#

monero

(25 articles)

History of Monero

> [Read the original blog post](https://blog.kycnot.me/p/monero-history) Bitcoin enthusiasts frequently and correctly remark how much value it adds to Bitcoin not to have a face, a leader, or a central authority behind it. This particularity means there isn't a single person to exert control over, or a single human point of failure who could become corrupt or harmful to the project. Because of this, it is said that no other coin can be equally valuable as Bitcoin in terms of decentralization and trustworthiness. Bitcoin is unique not just for being first, but also because of how the events behind its inception developed. This implies that, from Bitcoin onwards, any coin created would have been created by someone, consequently having an authority behind it. For this and some other reasons, some people refer to Bitcoin as "[The Immaculate Conception](https://yewtu.be/watch?v=FXvQcuIb5rU)". While other coins may have their own unique features and advantages, they may not be able to replicate Bitcoin's community-driven nature. However, one other cryptocurrency shares a similar story of mystery behind its creation: **Monero**. ## History of Monero ### Bytecoin and CryptoNote In March 2014, a Bitcointalk thread titled "*Bytecoin. Secure, private, untraceable since 2012*" was initiated by a user under the nickname "**DStrange**"[^1^]. DStrange presented Bytecoin (BCN) as a unique cryptocurrency, in operation since July 2012. Unlike Bitcoin, it employed a new algorithm known as CryptoNote. DStrange apparently stumbled upon the Bytecoin website by chance while mining a dying bitcoin fork, and decided to create a thread on Bitcointalk[^1^]. This sparked curiosity among some users, who wondered how could Bytecoin remain unnoticed since its alleged launch in 2012 until then[^2^] [^3^]. Some time after, a user brought up the "CryptoNote v2.0" whitepaper for the first time, underlining its innovative features[^4^]. Authored by the pseudonymous **Nicolas van Saberhagen** in October 2013, the CryptoNote v2 whitepaper[^5^] highlighted the traceability and privacy problems in Bitcoin. Saberhagen argued that these flaws could not be quickly fixed, suggesting it would be more efficient to start a new project rather than trying to patch the original[^5^], an statement simmilar to the one from Satoshi Nakamoto[^6^]. Checking with Saberhagen's digital signature, the release date of the whitepaper seemed correct, which would mean that Cryptonote (v1) was created in 2012[^7^] [^8^], although there's an important detail: *"Signing time is from the clock on the signer's computer"* [^9^]. Moreover, the whitepaper v1 contains a footnote link to a Bitcointalk post dated May 5, 2013[^10^], making it impossible for the whitepaper to have been signed and released on December 12, 2012. As the narrative developed, users discovered that a significant **80% portion of Bytecoin had been pre-mined**[^11^] and blockchain dates seemed to be faked to make it look like it had been operating since 2012, leading to controversy surrounding the project. The origins of CryptoNote and Bytecoin remain mysterious, leaving suspicions of a possible scam attempt, although the whitepaper had a good amount of work and thought on it. ### The fork In April 2014, the Bitcointalk user **`thankful_for_today`**, who had also participated in the Bytecoin thread[^12^], announced plans to launch a Bytecoin fork named **Bitmonero**[^13^] [^14^]. The primary motivation behind this fork was *"Because there is a number of technical and marketing issues I wanted to do differently. And also because I like ideas and technology and I want it to succeed"*[^14^]. This time Bitmonero did things different from Bytecoin: there was no premine or instamine, and no portion of the block reward went to development. However, thankful_for_today proposed controversial changes that the community disagreed with. **Johnny Mnemonic** relates the events surrounding Bitmonero and thankful_for_today in a Bitcointalk comment[^15^]: > When thankful_for_today launched BitMonero [...] he ignored everything that was discussed and just did what he wanted. The block reward was considerably steeper than what everyone was expecting. He also moved forward with 1-minute block times despite everyone's concerns about the increase of orphan blocks. He also didn't address the tail emission concern that should've (in my opinion) been in the code at launch time. Basically, he messed everything up. *Then, he disappeared*. After disappearing for a while, thankful_for_today returned to find that the community had taken over the project. Johnny Mnemonic continues: > I, and others, started working on new forks that were closer to what everyone else was hoping for. [...] it was decided that the BitMonero project should just be taken over. There were like 9 or 10 interested parties at the time if my memory is correct. We voted on IRC to drop the "bit" from BitMonero and move forward with the project. Thankful_for_today suddenly resurfaced, and wasn't happy to learn the community had assumed control of the coin. He attempted to maintain his own fork (still calling it "BitMonero") for a while, but that quickly fell into obscurity. The unfolding of these events show us the roots of Monero. Much like Satoshi Nakamoto, the creators behind CryptoNote/Bytecoin and thankful_for_today remain a mystery[^17^] [^18^], having disappeared without a trace. This enigma only adds to Monero's value. Since community took over development, believing in the project's potential and its ability to be guided in a better direction, Monero was given one of Bitcoin's most important qualities: **a leaderless nature**. With no single face or entity directing its path, Monero is safe from potential corruption or harm from a "central authority". The community continued developing Monero until today. Since then, Monero has undergone a lot of technological improvements, migrations and achievements such as [RingCT](https://www.getmonero.org/resources/moneropedia/ringCT.html) and [RandomX](https://github.com/tevador/randomx). It also has developed its own [Community Crowdfundinc System](https://ccs.getmonero.org/), conferences such as [MoneroKon](https://monerokon.org/) and [Monerotopia](https://monerotopia.com/) are taking place every year, and has a very active [community](https://www.getmonero.org/community/hangouts/) around it. > Monero continues to develop with goals of privacy and security first, ease of use and efficiency second. [^16^] This stands as a testament to the power of a dedicated community operating without a central figure of authority. This decentralized approach aligns with the original ethos of cryptocurrency, making Monero a prime example of community-driven innovation. For this, I thank all the people involved in Monero, that lead it to where it is today. *If you find any information that seems incorrect, unclear or any missing important events, please [contact me](https://kycnot.me/about#contact) and I will make the necessary changes.* ### Sources of interest * https://forum.getmonero.org/20/general-discussion/211/history-of-monero * https://monero.stackexchange.com/questions/852/what-is-the-origin-of-monero-and-its-relationship-to-bytecoin * https://en.wikipedia.org/wiki/Monero * https://bitcointalk.org/index.php?topic=583449.0 * https://bitcointalk.org/index.php?topic=563821.0 * https://bitcointalk.org/index.php?action=profile;u=233561 * https://bitcointalk.org/index.php?topic=512747.0 * https://bitcointalk.org/index.php?topic=740112.0 * https://monero.stackexchange.com/a/1024 * https://inspec2t-project.eu/cryptocurrency-with-a-focus-on-anonymity-these-facts-are-known-about-monero/ * https://medium.com/coin-story/coin-perspective-13-riccardo-spagni-69ef82907bd1 * https://www.getmonero.org/resources/about/ * https://www.wired.com/2017/01/monero-drug-dealers-cryptocurrency-choice-fire/ * https://www.monero.how/why-monero-vs-bitcoin * https://old.reddit.com/r/Monero/comments/u8e5yr/satoshi_nakamoto_talked_about_privacy_features/ [^1^]: https://bitcointalk.org/index.php?topic=512747.0 [^2^]: https://bitcointalk.org/index.php?topic=512747.msg5901770#msg5901770 [^3^]: https://bitcointalk.org/index.php?topic=512747.msg5950051#msg5950051 [^4^]: https://bitcointalk.org/index.php?topic=512747.msg5953783#msg5953783 [^5^]: https://bytecoin.org/old/whitepaper.pdf [^6^]: https://bitcointalk.org/index.php?topic=770.msg8637#msg8637 [^7^]: https://bitcointalk.org/index.php?topic=512747.msg7039536#msg7039536 [^8^]: https://bitcointalk.org/index.php?topic=512747.msg7039689#msg7039689 [^9^]: https://i.stack.imgur.com/qtJ43.png [^10^]: https://bitcointalk.org/index.php?topic=740112 [^11^]: https://bitcointalk.org/index.php?topic=512747.msg6265128#msg6265128 [^12^]: https://bitcointalk.org/index.php?topic=512747.msg5711328#msg5711328 [^13^]: https://bitcointalk.org/index.php?topic=512747.msg6146717#msg6146717 [^14^]: https://bitcointalk.org/index.php?topic=563821.0 [^15^]: https://bitcointalk.org/index.php?topic=583449.msg10731078#msg10731078 [^16^]: https://www.getmonero.org/resources/about/ [^17^]: https://old.reddit.com/r/Monero/comments/lz2e5v/going_deep_in_the_cryptonote_rabbit_hole_who_was/ [^18^]: https://old.reddit.com/r/Monero/comments/oxpimb/is_there_any_evidence_that_thankful_for_today/

Monero Under Attack: How the Community Responds to Selfish Mining Attacks

## **The September 14th Nightmare** On September 14th, 2025, merchants and exchanges woke up to discover that 55 transactions they believed to be confirmed had simply disappeared from the Monero network. Money that was "guaranteed" in their wallets had vanished. Already processed payments were invalidated. Transfers that seemed complete never happened. ![](https://www.eddieoz.com/content/images/2025/09/image-1.png)bitmonero.log on my own node This wasn't a casual bug or technical glitch. It was the result of a coordinated and devastating attack that shook one of the world's most respected privacy-focused cryptocurrencies. **What happened technically:** An 18-block "reorg" (reorganization) hit the Monero network - meaning that 18 blocks the entire network believed to be valid and permanent were suddenly discarded and replaced by an alternative version of history. To put this in perspective, reorganizations of more than 2-3 blocks are extremely rare in established blockchain networks. **The financial outcome:** 55 confirmed double spends (the same money spent twice) and 115 transactions completely invalidated. While we cannot know whether these were merchants, exchanges, or individuals transacting, this matters little in the face of real double spending scenarios - someone lost real money. This situation forced the Monero developer community into an emergency meeting to discuss urgent solutions. What emerged from this discussion were four controversial proposals, each with their own trade-offs between security, decentralization, and practicality. ## **Watch on Youtube (pt-BR)** ## **Understanding the Attack Mechanics** ### **How Selfish Mining Works** Before diving into the proposed solutions, it's crucial to understand how the Qubic entity managed to execute this attack. [Selfish mining is a theoretical concept known since 2014](https://www.cs.cornell.edu/~ie53/publications/btcProcFC.pdf?ref=eddieoz.com), but rarely seen in action at significant scale. **The Qubic Scheme:** 1. **Artificial Incentive**: The Qubic pool created its own token and rewards miners with this additional token beyond normal Monero rewards. This makes mining on their pool artificially more profitable. 2. **Secret Parallel Mining**: With concentrated hashrate, they mine a parallel chain in secret, keeping blocks without transmitting them to the network. 3. **Strategic Accumulation**: While the main network continues normally, they accumulate an increasingly larger sequence of valid blocks. 4. **Devastating Release**: At the strategic moment, they release the entire secret chain at once. Since it's longer than the main chain, Bitcoin/Monero consensus rules force the network to accept this new chain as the "true" one. 5. **Catastrophic Result**: All blocks from the original chain are discarded, making "confirmed" transactions disappear and enabling double spending. ![](https://www.eddieoz.com/content/images/2025/09/image-2.png)[https://x.com/torrents/status/1967273551070974382/photo/1](https://x.com/torrents/status/1967273551070974382/photo/1?ref=eddieoz.com) ### **Why Monero Was Vulnerable: The Decentralization Paradox** It's important to clarify that Monero's vulnerability doesn't come from a technical "weakness" compared to Bitcoin. Monero uses the RandomX algorithm (CPU-based), while Bitcoin uses SHA-256 (ASIC-based) - **these are completely incompatible technologies**. Bitcoin's hashrate cannot be used to attack Monero, just as Monero's hashrate cannot be used against Bitcoin. The real problem reveals a philosophical paradox in Monero's approach: #### **The CPU-Only Mining Philosophy** Since 2014, Monero has undergone multiple algorithm changes to maintain "egalitarian mining" - the idea that anyone with a regular computer can mine. RandomX, implemented in 2019, was designed to be "a final attempt to block specialized mining hardware." **The Promise:** Preventing ASICs would ensure decentralization, since anyone could mine with common CPUs. **The Reality:** Even without ASICs, mining still concentrated in pools. Currently, 2-3 pools control the majority of Monero's hashrate. #### **The ASIC vs CPU Debate: Two Visions of Decentralization** **Pro-CPU Arguments (Monero's Current Position):** - **Accessibility**: "Practically everyone in the world now has a smartphone in their pocket with a CPU and memory capable of mining RandomX" - **Monopoly Prevention**: ASICs create entry barriers through high costs and limited suppliers - **Democratic Control**: Prevents geographical concentration of mining farms **Pro-ASIC Arguments (Controversial Position):** - **The Decentralization Paradox**: ASIC defenders argue that once ASICs become widely available and cheap, anyone can buy them and mine - potentially creating more participants than current CPU mining. The current problem is that only a few pools dominate, even with "accessible" CPUs. - **Development Centralization**: Critics of ASIC resistance argue that maintaining this philosophy creates dangerous dependence on developers. Since Monero has changed its algorithm 5 times since 2014 to combat ASICs, the network becomes totally dependent on developers' capacity and willingness to implement constant changes. This may decentralize mining, but centralizes decision-making power over the network's future in a small group of technical developers. - **Stability vs Agility**: With established ASICs, the protocol wouldn't need to change constantly. Miners would have dedicated hardware with long-term interest in network security, instead of CPUs that can easily migrate to other projects (as seen in the Qubic attack). - **Economic Reality**: ASIC resistance may be fundamentally impossible long-term, especially if Monero's value grows significantly, making specialized hardware development economically viable. #### **How the Qubic Attack Exploited This Vulnerability** The attack wasn't about ASIC vs CPU technology - it was about **concentration through economic incentives**: 1. **Artificial Rewards**: The Qubic pool created its own token, offering extra rewards to miners 2. **Hashrate Concentration**: They managed to go from 10% to over 40% of total hashrate 3. **Philosophy Exploitation**: They used the ease of pool switching (advantage of CPU mining) against the network itself #### **The Paradox Revealed** The Qubic attack exposed a fundamental contradiction: - **CPU mining** was designed to prevent hardware concentration - But **doesn't prevent pool concentration**, which is where the attack actually happened - Miners with **dedicated hardware have greater economic interest** in long-term network security, as they made significant investments that only pay off if the network remains healthy and valuable - CPU miners can easily stop mining Monero and use their computers for other activities, while ASICs only serve one specific cryptocurrency #### **The Question of Dedicated Investment** Some in the community argue that miners with substantial investments in specialized hardware have economic incentives more aligned with network security: - **Long-term Interest**: ASIC miners made investments that only recover over years, creating strong incentive to keep the network secure and valuable - **Financial Commitment**: Unlike CPU miners who can easily migrate to other activities, ASIC miners have "skin in the game" - their investment is only valuable if Monero prospers This isn't a critique of RandomX or Monero's philosophy - it's recognition that **decentralization is a complex problem** that goes beyond mining algorithm choice. ## **The Four Solutions Under Debate** The Monero developers' emergency meeting generated four distinct proposals to combat selfish mining attacks. Each solution represents a unique trade-off between security, decentralization, and technical viability. **Note on the Discussion:** While four solutions were identified as options, the [September 17, 2025 meeting](https://github.com/monero-project/meta/issues/1268?ref=eddieoz.com#issuecomment-3313805186) focused predominantly on DNS Checkpoints, with Publish or Perish and Lucky Transactions being mentioned only briefly. The detailed analysis of these proposals comes from their technical specifications in GitHub repositories. ### **1. DNS Checkpoints: The Controversial Solution** **The Proposal:** The DNS checkpoints system uses 4-7 distinct DNS domains to store "checkpoints" - references that identify the correct version of the blockchain at specific moments. When a suspicious reorganization is detected, nodes consult these domains to verify which chain should be considered legitimate. ([https://github.com/monero-project/monero/issues/10064](https://github.com/monero-project/monero/issues/10064?ref=eddieoz.com)) **How it Works:** - Trusted entities maintain specific DNS domains - Blocks mined by known pools are authenticated and registered in these domains - During reorganizations, nodes consult at least 5 of the 7 domains - The version approved by the majority of domains is considered legitimate **Advantages:** - **Quick Implementation**: The code already exists in Monero, needing only to be activated - **Proven Effectiveness**: Worked against Bitmain's attacks in 2018 - **Low Impact**: Doesn't require a hard fork, only client-side changes **The Devastating Criticisms:** During EddieOz's analysis and community discussions, fierce criticisms emerged against this proposal: - **Unacceptable Centralization**: As kayabanerve put it in the meeting: "I have objections to it, I just don't see value in voicing them. The concept is so centralizing I'd say it's unacceptable." The proposal essentially places final authority over the blockchain state in the hands of some internet domains. - **Massive Attack Surface**: As spher_cosmo pointed out, this "increases attack surface". It's much easier to DDoS domains, hack web servers, or force legal takedowns than to attack a distributed blockchain. - **Privacy Issues**: As user A8 astutely observed: "Whoever queries leaves a trace." Each checkpoint query can be logged, tracked, and potentially used to map the Monero network. - **Dangerous Precedent**: As rbrunner warned: "I just want to warn about the alarming tendency of band-aids becoming permanent." **EddieOz's Position:** "I don't think that's the way. You're placing trust in blockchain history in four internet domains. That's not what it was created for, right? To function alone, without you needing to trust anyone." ### **2. Publish or Perish (POP): The Technical Favorite** **The Proposal:** "Publish or Perish" represents an elegant approach to the problem: force miners to publish blocks immediately or lose the chance to include them in the main chain. This solution specifically targets selfish mining attacks when the attacker possesses between 25-50% of the hashrate. **Technical Functioning:** The proposal [monero-project/research-lab#144](https://github.com/monero-project/research-lab/issues/144?ref=eddieoz.com) presents two variants: **Soft Fork Version:** - Introduces concept of "late blocks" - Blocks arriving &gt;5 seconds after another block of the same height are considered "late" - Late blocks don't contribute to chain weight - Uses "uncle blocks" to track information from alternative chains - Requires attacker to mine 3 more blocks than the honest chain to cause reorg - Reduces attacker's potential rewards from \~88% to \~64% **Hard Fork Version (More Robust):** - Reduces block time to 60 seconds - Increases coinbase maturity to 1,440 blocks (1 day) - Implements "Reward Splitting" - divides rewards between current miners and uncle block miners - Aims to completely eliminate economic incentives for selfish mining **Why It Works:** This solution attacks the core of the selfish mining strategy. If you can't accumulate blocks in secret, you can't execute the attack. It's like forcing all poker players to show their cards as they receive them. **Technical Parameters:** - `k = 3` (blocks more than honest chain) - `D = 5` seconds (propagation delay) - Reward reduction to 0.3 XMR **Honest Limitations:** - **Doesn't Solve 51%**: Only effective against attackers with &lt;50% hashrate - **Implementation Complexity**: Especially the hard fork version - **Network Synchronization**: May penalize miners with poor connectivity - **Still Theoretical**: Awaits simulations and deeper analysis **EddieOz's Approval:** "Publish or Perish I found most interesting among them. More than putting a probabilistic layer." ### **3. Lucky Transactions: The Probability System** **The Proposal:** This solution [monero-project/research-lab#145](https://github.com/monero-project/research-lab/issues/145?ref=eddieoz.com) adds a sophisticated mathematical mechanism to transaction inclusion, creating different security thresholds against 51% attacks. **Technical Mechanics:** A transaction is considered "lucky" if it meets the mathematical condition: ``` H(checkpoint_hash || key_image) < target * amount * (checkpoint_height - input_height) ``` **How It Works:** - **Smart Prioritization**: Transactions with older outputs or larger values have higher probability of being "lucky" - **Zero Fee**: Lucky transactions can be included without fees - **New Block Weight**: `block_weight = (included_lucky_diff + current_lucky_diff / M) * pow_diff` - **Miner Incentive**: Including lucky transactions becomes economically attractive **Scalable Security:** The system creates different security thresholds based on the percentage of lucky transactions: - **0% lucky transactions**: Attacker needs &gt;80% hashrate - **50% lucky transactions**: Attacker needs &gt;50% hashrate - **100% lucky transactions**: Attacker needs only &gt;20% hashrate **Philosophy Behind:** The idea is that "established" transactions (with old outputs) represent legitimate long-term use, while transactions with very new outputs can be quickly created by attackers to manipulate the system. **Privacy Trade-offs:** - **Leaks Information**: Reveals minimum age of inputs and transaction values - **Preserves Identity**: Maintains anonymity through ring signatures - **Chain Analysis**: May facilitate temporal correlation of transactions **Conceptual Problems:** - **Complex UX**: Users need to understand complex mathematics to optimize transactions - **Predictability**: Deterministic system can be "gamed" by sophisticated attackers - **Entry Barrier**: New users with recent outputs are penalized ### **4. Proof of Stake: The Radical Change** **The Proposal:** The most radical option would be to completely abandon Proof of Work in favor of Proof of Stake. **Why It Was Considered:** - Would eliminate the selfish mining problem - Would reduce energy consumption - Would provide faster finality **Why It Was Rejected:** The Monero community deeply values the Proof of Work philosophy and sees PoS as fundamentally centralizing. While PoS was mentioned as one potential long-term solution, it received little serious consideration during the meeting. ## **The Meeting Dynamics: Democracy in Action** The meeting revealed a divided community, but one committed to transparent democratic processes. Renowned developers participated, including rucknium (moderator), ArticMine, jberman, kayabanerve, sgp\_, and other experts. ### **Three Schools of Thought** **The Pragmatists** (rucknium, ArticMine, spirobel): - Defend DNS checkpoints as a necessary evil - Emphasize urgency in the face of active threat - Cite historical success against Bitmain **The Purists** (kayabanerve, sgp\_, kill-switch): - Reject centralizing solutions - Prioritize the project's original philosophy - Warn about dangerous precedents **The Realists** (tevador, DataHoarder, ofrnxmr): - Recognize inevitable trade-offs - Focus on practical viability - Seek gradual transition solutions ### **Notable Quotes** **kayabanerve on centralization:** "At this point, I understand DNS checkpoints. I just feel we have to be unequivocally clear that even 'opt-in', it's a failure of our decentralization and needs to be a priority to remove." **sgp\_ on the reality of checkpoints:** "I see DNS checkpoints as effectively saying 'we are becoming centralized until we come up with something better'." **articmine on decentralization:** "The checkpoints are advisory. It is up to the miners to implement them. The latter is decentralized." ## **Deep Technical Implications** ### **For the Monero Ecosystem** The impact of this crisis goes far beyond purely technical issues. Exchanges have already raised confirmation requirements - some demanding more than 30 confirmations instead of the traditional 6-10. The consequences include: - **Degraded Experience**: Transactions take hours to confirm - **Compromised Trust**: Users question the network's security - **Economic Pressure**: Traders migrate to more agile alternatives ### **For the Privacy Movement** Monero represents more than a cryptocurrency - it's a symbol of the fight for financial privacy. Seeing the network under attack generates consequences that extrapolate beyond technical issues: - **Critic Validation**: Opponents of financial privacy point to the problems as evidence of unviability - **Community Fragmentation**: Different views on solutions may divide developers - **Precedent for Other Networks**: How other privacy-focused cryptocurrencies respond to similar threats ## **The Scalability Question** Parallel to the attack debate, the meeting also addressed post-FCMP++ scalability: ### **Transaction Parameters** - **Size Limit**: Proposals for 160KB per transaction - **Fee Structure**: Rebalancing for new architecture - **P2Pool Considerations**: Adjustments for decentralized pools ### **Future Implications** Scalability changes may affect: - Transaction costs for users - Viability of different use cases - Competitiveness vs other cryptocurrencies ## **The Emerging Consensus** After hours of intense debate, a fragile consensus emerged: ### **Discussion Trends (Not Formal Decisions)** 1. **DNS Checkpoints Gain Reluctant Acceptance**: Despite fierce criticism, they emerge as the most viable short-term option, but only as a coordinated "opt-in" system 2. **Pool Coordination**: Focus on engaging NOSH (Nanopool, MoneroOcean, SupportXMR, Hashvault) which represent &gt;50% of global hashrate 3. **"Failure" Recognition**: Explicit admission by the community that checkpoints represent a "failure of decentralization" 4. **Long-term Research Funding**: luigi1111 tentatively approved kayabanerve's CCS (Community Crowdfunding System) for 175 XMR (about $26,000) to research permanent "finality layer" solutions - systems that would make it impossible to reverse transactions after a certain point, definitively eliminating reorg attacks ### **Realistic Timeline** - **Immediate**: DNS checkpoints activation in testnet - **1-3 months**: Mainnet implementation if attacks continue - **6-12 months**: Development of decentralized solutions - **1-2 years**: Transition to permanent finality layer ## **Lessons for the Crypto Ecosystem** This crisis offers valuable lessons for the entire cryptocurrency ecosystem: ### **About Security** - **Concentration is the Real Risk**: It's not absolute hashrate, but its distribution that determines vulnerability - **Economic Incentives are Critical**: Attackers can manipulate rewards to concentrate mining power - **Attacks Evolve**: Theoretical strategies from 2014 finally materialized in practice ### **About Governance** - **Transparency is Crucial**: Open discussions enable better decisions - **Trade-offs are Inevitable**: Perfect solutions don't exist - **Community Matters**: Technical decisions require social alignment ### **About Innovation** - **Pressure Creates Solutions**: Crises force accelerated innovation - **Diversity of Opinion is Valuable**: Different perspectives lead to better outcomes - **Gradual Implementation**: Radical changes require time and testing ## **Looking to the Future** The battle for Monero's security is far from over. The proposed solutions represent only the first round of a longer war between developers and attackers. ### **Next Developments** - **Finality Layer Research**: Deep investigation into finality layers - **PoW Improvements**: Possible improvements to the RandomX algorithm - **Network Effects**: Efforts to increase legitimate hashrate ### **Open Questions** - Will DNS checkpoints remain truly temporary? - Will the community maintain unity during the transition? - Will other privacy-focused projects face similar attacks? ## **Conclusion: A Community Tested by Fire** The Monero crisis reveals technical vulnerabilities and also exposes the true character of a community committed to principles. The willingness to openly debate imperfect solutions, recognize painful trade-offs, and maintain commitment to fundamental values demonstrates a rare maturity in the crypto ecosystem. **The Hard Reality:** As guest55 observed in the meeting: "i think we can come to a consensus that the blockchain is under attack" **The Decisive Moment:** Monero survived Bitmain's ASICs in 2018. Now it faces a different challenge - attacks that exploit its own decentralization philosophy. The chosen response will define not only the network's technical future, but its credibility as a leader in financial privacy. **The Final Paradox:** To defend decentralization, the community may have to temporarily accept centralized solutions. This isn't capitulation - it's strategic pragmatism from a community that understands that perfection cannot be the enemy of functional. The war for privacy continues. And Monero, even wounded, continues resisting. --- **About this article**: Based on the Monero developers meeting of September 17, 2025, complete transcripts and video analysis by EddieOz. To follow future developments, follow [@eddieoz](https://x.com/eddieoz?ref=eddieoz.com) and [eddieoz@sats4.life](https://nostr.com/eddieoz@sats4.life?ref=eddieoz.com). **Disclaimer**: This article represents technical analysis and does not constitute financial advice. Monero faces real security risks that may affect its value and usability. --- References: - Selfish Mining: [https://www.cs.cornell.edu/\~ie53/publications/btcProcFC.pdf](https://www.cs.cornell.edu/~ie53/publications/btcProcFC.pdf?ref=eddieoz.com) - Monero Research Lab Meeting - Wed 17 September 2025: [https://github.com/monero-project/meta/issues/1268#issuecomment-3313805186](https://github.com/monero-project/meta/issues/1268?ref=eddieoz.com#issuecomment-3313805186) - Selfish mining mitigations (Publish or Perish): [https://github.com/monero-project/research-lab/issues/144](https://github.com/monero-project/research-lab/issues/144?ref=eddieoz.com) - Lucky Transactions: [https://github.com/monero-project/research-lab/issues/145](https://github.com/monero-project/research-lab/issues/145?ref=eddieoz.com) - DNS Checkpoints: [https://github.com/monero-project/monero/issues/10064](https://github.com/monero-project/monero/issues/10064?ref=eddieoz.com)

An Analysis of Monero's Technical Limitations

Let us delve into Monero (XMR). Among the proponents of various altcoins, Monero arguably commands one of the most dedicated followings, perhaps second only to Ethereum. Unlike many altcoins where even investors often harbor speculative, short-term intentions, the genuine belief within the Monero community suggests an inherent appeal to the chain itself. The primary advantage touted by Monero (and similar so-called "privacy coins") is its robust privacy protection features. The demand for anonymous payment systems, tracing its lineage back to David Chaum, predates even the inception of Bitcoin. Monero's most heavily promoted strength, relative to Bitcoin, is that its privacy features are enabled by default. This relates to the concept of the "anonymity set." To guarantee anonymity, a user must blend into a crowd of ordinary users. The larger the group one hides within, the more difficult it becomes for an external observer to identify any specific individual. From the perspective of Monero advocates, Bitcoin's default transaction model is overly transparent, clearly revealing the flow of funds between addresses. While repeated mixing can enhance anonymity in Bitcoin, the fact that users must actively undertake such measures presents a significant hurdle. More critically, proponents argue, the very group engaging in such deliberate obfuscation is precisely the group one doesn't want to be associated with for effective anonymity. Hiding requires blending with the ordinary, not merely mixing with others who are also actively trying to hide — the latter, they contend, is akin to criminals mixing only with other criminals. This is a valid point. For instance, there's a substantial difference between a messenger app offering end-to-end encryption for all communications by default, versus one requiring users to explicitly create a "secret chat" for encryption. While I personally believe that increased self-custody of Bitcoin in personal wallets, acquisition through direct peer-to-peer payments rather than exchange purchases, and the widespread adoption of the Lightning Network would make tracing significantly harder even without explicit mixing efforts, let us concede, for the sake of argument, that Bitcoin's base-layer anonymity might not drastically improve even in such a future scenario. Nevertheless, Monero's long-term prospects appear considerably constrained when focusing purely on technical limitations, setting aside economic factors or incentive models for now. While discussions on economics can often be countered with "That's just your speculation," technical constraints present more objective facts and leave less room for dispute. Monero's most fundamental problem is its lack of scalability. To briefly explain how Monero obfuscates the sender: it includes other addresses alongside the true sender's address in the 'from' field and attaches what appears to be valid signatures for all of them. With a default setting of 10 decoys (plus the real spender, making a ring size of 11), the signature size naturally becomes substantially larger than Bitcoin's. Since an observer cannot determine which of the 11 is the true sender, and these decoys are arbitrary outputs selected from the blockchain belonging to other users, anonymity is indeed enhanced. While the sender cannot generate individually valid signatures for the decoy outputs (as they don't own the private keys), the use of a ring signature mathematically proves that one member of the ring authorized the transaction, allowing it to pass network validation. The critical issue is that this results in transaction sizes several times larger than Bitcoin's. Bitcoin already faces criticism for being relatively expensive and slow. Monero's structure imposes a burden that is multiples greater. One might question the relationship between transaction data size and transaction fees/speed. However, the perceived slowness of blockchains isn't typically due to inefficient code, but rather the strict limitations imposed on block size (or equivalent throughput constraints) to maintain decentralization. Therefore, larger transaction sizes directly translate into throughput limitations and upward pressure on fees. If someone claims Monero fees are currently lower than Bitcoin's, that is merely a consequence of its significantly lower usage. Should Monero's transaction volume reach even a fraction of Bitcoin's, its current architecture would struggle severely under the load. To address this, Monero implemented a dynamic block size limit instead of a hardcoded one. However, this is not a comprehensive solution. If the block size increases proportionally with usage, a future where Monero achieves widespread adoption as currency — implying usage potentially hundreds, thousands, or even hundreds of thousands of times greater than today — would render the blockchain size extremely difficult to manage for ordinary node operators. Global internet traffic might be consumed by Monero transactions, or at the very least, the bandwidth and storage costs could exceed what individuals can reasonably bear. Blockchains, by their nature, must maintain a size manageable enough for individuals to run full nodes, necessitating strict block size limits (or equivalent constraints in blockless designs). This fundamental requirement is the root cause of limited transaction speed and rising fees. Consequently, the standard approach to blockchain scaling involves Layer 2 solutions like the Lightning Network. The problem is, implementing such solutions on Monero is extremely challenging. Layer 2 solutions, while varying in specific implementation details across different blockchains, generally rely heavily on the transparency of on-chain transactions. They typically involve sophisticated smart contracts built upon the ability to publicly verify on-chain states and events. Monero's inherent opacity, hiding crucial details of on-chain transactions, makes it exceptionally difficult for two mutually untrusting parties to reach the necessary consensus and cryptographic agreements (like establishing payment channels with verifiable state transitions and dispute mechanisms) that underpin such Layer 2 systems. The fact that Monero, despite existing for several years, still lacks a functional, widely adopted Layer 2 implementation suggests that this remains an unsolved and technically formidable challenge. While theoretical proposals exist, their real-world feasibility remains uncertain and would likely require significant breakthroughs in cryptographic protocol design. Furthermore, Monero faces another severe scaling challenge related to its core privacy mechanism. As mentioned, decoy outputs are used to obscure the true sender. An astute observer might wonder: If a third party cannot distinguish the real spender, could the real spender potentially double-spend their funds later? Or could someone's funds become unusable simply because they were chosen as a decoy in another transaction? Naturally, Monero's developers anticipated this. The solution employed involves key images. When an output is genuinely spent within a ring signature, a unique cryptographic identifier called a "key image" is derived from the real output and the spender's private key. This derivation is one-way (the key image cannot be used to reveal the original output or key). This key image is recorded on the blockchain. When validating a new transaction, the network checks if the submitted key image has already appeared in the history. If it exists, the transaction is rejected as a double-spend attempt. The crucial implication is that this set of used key images can never be pruned. Deleting historical key images would directly enable double-spending. Therefore, Monero's state size — the data that full nodes must retain and check against — grows linearly and perpetually with the total number of transactions ever processed on the network. Summary In summary, Monero faces critical technical hurdles: Significantly Larger Transaction Sizes: The use of ring signatures for anonymity results in transaction data sizes several times larger than typical cryptocurrencies like Bitcoin. Inherent Scalability Limitations: The large transaction size, combined with the necessity of strict block throughput limits to preserve decentralization, creates severe scalability bottlenecks regarding transaction speed and cost under significant load. Dynamic block sizes, while helpful in the short term, do not constitute a viable long-term solution for broad decentralization. Layer 2 Implementation Difficulty: Monero's fundamental opacity makes implementing established Layer 2 scaling solutions (like payment channels) extremely difficult with current approaches. The absence of a widely adopted solution to date indicates that this remains a major unresolved challenge. Unprunable, Linearly Growing State: The key image mechanism required to prevent double-spending mandates the perpetual storage of data proportional to the entire transaction history, unlike Bitcoin where nodes can prune historical blocks and primarily need to maintain the current UTXO set (whose size depends on usage patterns, not total history). These technical constraints raise legitimate concerns about Monero's ability to scale effectively and achieve widespread adoption in the long term. While ongoing research may alleviate some of these issues, at present they represent formidable challenges that any privacy-focused cryptocurrency must contend with.

中文用户列表

排名随机, 列表正在增加中。 ## Cody Tseng jumble.social 的作者 https://jumble.social/users/npub1syjmjy0dp62dhccq3g97fr87tngvpvzey08llyt6ul58m2zqpzps9wf6wl * Running [ wss://nostr-relay.app ] (free & WoT) 💜⚡️ * Building 👨‍💻: * https://github.com/CodyTseng/jumble * https://github.com/CodyTseng/nostr-relay-tray * https://github.com/CodyTseng/danmakustr * https://github.com/CodyTseng/nostr-relay-nestjs * https://github.com/CodyTseng/nostr-relay * https://github.com/CodyTseng * ## 阿甘 * @agan0 * 0xchat.com * canidae40@coinos.io * * https://jumble.social/users/npub13zyg3zysfylqc6nwfgj2uvce5rtlck2u50vwtjhpn92wzyusprfsdl2rce * ## joomaen * Follows you * joomaen.com * 95aebd@wallet.yakihonne.com * * #nobot * https://joomaen.filegear-sg.me/ * * https://jumble.social/users/npub1wlpfd84ymdx2rpvnqht7h2lkq5lazvkaejywrvtchlvn3geulfgqp74qq0 * ## 颜值精选官 * wasp@ok0.org * * 专注分享 各类 图片与视频,每日为你带来颜值盛宴,心动不止一点点。欢迎关注,一起发现更多美好! * https://jumble.social/users/npub1d5ygkef6r0l7w29ek9l9c7hulsvdshms2qh74jp5qpfyad4g6h5s4ap6lz * ## 6svjszwk * 6svjszwk@ok0.org * * 83vEfErLivtS9to39i73ETeaPkCF5ejQFbExoM5Vc2FDLqSE5Ah6NbqN6JaWPQbMeJh2muDiHPEDjboCVFYkHk4dHitivVi * #low-time-preference * #anarcho-capitalism * #libertarianism * #bitcoin #monero * https://jumble.social/users/npub1sxgnpqfyd5vjexj4j5tsgfc826ezyz2ywze3w8jchd0rcshw3k6svjszwk * ## 𝘌𝘷𝘦𝘳𝘺𝘥𝘢𝘺 𝘔𝘰𝘳𝘯𝘪𝘯𝘨 𝘚𝘵𝘢𝘳 * * everyday@iris.to * * 虽然现在对某些事情下结论还为时尚早,但是从趋势来看,邪恶抬头已经不可避免。 * 我们要做的就是坚持内心的那一份良知,与邪恶战斗到底。 * 黑暗森林时代,当好小透明。 * * bc1q7tuckqhkwf4vgc64rsy3rxy5qy6pmdrgxewcww * https://jumble.social/users/npub1j2pha2chpr0qsmj2f6w783200upa7dvqnnard7vn9l8tv86m7twqszmnke * ## nostr_cn_dev npub1l5r02s4udsr28xypsyx7j9lxchf80ha4z6y6269d0da9frtd2nxsvum9jm@npub.cash Developed the following products: - NostrBridge, 网桥转发 - TaskQ5, 分布式多任务 - NostrHTTP, nostr to http - Postr, 匿名交友,匿名邮局 - nostrclient (Python client) . -nostrbook, (nostrbook.com) 用nostr在线写书 * https://www.duozhutuan.com nostrhttp demo * https://github.com/duozhutuan/NostrBridge * * https://jumble.social/users/npub1l5r02s4udsr28xypsyx7j9lxchf80ha4z6y6269d0da9frtd2nxsvum9jm * ## CXPLAY * lightning@cxplay.org * 😉很高兴遇到你, 你可以叫我 CX 或 CXPLAY, 这个名字没有特殊含义, 无需在意. * ©本账号下所有内容如未经特殊声明均使用 CC BY-NC-SA 4.0 许可协议授权. * 🌐如果您在 Fediverse 收到本账号的内容则说明您的实例已与 Mostr.pub 或 Momostr.pink Bridge 互联, 您所看到的账号为镜像, 所有账号内容正在跨网传递. 如有必要请检查原始页面. * 🧑‍💻正在提供中文本地化(i10n): #Amethyst #Amber #Citrine #Soapbox #Ditto #Alby * https://cx.ms/ https://jumble.social/users/npub1gd8e0xfkylc7v8c5a6hkpj4gelwwcy99jt90lqjseqjj2t253s2s6ch58h ## w * 0xchat的作者 * 0xchat@getalby.com * Building for 0xchat * https://www.0xchat.com/ * https://jumble.social/users/npub10td4yrp6cl9kmjp9x5yd7r8pm96a5j07lk5mtj2kw39qf8frpt8qm9x2wl ## Michael * highman@blink.sv * Composer Artist | Musician * 🎹🎼🎤🏸🏝️🐕❤️ * 在這裡可以看到「我看世界」的樣子 * 他是光良 * https://jumble.social/users/npub1kr5vqlelt8l47s2z0l47z4myqg897m04vrnaqks3emwryca3al7sv83ry3