BTC$77,213▼ 0.39%
ETH$2,116▼ 0.78%
SOL$85.65▲ 0.78%
HYPE$57.73▲ 15.29%
XRP$1.36▼ 0.53%
BNB$649.20▲ 0.73%
DOGE$0.1045▲ 0.50%
AVAX$9.31▲ 0.70%
LINK$9.58▼ 0.12%
TAO$278.80▲ 5.59%
ZEC$661.59▲ 13.74%
NEAR$1.76▲ 7.73%
BTC$77,213▼ 0.39%
ETH$2,116▼ 0.78%
SOL$85.65▲ 0.78%
HYPE$57.73▲ 15.29%
XRP$1.36▼ 0.53%
BNB$649.20▲ 0.73%
DOGE$0.1045▲ 0.50%
AVAX$9.31▲ 0.70%
LINK$9.58▼ 0.12%
TAO$278.80▲ 5.59%
ZEC$661.59▲ 13.74%
NEAR$1.76▲ 7.73%
RSS
Exclusive · Aug 7, 2026

Did Researchers Just Crack Monero's Tor Privacy? We Asked Co-Founder Riccardo Spagni

A research paper claiming to deanonymize Monero transactions sent over Tor received pushback from Monero co-founder Riccardo Spagni, AKA FluffyPony.

The paper was posted on arXiv on July 8 by researchers at Beijing University of Posts and Telecommunications. It introduces ProxyMark, a three-stage method for linking Monero transactions sent over Tor to the IP address of the node that originated them.

The technique was tested on the live Tor network, Monero’s mainnet, and its testnet.

IP Decloaking, Not Deanonymization

The privacy coin’s co-founder told Scalper News that XMR’s cryptographic privacy remains intact and has not been breached by ProxyMark.

Spagni stated that the paper contains decent protocol research, but is ‘wearing a sky-is-falling headline three sizes too big’, overstating its impact to users.

‘Firstly,’ he said, ‘it’s not “deanonymizing”. Monero’s privacy is cryptographic. Who paid whom, and how much, stays hidden on-chain, and nothing in this paper touches any of that.’

He explained that the worst case scenario is that an attacker could learn which IP address a transaction originates from, stating that a more accurate term for the technique would be ‘IP decloaking.’

The co-founder also took issue with the framing of the research, saying it only works if the attacker controls the target's Tor entry guard, the first relay in a user's Tor circuit that sees their true IP address.

Attackers Would Need a Third of Tor's Guard Capacity For a Shot

"An analogy: Tor randomly assigns the first leg of your journey to one of thousands of taxi drivers," he said. "This attack requires the attacker to be your driver, and the paper's own appendix prices the ticket."

According to Spagni, an attack would require owning so much of Tor’s relay bandwidth that only a nation-state could afford it. He added that Tor’s directory authorities constantly monitor for this kind of relay flooding, making it unlikely that it would pass unnoticed even if it was possible.

The paper itself acknowledges that an attacker running 1,000 relays has about a 27% chance of becoming a Tor client node’s entry guard, and a 46% chance of becoming a hidden-service node. 1,000 relays is about a third of the network’s total guard bandwidth.

The research tests were configured to use the attacker’s relay as its only guard.

Spagni told Scalper News that ‘each stage was tested separately under favourable conditions, and nobody ran the full attack end-to-end against a victim picking guards normally.’

The True Monero/Tor Vulnerability

To give credit where it’s due, Spagni acknowledged that ‘the underlying Monero P2P observations are real and worth fixing, mainly the way transactions you originate get forwarded over hidden-service peers before they reach the wider network.’

He added that ‘The paper's own proposed fix (extending Dandelion++'s stem phase across those Tor-side connections) is a good idea, it's entirely on the Monero side, and I'd expect contributors to pick it up. Nobody needs to touch Tor.’