer overlay, abstracting transport from the carrier layer. Its code is open and auditable — published, in the exact sense this edition defends, as protected expression. It is a confidentiality-and-routing tool, honest about its limits: it protects what you say and how you connect, and, like all such tools, it cannot by itself defeat a prosecution of the person who wrote it — which is why this edition argues the freedom to build privacy has to be defended in courts and statutes as well as in code.
https://ur.io