Fun fact: After some $330m of BTC were stolen last month, Monero spiked 40%+, presumably because the proceeds of that theft were laundered. https://x.com/zachxbt/status/1916756932763046273
De-anonymization attacks against the privacy coin XMR
81–90 of 116 posts
Re: De-anonymization attacks against the privacy coin XMR
#82Great article, and I'm glad to see privacy being a focus in a cryptocurrency, but I would like to see some other sources that aren't also promoting the token. That said, I do think it's got the brightest future of any coin besides BTC for the very reason.
Preface this by saying I am not a fan of any cryptocurrency, but I really struggle to understand why Monero has a smaller market cap than BTC. It has to be inertia related right? Monero just seems like a fundamentally better piece of technology. Are there scaling issues with Monero, similar/worse than BTC?
Consider that a lot of Bitcoin is assumed to be locked up.
If an old satoshi wallet started moving funds, the price would probably halve.
Re: De-anonymization attacks against the privacy coin XMR
#83Given EU is going to ban all privacy-preserving cryptocurrencies in 2027, what are the options for EU citizens?
Re: De-anonymization attacks against the privacy coin XMR
#84Re: De-anonymization attacks against the privacy coin XMR
#85Earlier quoted context omitted.
Correct, I don't find these to be limitations for any user of Monero, its just a way not to use it. > repeatedly withdraw money from one exchange and then deposit it to another right, don't do that. Withdraw to your wallet. Wait several days. Transfer elsewhere in different denominations. Problem solved for everything you wrote, and its been nearly the same for the entire lifespan of Monero, 11 years now. > Breaks wi…
>right, don't do that. Withdraw to your wallet. Wait several days. Transfer elsewhere in different denominations. Unfortunately, it doesn't work like that. The EAE attacks only require that the end destination is colluding with the start destination. Like everything with decoys, privacy is stochastic. So I wouldn't go around making absolute claims about the privacy as many proponents of monero like to do. The develop…
Right now it seems Eve just needs to do a dust attack and addresses she’s seen before
And wallets like Featherwallet just need to segregate dust from the pool of outputs, and that kind of attack is totally thwarted
Fortunately Eve doesnt know if an address is part of the same wallet and Featherwallet hides the ability to reuse addresses, although users are lazy and may rely on old addresses being accepted destinations for anyone sending them funds. It would be great if wallets notified of dust, or asked you to recognize transactions in.
Re: De-anonymization attacks against the privacy coin XMR
#86I work in applied cryptography and XMR is my preferred cryptocurrency.
Why not Zcash?
Though Zcash proponents will say the tax is a good thing. The tax is so good, that instead of getting rid of the tax after half of the coins were mined like the developers originally promised, the devs kept the dev tax for all of the mined coins.
Re: De-anonymization attacks against the privacy coin XMR
#87This is by no means a comprehensive analysis. This analysis misses the most major limitation with Monero's decoy based approach to transaction obfuscation: Eve-Alice-Eve attacks (also known as ABA attacks). It also misses an analysis of the possible insecurity of churning and a significant history of randomness implementation errors and flooding attacks specific to Monero. The exact consequences of some of these atta…
Correct, I don't find these to be limitations for any user of Monero, its just a way not to use it. > repeatedly withdraw money from one exchange and then deposit it to another right, don't do that. Withdraw to your wallet. Wait several days. Transfer elsewhere in different denominations. Problem solved for everything you wrote, and its been nearly the same for the entire lifespan of Monero, 11 years now. > Breaks wi…
As a non-user of Monero, how do I find out what the security properties are and what information is leaked when various actions are taken? The OP's analysis is deeply lacking in this and the apparent rule against repeated transactions is non-obvious
Re: De-anonymization attacks against the privacy coin XMR
#88This is by no means a comprehensive analysis. This analysis misses the most major limitation with Monero's decoy based approach to transaction obfuscation: Eve-Alice-Eve attacks (also known as ABA attacks). It also misses an analysis of the possible insecurity of churning and a significant history of randomness implementation errors and flooding attacks specific to Monero. The exact consequences of some of these atta…
Amusingly, assume the CIA has figured out a clever trick for opening up Acme Secure Envelopes in transit. If they publish a report detailing at length how amazing and tamper proof Acme products are, the world would take note and sales would plummet overnight. If, however, you publish the same report on a blog about how to mail documents securely...
Re: De-anonymization attacks against the privacy coin XMR
#89Earlier quoted context omitted.
Correct, I don't find these to be limitations for any user of Monero, its just a way not to use it. > repeatedly withdraw money from one exchange and then deposit it to another right, don't do that. Withdraw to your wallet. Wait several days. Transfer elsewhere in different denominations. Problem solved for everything you wrote, and its been nearly the same for the entire lifespan of Monero, 11 years now. > Breaks wi…
"right, don't do that." As a non-user of Monero, how do I find out what the security properties are and what information is leaked when various actions are taken? The OP's analysis is deeply lacking in this and the apparent rule against repeated transactions is non-obvious
there would be the monero subreddit where you could ask these questions
LLMs would be trained on them by now
Books like Mastering Monero exist, and will become obsolete if the proposed upgrades go through
Annual DNM OPSEC GUIDE will likely cover it (darknet market operational security guide)
Re: De-anonymization attacks against the privacy coin XMR
#90Earlier quoted context omitted.
It's massively common. USDT is the usual coin of choice because even though the ledger is public, the convenience and relative stability massively outweighs the security risks. In the jobs I've seen, the marks will be 'investing' in BTC but the criminals will be moving those funds out into USDT the moment it hits the bandit wallet.
USDT can be frozen so its not the best choice. Its definitely a failure of the Tether team if criminals can openly use it to launder funds without it getting frozen, but they are famously anti regulation.