8 ms·
De-anonymization attacks against the privacy coin XMR
- TarikHassan3 1y agoGreat article, and I'm glad to see privacy being a focus in a cryptocurrency, but I would like to see some other sources that aren't also promoting the token. That said, I do think it's got the brightest future of any coin besides BTC for the very reason.
- stuxnet79 1y ago> That said, I do think it's got the brightest future of any coin besides BTC for the very reason. Brightest future in terms of what? Traction? Market cap? This is what I thought 7 years ago, and I beefed up my XMR position as a result. Meanwhile, Bitcoin an objectively inferior technology, has 25x since then.
- candiddevmike 1y agoPreface this by saying I am not a fan of any cryptocurrency, but I really struggle to understand why Monero has a smaller market cap than BTC. It has to be inertia related right? Monero just seems like a fundamentally better piece of technology. Are there scaling issues with Monero, similar/worse than BTC?
- dboreham 1y ago> better piece of technology Technology quality is uncorrelated with market cap. This would be like saying Frontier Airlines should have a higher market cap than United because one uses Linux and the other is still on mainframes..
- PokedBear 1y agoIt doesn't need a lot of speculative value in order to be useful. It just needs enough value to make the transactions meaningful. And that means people are a lot less likely to drive up the price via speculation.
- ujkhsjkdhf234 1y agoBTC is not about usefulness. The Bitcoin community has abandoned all of the original principles that made them. It is now just about line goes up and make money.
- MoneroDotForex 1y agoThe Monero community is the one that at least tries to emulate to Satoshi's Bitcoin.
- tromp 1y agoYes, it scales much worse: * node resources scale with the size of the UTXO set (unspent outputs), which in Monero's case balloons to the entire TXO set (all outputs, orders of magnitude larger) * a typical 2-input 2-output transaction is 4 times larger * wallets have to track all outputs to choose random decoys for transaction inputs One can argue that this is the price to pay for significantly better privacy, but the largest benefits come from having no visible amounts or addresses, which can be achieved with significantly better scalability than BTC [1]. [1] https://forum.grin.mw/t/scalability-vs-privacy-chart/8114 https://forum.grin.mw/t/scalability-vs-privacy-chart/8114
- coldblues 1y agoTari uses Mimblewimble (privacy coin developed by previous Monero devs with a focus on privacy), so we're not far from being able to benefit from it.
- proxynoproxy 1y agoDon’t forget that opaque blockchains can have invisible inflation. Transparent blockchains will always be worth more, as the user can verify that inflation has not occurred. This applies to grin as much as xmr.
- beeflet 1y agoIn opaque blockchains, the mechanism that prevents inflation is the same mechanism that prevents double-spending. The user can verify that inflation has not occurred by running a monero node. Everything considered, I don't think that the risk of a monero inflation bug is greater than a bitcoin inflation bug when you consider the complexity associated with scripting.
- tromp 1y agoIndeed that is one downside of hiding amounts, as shown in row "Fully auditable supply" in [1]. Finding out just one discrete log (log_G(H)) can collapse the whole system with undetectable inflation. [1] https://phyro.github.io/grinvestigation/why_grin.html https://phyro.github.io/grinvestigation/why_grin.html
- short_sells_poo 1y agoMindshare and hype tend to be self reinforcing and create their own gravity. BTC has the largest market share because it has the largest market share. The moment it got derivatives and ETFs listed and traded on major US exchanges (e.g. CME futures), it became the clear winner because if you are a hedge fund and want to get on the crypto bandwagon, it's easily accessible, liquid and doesn't require extra paperwork. So you trade that instead of going on some unregulated exchange where you might end up as a news headline of "Hedge Fund loses money in crypto exchange exit scam".
- im3w1l 1y agoOne important factor is that Monero are printed at a constant rate, unlike BTC that are printed at an exponentially slowing rate. A constant rate of printing means the supply is uncapped but the inflation rate will approach zero. Monero's choice is arguably better for actual use as a currency, as the printing will prevent deflation from lost coins. But it makes it less attractive as an investment.
- wkat4242 1y ago> But it makes it less attractive as an investment. For me that's a feature not a bug. The investor cryptobros have thoroughly killed the interest in BTC as a real payment method and made it just a vaporware pyramid scheme. They have accumulated a lot of influence. Also they corrupted the whole idea behind bitcoin which was independence from the old centralised banking system where others control your money. To guarantee their investments they've rebuilt the whole old system in bitcoin with the exchanges and some regulators even demanding you use them to store your BTC.
- piracyrules 1y ago[dead]
- deleted 1y ago[deleted]
- sfjailbird 1y agoIsn't BTC privacy achievable these days with coinjoin, lightning network etc.? In that case no much reason for monero.
- tsimionescu 1y agoIt still seems fantastical to me that lightning network is presented as "something running on BTC", when it is "something running completely separately, instead of BTC". Transactions on Lightning network are not transactions on BTC, and have none of the guarantees of BTC (and in fact have no reliable guarantees of no double spending). The only way to get BTC-like guarantees of no double-spending for Lightning network transactions is to put every transaction on the BTC block chain ("close the channel" after every transaction). And then, of course, you get back all of the problems of BTC (minuscule TPS not enough for a small village, 0 privacy, huge energy costs).
- swores 1y agoIf what tsimionescu says about Lightning is wrong, can somebody kindly reply to them explaining why rather than just downvoting which doesn't help anyone. (Maybe there's a reason they were downvoted that isn't their being wrong, but I don't see what that would be.) (And sorry for going against the guidelines and talking about downvotes, but I'm really just asking for someone to either confirm what they said is right or explain why it isn't, I'm not caring about the votes themselves.)
- tromp 1y agoSee https://blog.breez.technology/lightning-btc-iou-62e3a712c913 https://blog.breez.technology/lightning-btc-iou-62e3a712c913 for instance.
- tsimionescu 1y agoAs that post makes clear at the end, if you don't monitor the BTC block chain actively (with an app or by paying a third party you trust to hopefully do it for you), you can be cheated out of your BTC with Lightning.
- lawn 1y ago> Are there scaling issues with Monero, similar/worse than BTC? While there are scaling issues with BTC it's severely worsened by the fact that BTC had refused to scale on-chain. Monero is technically much harder to scale but since it doesn't have the same self-imposed restriction it can handle more transactions than Bitcoin can.
- protocolture 1y ago>It has to be inertia related right? Consider that a lot of Bitcoin is assumed to be locked up. If an old satoshi wallet started moving funds, the price would probably halve.
- welsandjeremy 1y agoThe recent ByBit hack and subsequent takedown of the exchange that was used to convert the USDT and BTC to Monero essentially proves that XMR is private from even western governments.
- jijijijij 1y agoIt's evidence at best.
- stasmo 1y agoIf the US debt problem leads to capital controls, using Monero will become a federal offence overnight. Might as well call it money-laundering coin.
- ChrisfromLees 1y agoDo you think that is a likely scenario under this government?
- ty6853 1y agoIDK about this particular administration, but the government did place Tornado cash on the sanctions list (now removed). Which does operate differently than monero, but from the view of a bureaucrat I think similar effect.
- ujkhsjkdhf234 1y agoYes. I would bet on it. Certain Democrats don't like Monero because of the criminal activity around it. If the king told Republicans to ban it, they would be able to get enough Dems on board to avoid any filibuster problems.
- NoMoreNicksLeft 1y ago[flagged]
- ty6853 1y agoNo I think money laundering is when you knowingly mix proceeds of crime, obscuring it. Like if I make drug dealing illegal, then require drug dealer to pay taxes. And then take the tax money, and conceal and intermix it into the form of the value of the 8th street bridge to cross the creek.
- NoMoreNicksLeft 1y ago>No I think money laundering is when you knowingly mix proceeds of crime, obscuring it. I can exempt myself from the $10k deposit/withdrawal/structuring rules at the bank by affirming to them that it's not the proceeds of a crime? If a cop decides to take the $300 out of my wallet, I just state "that's not drug money" and he has to give it back then and there? Keep in mind that I can lose the money without a conviction, trial, or even being charged, so I don't think this has anything to do with it being the proceeds of a crime.
- IceHegel 1y agoAll I know is that if the government is trying to ban it, the tech probably works.
- DJHenry56 1y agoI agree, that's the biggest proof so far.
- Retric 1y agoAlternatively, because they’re talking about banning it without actually banning it, it must be compromised.
- piracyrules 1y ago[dead]
- selfmodruntime 1y agoIt is defacto banned at most fiat exchanges. The ban is happening.
- mrbluecoat 1y agoDERO could be an alternative with their full encryption of user balances and transactions
- TBaaddi 1y agoMonero has been used and proven for over a decade. No one wants to switch to some unknown tech with an unknown development team.
- DaSHacka 1y agoThe latter is arguably the more important of the two. I remember a scare some years back around a Monero developer that turned out to be a nothingburger, but it goes to show how important it is that the core development team is trustworthy, or at least sticks to their beliefs and don't capitulate to third-parties (whether public or private in nature). Monero is the one coin I can confidently say I trust the core developers on, it's had a strong history of making the right decisions where it counts in my opinion (breaking ASICs w/the monero-classic situation, making the official client default to downloading the entire chain, etc)
- OsrsNeedsf2P 1y agoHow much of the Monero development team is actually known? Last I checked some of their core team were anonymous but that might have changed
- deleted 1y ago[deleted]
- arccy 1y agoknown as in have a proven reputation / track record.
- MoneroDotForex 1y agoProven but pseudonymous, like Satoshi was. Adopted and used first by darkweb pot dealers, like Bitcoin was. Price supressed by government and banking hostility, like Bitcoin was.
- FabHK 1y agoFun fact: After some $330m of BTC were stolen last month, Monero spiked 40%+, presumably because the proceeds of that theft were laundered. https://x.com/zachxbt/status/1916756932763046273 https://x.com/zachxbt/status/1916756932763046273
- yieldcrv 1y ago> presumably because the proceeds of that theft were laundered this phrase highlights some really common but unnecessary misunderstandings 1) the proceeds swapped to Monero. there is nothing "presumably" about that because we can see they were swapped to Monero. It isn't a correlation, the instant exchanges show and retain records that they were swapped to Monero. 2) they are unlinking the origin and destination of illicitly obtained funds, so that is laundering BUT 3) its equally as likely that Monero is the destination. there is no further swapping out to hide. no further laundering to complete. Monero can be used to purchase goods, services, and invest with as well. I think this is as misunderstood as people actually wanting to hold bitcoin was 10 years ago. 4) Monero is an old coin, from one of the first crypto cycles, one thing that's held people back from using it and other mixers is the liquidity. If a large hack of funds used any one of them, then most of the funds coming out would be probabilistically part of the hack and illicit. But if MANY of the hacks used it and other licit sources, this would improve the liquidity for everyone and other hacks. Liquidity begets liquidity. It was only a matter of time before someone started it.
- ofjcihen 1y agoI wonder how common this kind of swapping is. Its an interesting financial vehicle when a valid and legal investment strategy is to try to time the laundering of different assets.
- multjoy 1y agoIt's massively common. USDT is the usual coin of choice because even though the ledger is public, the convenience and relative stability massively outweighs the security risks. In the jobs I've seen, the marks will be 'investing' in BTC but the criminals will be moving those funds out into USDT the moment it hits the bandit wallet.
- zargon 1y agoI can’t find a date on this article. And this is exactly the type of content that needs a date.
- LegionMammal978 1y ago2024-12-23 through 2024-12-30, if the HTML metadata is to be believed. It's always a pain when article-oriented websites try to hide this sort of thing.
- madars 1y agoThis reads like standard AI slop. A giveaway is structured Attempt/Methodology/Efficacy pattern repeated all the way through the article, while top level categories are overlapping. (ZeroGPT: "Your Text is Likely generated by AI/GPT".)
- TBaaddi 1y agoYou just used some bullshit AI tool to call my work, that took me several weeks to research and write, "AI slop". That's after getting a degree and spending over a decade in financial journalism. You will read this but still insist you are smart. People like you are the reason people are falling for "AI slop".
- MoneroDotForex 1y agoThank you for the input. As the linked news and opinion blog's editor I saw a spike in traffic from this HN thread, and I'm happy to answer any question anyone here may have about it. I have added the date and author's name to this article and will make that the standard.
- yieldcrv 1y ago> Conclusion: Monero’s Privacy Remains Resilient tl;dr every method from the private sector and the state has resulted in nothing, or an upgrade to the Monero network for anyone interested in using Monero, consider using Feather Wallet. This wallet implements some better best practices than the community's wallet. Feather Wallet does initial syncing over clearnet for speed, and then connects to TOR and then only connects to other nodes hosted over Onion network. So you aren't even needing to connect to exit nodes. It also hides the root address which starts with 4, and only shows you subaddresses that starts with 8. I always felt it was important that nobody ever could distinguish between a root address and subaddress. It ensures you don't re-use addresses, which is an ancient and still relevant best practice that most cryptocurrencies and wallet have avoided for user experience. Feather Wallet makes it easy though. Timing attacks are still relevant. For anyone aiming to use Monero as merely a conduit, wait 1 week or 2 before moving funds out, and move them out in different denominations than you put in. (In comparison, if you put $50,000 of XMR in, and a couple ours later moved $50,000 of XMR out in one transaction, this could realistically deanonymize you.) The more people using Monero for benign but equally as private purposes, the more it improves the utility of Monero for everyone.
- ianmiers 1y agoThis is by no means a comprehensive analysis. This analysis misses the most major limitation with Monero's decoy based approach to transaction obfuscation: Eve-Alice-Eve attacks (also known as ABA attacks). It also misses an analysis of the possible insecurity of churning and a significant history of randomness implementation errors and flooding attacks specific to Monero. The exact consequences of some of these attacks remain an open question, but worthy of mention. A simple and surprising limitation of Monero and any other decoy-based approach is that if you repeatedly withdraw money from one exchange and then deposit it to another, those transactions are not private (edit: even if we ignore payment value). This is a form of Eve-Alice-Eve attack. Monero uses decoy transactions to obscure the transaction history on-chain, but it does not remove the history. There's a reason every other major privacy protocol (Zcash, Tornado Cash, Railgun, Aleo, Penumbra, etc.) does not use Monero's decoy-based approach, and even the Monero developers are moving to the standard zero-knowledge proof over an accumulator (IIRC a merkle tree like everyone else) based approach that they call Full Chain Anonymity Proofs. As a meta-comment, this is one of a genre of Monero "privacy" analysis documents that are circulated as a way to claim there are no known actively used exploits. This is little better than the classic "my scheme is secure; here's a bounty for anyone who breaks it" form of cryptographic analysis we often see with flawed encryption schemes. Breaks will not always be public.
- yieldcrv 1y agoCorrect, I don't find these to be limitations for any user of Monero, its just a way not to use it. > repeatedly withdraw money from one exchange and then deposit it to another right, don't do that. Withdraw to your wallet. Wait several days. Transfer elsewhere in different denominations. Problem solved for everything you wrote, and its been nearly the same for the entire lifespan of Monero, 11 years now. > Breaks will not always be public. There are court cases that give the confidence necessary. It is also something to stay abreast of. Always just ask yourself who the transaction is intended to be hidden from.
- beeflet 1y ago>right, don't do that. Withdraw to your wallet. Wait several days. Transfer elsewhere in different denominations. Unfortunately, it doesn't work like that. The EAE attacks only require that the end destination is colluding with the start destination. Like everything with decoys, privacy is stochastic. So I wouldn't go around making absolute claims about the privacy as many proponents of monero like to do. The developers advise against making these sorts of claims. Monero makes privacy a lot easier, but it's not perfect. >There are court cases that give the confidence necessary. It is also something to stay abreast of. Always just ask yourself who the transaction is intended to be hidden from. In the free world, we have the concept of innocent-until-proven-guilty and evidence-beyond-a-reasonable-doubt. Decoy-based approaches give you plausible deniability, but this often isn't enough for more domains where a lower standard of proof is needed. Fortunately, all this and more will be fixed in FCMP++ upgrade.
- coldblues 1y agohttps://www.getmonero.org/2024/04/27/fcmps.html https://www.getmonero.org/2024/04/27/fcmps.html After this is implemented, it will really strengthen its privacy. It will take a few years of development, iteration and planning. Move slow and... don't break things?
- ddtaylor 1y agoI was interested to see some AI providers support crypto as their payment. I think we are entering a future where AI regulation puts more people on the darknet.
- jijijijij 1y agoVery cyberpunk and all, but how are AI regulations driving people to the darknet? You think those highly centralized billion dollar compute operations will secretly offer hidden services so people can ... what? Generate fucked up shit without restrictions? Lol, you could probably do traffic analysis with thermal imaging from a satellite.
- ddtaylor 1y ago> Generate fucked up shit without restrictions? No, that already exists and is not relevant IMO. My comment has nothing to do with what kind of content you generate. The USA in specific has had a similar problem before with encryption being classified as a munition making very problematic to import or export encryption. That's actually pretty well documented in various pieces of Java code from Sun if you're curious, because different algorithms could not be part of the JRE/JDK that was distributed publicly. Your mention of "highly centralized billion dollar compute operations" is actually related to the training of the models not the inference. Doing inference for many of these models is readily available at modest consumer hardware availability. There are many different ways to break up models (MoE) etc. The notion that you need a large super computer to do inference is unfounded. Also, as a reminder, cryptocurrency mining has already proven this to be a thing. Some stay above ground, some go to geopolitical areas for shelter and some stay underground entirely. For your entertainment I will also include a more simplified play-by-play of how this can play out in the near future: 1. OpenAI or some other USA based AI company continues to get outplayed by foreign models (Qwen, Deepseek) 2. Company cries to government 3. Government does a similar munitions or tariff to what we saw with encryption. Requires at the least anyone wanting to use AI gets one from the good boy list etc. Now you either (a) use only AI from the good boy list and get outplayed in the global marketplace where our main export is global technology or (b) start acting like a Chinese citizen and using a VPN to access AI services not available only on the approved good boy list. I will stop here because the rest is already very well documented with how this progresses and you get the same result as the darknet marketplaces (DNM). DNS censorship for AI services not on the good boy list. DNS censorship and legal pressure for VPNs that allow non-good-boy-list services, etc. Why wouldn't someone change a few .com endpoints to .onion and keep it moving while you send some coin to a wallet?
- phusion 1y ago[flagged]
- phusion 1y ago[flagged]
- password4321 1y agoI don't have a link but I vaguely recall some criminal being tracked down because they cashed out the exact same value of Monero they received for their crime in a single transaction. I believe this falls under item 1 in the article but the reference link does not even discuss Monero. I am interested in any references to tracking Monero in criminal court cases. So far it seems to be one of the most effective ways to "keep getting away with it".
- woah 1y agoTiming and amount correlation is something that not even the most sophisticated cryptography can stop.
- john_alan 1y agoI work in applied cryptography and XMR is my preferred cryptocurrency.
- woah 1y agoWhy not Zcash?
- linschn 1y agoNot the OP, but Zcash's privacy feztures are optional and seldom used in practice, whereas monero is secure by default. It helps with blending in the crowd.
- john_alan 1y agoright, plus the anonymity set size, plus the original trusted setup (now largely resolved)
- RandomBacon 1y agoMonero doesn't have a dev tax. Though Zcash proponents will say the tax is a good thing. The tax is so good, that instead of getting rid of the tax after half of the coins were mined like the developers originally promised, the devs kept the dev tax for all of the mined coins.
- password4321 1y agoWhat is the least amount of effort to setup a Monero address like a tip jar, deferring transfers and if necessary even checking the balance until setting up something more full-blown later?
- beeflet 1y agoCheck out feather wallet (https://featherwallet.org/ https://featherwallet.org/) on desktop or cake wallet (https://cakewallet.com/ https://cakewallet.com/) on mobile. Once you create a wallet and write down the seed phrase, generate a "view key". Creating a new wallet from this "view key" allows you to see incoming transactions to your addresses, but not spend them. So you don't need as much security for "view-only" wallets. You can generate an address from either wallet. It's a long string of numbers and letters that begins with an "8", under "Receive".
- storus 1y agoGiven EU is going to ban all privacy-preserving cryptocurrencies in 2027, what are the options for EU citizens?
- protocolture 1y agoDo it anyway
- mickey475778 1y ago[dead]
- Lavia3 1y ago[dead]