Category: Uncategorized

  • Is Zcash legit or a compromised scam?

    Is Zcash legit or a compromised scam?

    Is Zcash a legitimate privacy focused project, or is it compromised?

    I don’t pretend to know the answer for definite, but it’s a valid question.

    Below let’s look at some red flags regarding ZCash:

    1) ZCash was developed from Zerocash, which was funded by the the US & Israeli governments

    Zerocash website screenshot
    Image source: http://zerocash-project.org/about_us

    Zerocash was the precursor to ZCash:

    Zcash documentation - history notes
    Image source: https://zcash.readthedocs.io/en/latest/rtd_pages/basics.html

    Make of the funding situation what you will, all I know is that it happened.

    Then, looking further at the authors of Zerocash, we can see that some continued their involvement once it became known as ZCash:

    • In 2018 Eli Ben-Sasson (of the Technion Institute in Israel) and Alessandro Chiesa (mentioned above in the zerocash screenshot) apparently formed “Starkware Industries” which ZCash then invested in (source).
    • As of 2025, Christina Garman is still involved. She’s on the board of directors (link) of Bootstrap Project, who are the parent company of Electric Coin Company (source), who in turn are the main developers of Zcash.

    2) Original Trusted Setup Issues

    Peter Todd Selfie

    One of the original trusted setup participants, Peter Todd (above) warned in his blog post:

    • “It is IMPOSSIBLE for myself and the other participants to prove to a third party that we did not collude to keep the secret key”
    • and “Until the software and deterministic builds are audited, the entire ceremony is a bunch of crypto hocus pocus that means nothing”

    Granted, he updated the blog post to say:

    “The original trusted setup is pretty much no longer relevant as the underlying crypto has been upgraded (it turned out to be broken for an entirely different reason)”

    Peter Todd Torched Laptop
    Image: Peter Todd’s torched laptop components after the trusted setup

    An interesting bit of information related to the trusted setup is that Edward Snowdon was one of the six participants, although he took part under the pseudonym John Dobbertin (source).

    Snowden + Zcash Coin

    3) The Centralised Dev Fund

    With cryptocurrencies like Bitcoin and Monero there is no “dev fund” to centralise things.

    However, with ZCash they’ve had a “development fund” since the genesis.

    The Electric Coin Company (ECC) was earning a portion of the 20% dev fund from it’s genesis in 2016 to 2024.

    Zcash founders reward timeline

    The first 4 years emitted 50% of the total token allocation.

    Whilst ZCash are claiming to decentralize, their current proposal is that ECC will compete for 12% of the 20% dev fund, based on user voting.

    However, it’s noteworthy in ZIP-0271 (https://zips.z.cash/zip-0271) that ECC would be 1 of the 2/3 multisig threshold signers controlling the lockbox containing 12% of the block reward.

    Lockbox disbursement notes
    Source

    4) The money printing bug

    Whilst it’s not unique to Zcash it’s worth being aware that Zcash had an inflation bug that existed “for years” until it was patched in 2019 by a Zcash Company cryptographer; Ariel Gabizon of the Weizmann Institute in Israel.

    The electric coin company write-up is here.

    They note: “We have found no evidence that the vulnerability was discovered by anyone else or that counterfeiting occurred”

    Roundup

    As a fan of privacy enhancing technology I tend to think the more projects in the space, the better.

    However, the reality is that not all projects are going to be created with the public good in mind.

    Whether Zcash is or not, I don’t know, but it seems to make sense to highlight the red-flags so that others can form an educated opinion.

    When I’ve got further time I’ll add more.

    Let me know your thoughts in the comments.

  • About Monero’s RandomX

    About Monero’s RandomX

    (Please note: this article was originally posted in 2019 on the monerooutreach.org site, which has since gone offline. It’s an interesting article, so I am mirroring it here.)

    What year is it? It seems like only yesterday they were saying that a privacy coin couldn’t be pruned and that ASICs will win in the end. But here we are…about to prune and talking about RandomX…wearing our space helmets. RandomX still must go through the process of becoming tried and true, but it’s an exciting part of Monero’s pipeline. This guide gives an overview of its nature and plans, and where you can learn more.

    What is RandomX?

    RandomX is a new Proof-of-Work (PoW) algorithm that Monero is scheduled to begin using in the next network update. RandomX is designed to be ASIC resistant by using random code execution and memory-hard techniques to prevent specialized mining hardware from dominating the network. Because RandomX is optimized for general-purpose CPUs, the network will become more decentralized and egalitarian in the distribution of block rewards.

    Visit the github.com/tevador/RandomX for more details or watch Howard Chu (hyc) speak about RandomX at Monero Konferenco. At the time of writing, RandomX is beginning the auditing process with Trail Of BitsX41Quarkslab and the Kudelski Group. RandomX is scheduled to go live during the next Monero network update.

    RandomX has two modes with different memory requirements and performance. Fast Mode requires 2GB of shared memory but has 4x-6x the performance of Light Mode which only requires 256MB of RAM. Fast mode is intended for dedicated miners. Light mode is designed to allow fullnodes to validate blocks without requiring the 2+GB of RAM, so that small devices (like ARM single-board computers, e.g. Rock64) can still be used as standalone nodes.

    Comparison of different CPUs and their Random X performance

    RandomX Collaboration

    RandomX was developed for Monero by tevador, hyc, vielmetti, antanst and SChernykh. Already other organizations are interested in adopting it. Arweave, a serverless storage enabler donated the Trail of Bits audit to the Monero community and will be implementing RandomX before Monero for their unique application. Arweave provides an innovative cryptocurrency-based approach to decentralized, long-term data storage. Mining on Arweave relies on both proof of work and—as a new concept unique to Arweave—proof of access. Arweave miners are incentivized through proof of access to replicate and have quick access to data stored in the network.

    Wownero is also launching RandomX in their upcoming v0.6 update and will call it RandomWOW. RandomX code will be updated after the audits are complete, so there will be some code divergence by the time Monero forks in October. Another difference is that RandomWOW will have a smaller scratchpad for hashing, 1MB instead of 2MB, smaller number of VM execution iterations, and increased chained VM executions per hash to increase program compilation cost for GPUs.

    Learn More

  • Monero Quick Facts – with PDFs

    Monero Quick Facts – with PDFs

    Prior to the Monero Outreach site going offline, they had created a Quick Facts PDF that summarized key features of Monero.

    It was last updated in May 2019. Rather than let it die (source), I’ve updated it here, with full credit to Monero Outreach for the original content:

    Below is a text-based web version:

    Core Principles

    DECENTRALIZATION

    As an open-source project led and funded by a decentralized team of developers and community members, it cannot be censored. Most contributors are volunteers and the community is spread all over the globe.

    SECURITY

    As a decentralized cryptocurrency, Monero is secured by a large network of users throughout the world. Transactions are confirmed by distributed consensus and then immutably recorded on the blockchain.

    SCALABILITY

    Unlike Bitcoin and other projects that often rely on hardcoded constants, Monero’s dynamic block size adapts automatically to the volume of transactions, providing lower fees and faster confirmations.

    PRIVACY

    Monero uses sophisticated cryptography through ring signatures, ring confidential transactions, and stealth addresses to obfuscate the origins, amounts, and destinations of all transactions. Users can decide exactly how much information they reveal and to whom.

    CENSORSHIP RESISTANCE

    Due to Monero’s privacy characteristics, no specific address or user wallet can be blacklisted by miners or by any economic actors. As a result, users are free from censorship and capital controls.

    FUNGIBILITY

    Monero is fungible because it is private by default. There is no visible history attached to each particular coin. It means users and businesses do not need to worry about being accused of accepting tainted money, and that one Monero will always be equal to another.

    HISTORY OF MONERO

    Monero was launched in April 2014. It was a fair, pre-announced launch of the CryptoNote reference code. There was no pre-mine or “insta”-mine, and no portion of the block reward goes to development. See the original Bitcointalk thread here.

    Monero has made several large improvements since launch, with many of them tracked in a timeline here. Nearly all improvements have provided advances to security or privacy, or they have facilitated use. Monero continues to develop with goals of privacy and security first, ease of use and efficiency second.

    WHAT DOES MONERO MEAN?

    The word Monero is from the Esperanto language. The creators chose to use Esperanto because it is a ‘decentralized’ language and represents the breaking of barriers between people, on a global scale. In Esperanto, Monero is a word composed of three elements freely put together, one syllabus each: mon + er + o. Each has a meaning.

    mon: money
    er: the smallest part
    o: a thing (grammatically speaking: a noun)

    Which means ‘monero’ can be analyzed as meaning: “a noun that describes the smallest part of money”. Or, a coin.

    KEY DIFFERENTIATING FACTORS

    Monero Uses The CryptoNote Codebase: This is fundamentally different from codebases used by Bitcoin or Ethereum and the many other cryptocurrencies that are derived from each. It is known for its considerable privacy improvements.

    Privacy Is Mandatory; Transparency Is Opt-in: Monero is private for every layer of a transaction: information of the sender, receiver, or the transaction itself. A user has the option to create and share a view-only wallet that reveals inputs or use view-keys to reveal specific transactions.

    Routine Network Upgrades: The community of Monero developers regularly perform network upgrades (hard forks) to ensure that all users can take advantage of the best available security, privacy, and features. This allows the Monero network to remain more nimble and secure by adapting to any opportunities or threats that arise.

    Monero Block Reward: Monero has taken a different approach to Bitcoin regarding the block reward. Rather than limit the supply to 21 million coins, Monero uses a perpetual block reward of 0.6 XMR per 2-minute block. This allows Monero to utilize an adaptive block size, that can grow (and shrink) based on demand. This contrasts with Bitcoin’s fixed block size. Note that up until 2040, there will be less XMR in circulation than BTC.

    Monero Research Lab: Monero is not only committed to making a fungible currency, but also to continuing research into the realm of financial privacy as it involves cryptocurrencies in general. Monero Research Lab (MRL) is a group of academic researchers in fields of mathematics, physics, security, and blockchain computation who research solutions for Monero and publish academic papers with their findings.

    Mining Is Accessible: Anyone with a connected device or web browser can participate.

    REAL-WORLD IMPLICATIONS & USES

    Because Monero is secure, low-fee, and borderless, people can easily send money despite corrupt and broken governments or banks and business can be conducted without competitors snooping in critical information. This provides economic empowerment of individuals and businesses in oppressive countries, depressed economies, or highly competitive business environments.

    Private financial history protects consumers and companies from price manipulation, supply chain exploitation, economic discrimination, or the like. Monero is the only cryptocurrency that has the features to serve as completely fungible, decentralized, electronic cash.

    TECHNICAL FUNDAMENTALS

    (As of 07/06/2024)

    • Amount of Active Nodes: ~12,000 (Source: monero.fail/map)
    • Network Hash Rate: 2 GH/s
    • Average Transactions/Hour: 33,000 (30-day average)
    • Monero in Circulation: 18,445,551 XMR (Approximate)
    • Market Capitalization: $2,927,951,481 USD
    • Current Block Reward: 0.6 XMR
    • Average Block Interval: 2 Minutes

    With the “tail emission” of 0.6 XMR/block, by 2040 there will be an equal amount of Monero as Bitcoin (roughly 21 million).

    FEATURES IN DEVELOPMENT

    Although Monero is already available and being used across the globe, the community of developers have exciting goals to continue enhancing the privacy, security, and usability features of Monero and cryptocurrency in general. These are a few that are coming soon:

    Full Chain Membership Proofs (FCMPs): Currently, Monero uses a technology called Ring Signatures to protect the privacy of a sender. It combines the signature of the real output with 15 decoys, to create an anonymity set size of 16. FCMPs will increase the anonymity set from 16 to every output in the blockchain. This would improve on one of the weaker aspects of Monero’s privacy.

    Seraphis: Seraphis is a fourth-generation privacy-focused transaction protocol abstraction for Monero, offering simpler multisig support, flexible multi-tier address schemes, and efficient key image construction for better performance and modularity, though it requires users to transition from CryptoNote-style addresses.

    Cuprate: This alternative Monero node, being developed in Rust, will enhance network security and redundancy by independently validating consensus rules and significantly reducing the risk of implementation and memory safety bugs. A beneficial side effect of its creation, to date, been a small number of fixes to both the existing node implementation.

    ADDITIONAL RESOURCES

  • How the Dandelion++ Protocol Works on Monero

    How the Dandelion++ Protocol Works on Monero

    (Please note: this article was originally posted on the monerooutreach.org site, which has since gone offline. It’s an interesting article, so I am mirroring it here.)

    “Dandelion++ stops bad actors from linking your IP address to your Monero transactions.” – 2nd of March, 2020

    Monero stands on its Peer-to-Peer (P2P) communication network. The network’s blockchain-aware computers – called nodes – share the information that powers Monero, such as node addresses, historical blockchain data, blocks as they are mined, and new transactions to be added to blocks.

    The nodes are identified using Internet Protocol (IP) addresses, exposing the risk that observers can connect IP addresses to transactions, deanonymizing the data they contain.

    Dandelion++ is a method for hiding this connection and was deployed to the network in May 2020. This article describes how Dandelion++ works and what it does for users of Monero.

    Monero’s P2P Network

    Monero has two conceptual parts:

    1. A P2P network
    2. Applications that run on this network

    Applications deal with addresses, keys, and transactions, while the network organizes and ensures the flow of information.

    To understand Dandelion++, it is important to consider both the P2P network’s structure and the way wallets use it to communicate transactions.

    Its structure comprises thousands of nodes across the globe—tens of thousands if passive nodes are included—each one connected over the Internet to usually only a small group of other nodes called peers [1]. Nodes communicate with their peers using the same Transmission Control Protocol (TCP) protocol used by Web browsers and Web servers. A node’s peers appear random and need not be close geographically. A common number of peers is eight, but some nodes have hundreds, with each node finding its peers by first asking special master nodes for their peers, then asking those for new peers, and so forth.

    The result is a network of many computers, each communicating through TCP with only a scattered, usually limited, collection of the others.

    A Monero wallet must communicate with one of these nodes as a gateway to the P2P network. Some wallets, like the official GUI wallet, can run their own node, while others, like Menerujo on a smart phone, always use a remote node. Wallets spend Monero by creating and broadcasting a transaction via its gateway node, with the goal that the transaction eventually finds its way to a miner’s node for inclusion in a mined block. Each transaction holds information that is limited but contains some meaningful data, including a set of possible sources of spent funds.

    Right now, the Monero node starting the broadcast of a new transaction uses a process called flooding. It communicates the transaction to all its peers, who in turn communicate to all their peers, and so forth, with some checks to prevent redundant communication. The information travels in all directions over the network like a wave. Some cryptocurrencies, like Bitcoin, randomize the timing of this broadcast, but Monero does not.

    The Problem

    Your IP address can tell a lot about you. (For a sample of what is known about your IP address, you can visit an IP information site like whatismyipaddress.com.) With information from your Internet Service Provider (ISP) or Virtual Private Network (VPN) provider, as the case may be, it might identify you by name. Any connection between your IP address and the transactions you create leaks information—even the mere act of making Monero transactions is probably not something you want strangers to know. The problem is that the flooding of transactions over the Monero P2P network lets others make just this transaction-to-IP-address connection [2].

    Connecting an IP address to a transaction isn’t easy or flawless. It takes many observers and lots of work. But using a botnet, for example, connected to the Monero P2P network allows calculation of a likely transaction origin through analysis of timing and comparison with information known about peers. When there is a loud noise, you know which way to look because your brain extracts the direction from the timing and distortion of the sound in each ear. Analysis on flooded cryptocurrency packets received at different locations lets a spying adversary do the same. Transaction creation is like a loud noise for botnet nodes that are like ears.

    Dandelion

    To address this problem, esteemed researchers at the University of Illinois first developed a set of techniques they called Dandelion [2]. The initial focus was on Bitcoin, but it applies to Monero as well. The idea with Dandelion is to first route transactions to a remote node in a special undetectable way before initiating the flooding.

    The Dandelion authors delved into the theory and practice of using botnets to find sources of cryptocurrency transactions. This included the creation of mathematical models for anonymity (please see [2] for detailed information) that were used to analyze three propagation techniques:

    1. Basic flooding (Monero’s method)
    2. Randomized flooding called diffusion (Bitcoin’s method)
    3. Diffusion by proxy

    The last technique first forwards a transaction to a random node, which then broadcasts it using diffusion.

    All three techniques were found to be inadequate using the authors’ mathematical models.

    To address this inadequacy, the authors proposed Dandelion. Dandelion defines a process for finding a proxy node to broadcast, called the anonymity (or stem) phase. And it establishes another process for broadcast, called the spreading (or fluff) phase. In general, the two phases use different sets of peer connections with the important difference that the anonymity phase connection set changes with time. The descriptive name Dandelion comes from the process of first seeking out a proxy node along a special linear search path, then from this proxy node spreading the information rapidly and symmetrically—the shape of information flow resembles a dandelion.

    Dandelion, analyzed using the authors’ mathematical models, when used by all nodes proves to resist spying by a team of nodes that are passive observers. With Dandelion, a botnet participating honestly in the P2P network cannot reliably link transactions with IP addresses.

    Dandelion++

    However, an adversary seeking to link transactions with IP addresses may not be passive, and may not follow the rules of the network. Some honest nodes may not run Dandelion. Motivated by the growing market for wide-area cryptocurrency analysis, such as by Chainalysis [4], the authors revisited the assumptions from their earlier work and, with collaborators, a year later developed Dandelion++ [3]. Dandelion++ tweaks Dandelion to resist large-scale rule-breaking deanonymization attacks.

    The creators of Dandelion++ modeled an adversary as a botnet with spy nodes distributed throughout the network, forming some significant fraction of the overall network. In their model, these nodes need not follow the rules. They can generate any number of outbound connections to any honest or adversarial nodes. They use all available information, including timing and the addresses of senders. It is in this very hostile environment that Dandelion++ succeeds in protecting anonymity.

    Dandelion++, like Dandelion, has a stem and fluff phase. In the new stem phase, to implement dynamic connectivity, it proceeds in discreet intervals, called epochs. Each node switches epoch independently, typically every few minutes. With each new epoch, a node picks two new relay connections at random from its outbound connections. Then whenever the node creates its own transaction it sends it over one of these two relays, always making the same choice for a given epoch. And whenever it gets a transaction from another node for forwarding during stem phase, if it is a relayer (more on this below), it sends it out randomly over one of the two relays.

    The fluff phase in Dandelion++ uses diffusion, the flooding process where the timing of the communications are random to make it harder for spy nodes to locate the source. Once a transaction has started the diffusion process it continues to propagate using diffusion, never going back to the stem phase. Diffusion starts, though, in special way with Dandelion++. For each epoch, a node classifies itself as either a relayer or a diffuser. The mode is determined at random at the start of the epoch. If a node is a diffuser, whenever it is given a transaction to relay as stem phase, it instead broadcasts it using diffusion, thereby starting the fluff phase.

    There is an additional, complementary piece to Dandelion++ called the fail-safe mechanism. Each node that relays a transaction during stem phase starts a timer for that transaction. If a time threshold passes without the node receiving the same transaction back during a fluff phase, it starts its own fluff phase. This serves two purposes: It frustrates attempts at deanonymization using timing, and it defeats so-called black-hole attacks where adversarial nodes discard transactions during the stem phase rather than relaying them.

    With these techniques in place, Dandelion++ gives formal guarantees of resistance to deanonymization. It achieves this using local techniques, unlike the Tor network, which requires global reasoning. Each elegant Dandelion++ node makes its own decisions about its behavior. The result is a fast and efficient, yet effective, technique for preventing even sophisticated adversaries from connecting IP addresses to transactions.

    Integration with Monero

    Though Dandelion++ was explicitly developed for Bitcoin, it was recently applied to Monero by developer Lee Clagett (vtnerd), with testing and review by developer moneromooo. Discussions and file changes made by these preeminent Monero developers can be seen as part of the source control pull request [5]. A pull request is part of the formal process by which new code enters the Monero code base. Though the Dandelion++ pull request was approved by moneromooo, at the time of this writing it has not yet completed all reviews and has not been merged into the Monero codebase.

    Dandelion++ is used by default, though it is possible to turn it off by defining the probability of entering fluff mode probability to 100% in the C++ code file cryptonote_config.h and recompiling.

    Importantly, even in this case of targeted recompilation, the new release uses diffusion, with its random delays, rather than basic flooding.

    There are some minor downsides and limitations. Dandelion++ adds delay to the propagation of transactions. This comes from multiple sources discussed by the Dandelion++ authors [3]. First, the existence of the stem phase adds delay, possibly a few seconds, based on the authors’ analysis and experimental evaluations. Diffusion adds random delays during the fluff phase, typically less than a second. Should the network be subject to a black-hole attack, the confirming wait by the initiator could delay transmission by minutes. These delays are not expected to affect the network materially. Also, Dandelion++ does not encrypt the P2P packets, and does not protect against ISP/VPN-level spying—for this, you can use Tor.

    Summary

    Dandelion++, developed originally for Bitcoin, and applied to Monero by developer Lee Clagett, prevents adversaries from connecting IP addresses to Monero transactions even in large-scale sophisticated attacks.

    It focuses particularly on resistance to botnets. Dandelion++ uses stem and fluff phases that make the flow of information take the shape of a dandelion, hence the name. This makes it hard for observers to locate the source of a transaction. This feature enhances Monero’s privacy features and carries Monero forward on its path of continual improvement.

    Learn More

    Sources/References

    [1] Exploring the Monero Peer-to-Peer Network, T. Cao, J. Yu, J. Decouchant, X Luo, and P. Verissimo, eprint.iacr.org/2019/411.pdf.
    [2] Dandelion: Redesigning the Bitcoin Network for Anonymity, S.B. Venkatakrishan, G. Fanti, and P. Viswanath, SIGMETRICS ’17, June 5-9, 2017, Urbana-Champaign, publish.illinois.edu/science-of-security-lablet/files/2016/07/Dandelion-Redesigning-BitCoin-Networking-for-Anonymity.pdf
    [3] Dandelion++: Lightweight Cryptocurrency Networking with Formal Anonymity Guarantees, G. Fanti, S.B. Venkatakrishnan, S. Bakshi, B. Denby, S. Bhargava, A. Miller, and P. Viswanath, arXiv:1805.11060v1, May 28, 2018, arxiv.org/pdf/1805.11060.pdf
    [4] Chainalysis, chainalysis.com.
    [5] Adding Dandelion++ support to public networks: #6314, github.com/monero-project/monero/pull/6314.

  • Monero Multisig How-To Use Guide – 2023

    Monero Multisig How-To Use Guide – 2023

    Note: This post is a copy of my pull request to the monerodocs site to update the multisig documentation section.

    Update: monerodocs is no longer live, but it has been mirrored to:

    The main caveat to be aware of, prior to using multisig, is to read the warning that’s displayed by default when you try to use multisig – and make sure that you understand it, and are ok to proceed on that basis.

    This article is my attempt to document the steps for using the multisig commands. However, you use them at your own risk.

    Intro

    In cryptocurrencies, multisig feature allows to sign a transaction with more than one private key. Funds protected with multisig can only be spent by signing with M-of-N keys.

    Example use cases:

    • shared account (1-of-2; both husband and wife individually have full access to their funds)
    • consensus account (2-of-2; both husband and wife must agree to spend their funds)
    • threshold account (2-of-3; an escrow service is involved as an independent 3rd party, to co-sign with either the seller, or with the buyer, if seller and buyer do not agree)
    • secure account (2-of-3; a single owner controls all 3 keys but secures them via a different means to diversify risks)
    • arbitrary threshold account (M-of-N; some cryptocurrencies provide full flexibility on the number of signers)

    Monero’s multisig design

    Monero doesn’t directly implement multisignatures (at least not in a classical sense). Monero emulates the feature by secret splitting.

    Transactions are still signed with a single spend key. The spend key is a sum of all N private keys. The rationale for such design is to decouple multisig from ring signatures.

    Let’s consider the 2-of-3 scheme. We have 3 participants. Each participant is granted exactly 2 private keys in a way that pairs do not repeat between participants. This way any 2 participants together have all 3 private keys required to create the private spend key.

    Multi-signing is a wallet-level feature, and there is no separate multisig address type. This means there is no way to learn from the blockchain which transactions were created using multiple signatures.

    After multisig wallet setup every participant ends up knowing the public address and private view key. This is necessary for participants to recognize and decipher transactions they are supposed to co-sign.

    Multisig wallet setup

    Multisig is currently only available via the Command Line Interface (CLI). This tutorial will assume you have some familiarity with the CLI before beginning.

    In this example we will use a 2-of-3 multisig scheme, as it generalizes well.

    Initially, while you’re becoming familiar with multisig, it’s suggested you begin by using stagenet, such that no valuable Monero are lost.

    If you’re not already familiar with stagenet, it is a separate, but functionally identical instance of the Monero network, created for testing purposes. To use it you simply add the –stagenet flag when creating and running your stagenet wallet.

    1: Create a new wallet

    To begin you will need to create a new wallet. Multisig cannot be applied to a wallet that has previously received funds.

    First you create a new wallet. The below the code assumes you’re using a remote node, but using a local node is ideal:

    ./monero-wallet-cli --stagenet --daemon-address address-URL  # Create your wallet

    n the above, replace address-URL with the actual URL that you want to connect to. At the time of writing, a list of remote nodes can be found at: monero.fail. The default view shows mainnet servers, so make sure to filter by stagenet servers first.

    Next, enable multisig via:

    set enable-multisig-experimental 1

    If you don’t set this flag, then try to issue the first command, you will see:

    Error: Multisig is disabled.
    Error: Multisig is an experimental feature and may have bugs. Things that could go wrong include: funds sent to a multisig wallet can't be spent at all, can only be spent with the participation of a malicious group member, or can be stolen by a malicious group member.
    Error: You can enable it with:
    Error:   set enable-multisig-experimental 1

    This warning message is there to let people know that Multisig is still an experimental feature and may have bugs. You can read more about this message below.

    Recommendation: By default the CLI applies a screen timeout of 90 seconds. After which, you will be asked to input your password to continue using the wallet. Unfortunately, once the wallet times out, it interrupts the multisig creation process.

    To extend the timeout to 10 minutes, use the command:

    set inactivity-lock-timeout 600

    To disable the timeout entirely (for this session only), use the command:

    set inactivity-lock-timeout 0

    2: prepare_multisig

    To begin, every participant independently generates initialization data, which is not an address.

    Participants then send their initialization data manually to all other participants over a secure channel.

    However, if you’re creating the multisig wallet without external participants, then you simply transfer the data between terminal windows.

    Begin by using the command:

    prepare_multisig

    Note: if you try to use this command on a wallet that has already been used, you will see the error message:

    Error: This wallet has been used before, please use a new wallet to create a multisig wallet

    After prepare_multisig you will see a message that looks similar to the below:

    MultisigxV2R1C9Bd2LNS9oDXLwDWbVbWc53nfUJpFnQqPDDtHksVVrY33DADgnhKetL5Swgk477uP1AENAy2pz11zW73NGqZojTai2TSDyARK3QR8uVt1t26oW21mFdZtd8iuNqTPBjuCc2q9jaRzqUG75rXtnn8eD5DwJX6NaMP63o2n2fta7dXZcpM
    Send this multisig info to all other participants, then use make_multisig <threshold> <info1> [<info2>...] with others' multisig info
    This includes the PRIVATE view key, so needs to be disclosed only to that multisig wallet's participants 

    The long string that begins Multisig is important, and will be shared with the other wallets in the next step.

    Before you move to the next step, you’ll want to run the prepare_multisig command on the rest of the wallets you want to use in your multisig setup. For example, 2 more if you’re doing a 2/3 multisig.

    3: make_multisig

    This command is where you set the threshold for your multisig wallet and then pass the initialization data from the other participants. The initialization data is the long string beginning Multisig mentioned above.

    For example, if you’re doing a 2 of 2 multisig, then your threshold is 2 and you’ll pass 1 piece of data. If you’re doing a 3 of 5 multisig, then your threshold is 3 and you’ll pass 4 pieces of data.

    Continuing with our 2/3 multisig example, you would then type into your CLI:

    make_multisig 2 <data1> <data2>

    Which in practice would look similar to:

    make_multisig 2 MultisigxV2R1MyhE1hgED7AFwytsfW44s7G4abNHFKhwfJH9kvB2Q7xNVBdJAyY9gm7eJkHVRo1T3Hb6PeYsyzUrqQsmpBByDq4iRywanpRLxLN2JKuvKPBDayAywAHBzGxdnGiyoXhLdnZiU6Azy3VNocwH1jgfFvYDUUCo7H8mFacnLUFVLC8LjEfz MultisigxV2R1CzwgGBTPxb51nWfvLg7mYPRBnqDgppZq85E745qR1NvGNCLBaHSCmUQ4JRb41tW9PUerAgz9pKHJ5NpKgE6vsZnpLJkCP3u4zwcXJW3UHjABc446jdQegP1hyHnGgJpah8RmdeLcLCAqa6WXgt3xJoz6QF5o66tnCiyJkYyebjWeXV2y

    If you were doing a 3/5 multisig, you’d instead run:

    make_multisig 3 <data1> <data2> <data3> <data4>

    Once this command is run on each wallet, you will then receive a second round of initialization data, that looks similar to:

    Another step is needed
    MultisigxV2Rn1LVYohry597ZfzPhWnuL6qcueBNdq4ivrP7zqDm4W5eKBhxgdcERcSvFs8F5EkLSuYFyKfBEeh4Fui6xHTeRqb7cWshXY96WruxMaSxMafTdPn48ko52e8UHvA4kWwpuPidBYg5dyVWoQLWgqCMDANxWnjhenw6HTwpT96yB8n1a16oQEYyQWg66r2sZHi9RMmivTsihnMq66rTHKPKKau1SHButDwQ

    Side note: If you make a mistake, such as inputting the wrong threshold or missing out some initialization data, there isn’t an undo function. That individual wallet will get created incorrectly, and you will need to re-do it.

    4: exchange_multisig_keys

    With the threshold established in the prior command, the exchange_multisig_keys command simply takes the init data from the other participants, no threshold parameter needed.

    For example:

    exchange_multisig_keys <data1> <data2>

    It is either run once or twice in total.

    Once if your wallet has the same threshold as the total number of participants, e.g. 2 of 2.

    Twice if you have a different threshold, e.g. 2 of 3.

    Continuing our 2/3 multisig example, after inputting the above exchange_multisig_keys command, we would then see:

    Another step is needed
    MultisigxV2Rn1WCSNqbsjuTXaPVfFsk3ekFF444yFN5PMCXcQHv1Pv794ZdkDZRnfVGgeP5JwpysR3ingQtQMMnmQDEXnP4qgdnh3SU2NXvfe7kMaSxMafTdPn48ko52e8UHvA4kWwpuPidBYg5JdJwdEAh8Ud7kBFX34zP33ZBbrYXcQbQKTcM3XQ8AEP8bVXHVqQSGzkAkjZRp3H63k6ZSXSYdH9WaC9pdr9FV3tx
    Send this multisig info to all other participants, then use exchange_multisig_keys <info1> [<info2>...] with others' multisig info

    Then for a second, and last time, we input:

    exchange_multisig_keys <data1> <data2>

    And we receive back:

    Multisig wallet has been successfully created. Current wallet type: 2/3
    Multisig address: 56MD1L4zky3bFXDQb9qvSx7PDbg8F4x1HgPrFNrDnGnYDqFZcWGswWc1p2moFa1F44ccJniY9Wkzk6urkJbEDvubHqYtkcs

    This results in a wallet public address and private view key to be known for all participants.

    So if you’re the sole participant in the multisig setup, you’ll know it has worked when you see the same multisig address across all the wallets.

    Receiving funds

    1: Funding the Multisig Account

    Addresses created by a multisig wallet operate the same as normal, non-multisig addresses. This means:

    • Each wallet can create subaddresses independently, no collaboration needed.
    • All participants can see incoming funds as they share the private view key.

    The main difference comes when trying to spend funds from a multisig wallet. See the Spending Funds section below for how to do this.

    2: Check Account Balance

    To check the account balance, open one of the multisig wallets and type the refresh command.

    This will refresh the wallet and display your balance. The output will look similar to the below, but with a different amount:

    Starting refresh...
    Refresh done, blocks received: 0                                
    Currently selected account: [0] Primary account
    Tag: (No tag assigned)
    Balance: 10.000000000000, unlocked balance: 10.000000000000 (Some owned outputs have partial key images - import_multisig_info needed)

    If you see that last sentence:

    (Some owned outputs have partial key images - import_multisig_info needed)

    This means that you haven’t synchronized your wallet with the threshold amount of wallets needed (1 other in the case of 2/3 multisig) for the outputs to become spendable.

    You can also use the command show_transfers to display a list of funds received and the transfer date, with the output looking similar to:

     1263592     in unlocked       2023-01-09 21:13:59      10.000000000000 c5a3eec347401b1e263f45577b840c036568aa841eb2ebc6eb1332c1bc281f28 0000000000000000 0.000000000000 76Matb:10.000000000000 1 - 

    Spending funds

    Prior to explaining the process for spending multisig funds, it may help to have a high level overview of the process. There are two core steps:

    1) First, the sharing of partial key-images – At minimum, the spender needs to get a partial key image from the people (1 or more) who will sign the transaction with him later. They need to export a file and share it with the future spender, who then imports the file to their wallet.

    2) Second, creating, signing & submitting the transaction – A transfer is created, written to file, and then this file needs to be signed by the co-signers, before it can lastly be submitted to the network.

    Preparation for spending

    Preparation Step 1: Export partial key image

    Prior to constructing a transaction, the spender will need to get a partial key image from the wallet or wallets which will later co-sign the transaction.

    In our 2/3 multisig example, the spender needs to get 1 partial key image, because the threshold is 2.

    The wallet that will provide the partial key image needs to enter the command:

    export_multisig_info key1

    Where key1 can be any filename. The output will then be:

    Multisig info exported to key1

    The file will be saved to the present working directory in the terminal.

    It then needs to be shared with the wallet which will create the spending transaction.

    Preparation Step 2: Import partial key image

    Now that the spending wallet has the partial key image it can import it. Assuming the file is in the present working directory, the command would be:

    import_multisig_info key1

    If two or more key images were being imported, you would specify them side by side, such as:

    import_multisig_info key1 key2 key3

    After issuing that command, the wallet will display how many new inputs it has verified, for example if 1 output is verified:

    Height 1263592, txid <c5a3eec347401b1e263f45577b840c036568aa841eb2ebc6eb1332c1bc281f28>, 10.000000000000, idx 0/1
    Multisig info imported. Number of outputs updated: 1

    Spending

    Spending Step 1 – Create Unsigned Transaction

    Creating a new transaction can be done by any of the multisig wallets. However, to avoid weird things from happening, only do it for 1 transaction at a time. If anything weird happens, re-do steps 1 & 2 again to fix.

    The wallet initiating the transfer should create a transfer, as per the normal CLI transfer process:

    transfer <address> <amount>

    So for example:

    [wallet 56MD1L]: transfer 72Qv1pqug5rX1qS77Bj9C4XBbrvdYRJLM6769bseDytqVZWV2iQxGDnZ85KmubdiCQgtZjeb4fPdUNGq8Foae5b1Bo77T64 5
    Wallet password: 
    
    Transaction 1/1:
    Spending from address index 1
    Sending 5.000000000000.  The transaction fee is 0.000167640000
    
    Is this okay?  (Y/Yes/N/No): Yes

    The output will look like:

    Unsigned transaction(s) successfully written to file: multisig_monero_tx

    The present working directory will now contain a file named multisig_monero_tx, which should then be shared with the co-signer.

    Spending Step 2 – Sign Transaction

    The wallet that has been chosen to co-sign the transaction now needs to run the command:

    sign_multisig multisig_monero_tx

    Which will result in an output similar to:

    Loaded 1 transactions, for 10.000000000000, fee 0.000167640000, sending 5.000000000000 to 72Qv1pqug5rX1qS77Bj9C4XBbrvdYRJLM6769bseDytqVZWV2iQxGDnZ85KmubdiCQgtZjeb4fPdUNGq8Foae5b1Bo77T64, 4.999832360000 change to 56MD1L4zky3bFXDQb9qvSx7PDbg8F4x1HgPrFNrDnGnYDqFZcWGswWc1p2moFa1F44ccJniY9Wkzk6urkJbEDvubHqYtkcs, with min ring size 16, dummy encrypted payment ID. Is this okay?  (Y/Yes/N/No): y
    Transaction successfully signed to file multisig_monero_tx, txid 82132a4302188b15c87916c05df79755dafb9ada78c39164937c246a4c2dee0a
    It may be relayed to the network with submit_multisig

    Note: Once you synchronize the partial key images, there is a certain time window by which you can create and send your transaction. I’m unsure exactly how long the time window is. If you leave it too long you will see the output:

    Error: Multisig error: This signature was made with stale data: export fresh multisig data, which other participants must then use

    The solution is to re-do steps 1 and 2 of the preparation for sending. Once that’s completed, you can return to the sending steps.

    Spending Step 3 – Submit Transaction

    Now that your transaction has been co-signed, it is possible to submit it. You can do this from any of the wallets, as long as they have the co-signed multisig_monero_tx file. Using the command:

     submit_multisig multisig_monero_tx

    You will then see an output similar to:

    [wallet 56MD1L]: submit_multisig multisig_monero_tx
    Wallet password: 
    Loaded 1 transactions, for 10.000000000000, fee 0.000167640000, sending 5.000000000000 to 72Qv1pqug5rX1qS77Bj9C4XBbrvdYRJLM6769bseDytqVZWV2iQxGDnZ85KmubdiCQgtZjeb4fPdUNGq8Foae5b1Bo77T64, 4.999832360000 change to 56MD1L4zky3bFXDQb9qvSx7PDbg8F4x1HgPrFNrDnGnYDqFZcWGswWc1p2moFa1F44ccJniY9Wkzk6urkJbEDvubHqYtkcs, with min ring size 16, dummy encrypted payment ID. Is this okay?  (Y/Yes/N/No): y
    Transaction successfully submitted, transaction <82132a4302188b15c87916c05df79755dafb9ada78c39164937c246a4c2dee0a>
    You can check its status by using the `show_transfers` command.

    The transaction has now been broadcast to the network. If you want to create another one, you will need to go back to the preparation stage and re-sync the partial key images.

    Mnemonic Seeds

    With a regular wallet is it possible to create a mnemonic seed that you can backup, and later use to recreate the wallet.

    Fortunately, multisig wallets have the same feature. The only difference is that the seed is a long string of letters and numbers, rather than a set of dictionary words. Unfortunately, it needs to encode too much data to fit neatly into the regular mnemonic seed dictionary output.

    To access your wallet seed, open the wallet within the CLI and type seed. You will see an output similar to this:

    NOTE: the following string can be used to recover access to your wallet. Write them down and store them somewhere safe and secure. Please do not store them in your email or on file storage services outside of your immediate control.
    
    020000000300000051512b513c603a023df44e2400ad58b3f4751e2dcba44b1d4316be5adffd330b773b3818a07ab6ccc4ffcee1feed5526296b52f5ea0844eb8562cb3e63e8154c5c91f0cfd102a830d8692cec64e662f7ffac4cb82dd950c891a92a22dc80930ab78dd01a1ec7ed04d90eff530d2af9d4e40670576863492357727c6615620e95d2e962632518d958040b710474a4c944cb3a286e3fe9ad0b1d651ff6d8b4c50c81a74423650210bbcb7b427435e90b3eb494cb108bd148cab56e5352303d55070d35e703217b7b051a96af50c1c912bc372f65a4ffa93631ae009a544106bd5dfcf477573387f159ce6cae10fb2ffe63f55e75ed94d0893ece9b67b0a1cf0fc2034ca04ef7c862494a13237bfaa8e822f824ea59de561353f2ac01fbc279280c

    Note: This seed will only recreate the individual wallet it is created from. Each wallet would need to be backed up separately.

    About the experimental feature warning message

    Prior to a pull request in mid 2022 (PR #8149) Monero’s multisig feature had some known bugs.

    PR #8149 fixed these issues, including findings identified by an independent audit of multisig.

    However, there is still a possibility of a yet unknown bug that would allow a malicious group member, in a worst-case scenario, to acquire all funds within the multisig wallet.

    Two potential steps to get Monero’s multisig implementation further tested and more secure would be the completion of a formal specification and a third-party audit. However, there is currently no timeline for this.

    It’s worth noting that the risks implied by this unknown bug scenario depend upon the individual use-case. For example:

    a) If one planned to use multisig in collaboration with other people, then this risk is there.

    b) If one planned to use multisig solely to shard a cold wallet, and store it in multiple locations, then this risk may be lessened. On the basis that it requires two coincidences to come together:

    i) A malicious actor who has the capability to exploit an unknown bug in Monero’s multisig.

    ii) This malicious actor is then able to access one of the, presumably secured, multisig wallets.

    However, if an exploit was made public knowledge, then the risk increases, because the attacker no longer needs to figure out the exploit, they simply need to locate your wallet and then implement the public exploit.

    Thus, if one took the risk to use multisig in method b), they would be prudent to stay up to date on multisig development. Such that they would learn quickly if such an exploit was discovered.

    References

    The below guides are very detailed, and were formative in the creation of this document. Note that they are both a little out of date, as a few of the CLI commands have been updated in the interim.

  • Are Ledger and Trezor seeds cross-compatible for Monero? No.

    Are Ledger and Trezor seeds cross-compatible for Monero? No.

    So, you have a Ledger (or Trezor) seed, and you want to use it with a Trezor (or vice-versa, a Ledger). Will your old seed work in the other device, in order to recover your Monero keys?

    Answer: No

    Unfortunately, Ledger and Trezor ended up using different key derivation algorithms. Such that using the same 24 word seed results in different keys between the devices.

    To quote a Trezor developer on Github:

    In our upcoming Monero implementation for Trezor, we plan to use SLIP-0010 as our primary derivation method.

    If I’m not mistaken the current Ledger implementation uses BIP-32 scheme with secp256k1 and then converts the secp256k1 point into a ed25519 point. SLIP-0010 takes a different apporach and specifies how to derive a BIP-32-like path on ed25519 curve directly.

    Does Monero have any opinion on this? We believe the Monero community should agree on some “standard” to allow compatibility between different HW vendors. Failing to do so would lead to an inconsistency where the same mnemonic seed does not converge to the same wallet.

    So it appears that Ledger picked one derivation method, and then later, Trezor picked another.

    That’s unfortunate – but there we go!

    To quote one user in the thread:

    Ledger Trezor Monero Compatibility Notes

    For a user that has a Trezor mnemonic seed, if they want to extract the keys, then there is an app on Github made by a developer who has done work for Trezor, that supposedly supports this. See:

    https://github.com/ph4r05/monero-agent/blob/master/PoC.md#trezor-seeds

    Follow the app’s documentation for how to do this safely.

  • Doge coin emission rate – and how it compares to Monero

    Doge coin emission rate – and how it compares to Monero

    Doge has gone from a joke, to quite an expensive asset. As a Monero fan, it was interesting to see another coin with a perpetual emission rate gain traction. Specifically, Doge’s emission rate is 10,000 new coins every block (Doge blocks are every 1 minute), forever. This is in contrast to Bitcoin, where the there is a max emission of 21 million coins, after which no more will be created. Below I’ve mapped out how the emission rate looks for the next 20 years for Monero and Doge. XMR vs DOGE emission for the next 20 years And then for the next 100 years… XMR vs DOGE emission for the next 20 years Despite Doge’s inflation rate starting off much higher than Monero’s, it’s notable that, over a long enough time period, they end up closer together, and both sub 1%. The spreadsheet used for the calculations can be found here – see the tab named “XMR vs DOGE Annual Increase”. Sharing just in case anyone else is curious about this.

  • Pomp Recommended Books – Bitcoin Focused

    Pomp Recommended Books – Bitcoin Focused

    In a recent interview with Lex Fridman, Anthony Pompliano (Pomp) described the books he found useful when learning about Bitcoin.

    Whilst I don’t agree with everything Pomp says, I do find his ideas interesting, so have made an effort to list down the books he recommended below.

    #1 – The Bitcoin Standard

    The Bitcoin Standard – The decentralized alternative to central banking by Saifedean Ammous

    The Bitcoin standard book

    Pomp suggests people start with this book, because “it lays out the picture nicely”. It focuses on:

    • Brief history of money
    • What is money – the need for sale-ability over time, space and scales
    • What stock to flow is, and why it’s important
    • The problems with government issues “fiat” money ($, €, ¥, £)
    • How things were previously the gold standard
    • How Bitcoin fits in

    Personally I’ve read it, found it useful, but acknowledge it’s a heavy read. For people with less time, who want a quicker overview, I recommend this blog post:

    #2 – Bitcoin: Hard Money You Can’t F*ck With

    Bitcoin: Hard Money You Can’t F*ck With – Why Bitcoin will be the next global currency by Jason A Williams

    Book cover

    Pomp mentioned this book was written by a friend of his, but didn’t mention much more, so will leave the blurb description below:

    Book intro:

    No-one controls it. No governments, no companies, no central banks, no money printing. It’s a revolution as big as the internet. And it’s never been hacked.

    Not only was bitcoin the best-performing asset on the planet in 2020, it quietly established itself as the next global reserve currency as central banks around the world desperately printed their money into oblivion.

    Hard Money You Can’t F*ck With explains bitcoin in simple, readable terms and maps out how this ‘magic internet money’ will grow into the best form of money we’ve ever had.

    Description via Goodreads

    #3 – Layered Money

    Layered Money – From Gold and Dollars to Bitcoin and Central Bank Digital Currencies by Nik Bhatia

    Book cover

    Pomp didn’t describe what sets Layered Money apart from the rest, or why he mentioned it in particular, so will leave the blurb description below.

    Nik Bhatia takes us into the origins of how money has evolved to function in a “layered” manner. Using gold as an example of this term, he traces the layers of this ancient currency from raw mined material, to gold coins, and finally to bank-issued gold certificates. In a groundbreaking manner, Bhatia offers a similar paradigm for the evolution of digital currencies. Bhatia’s analysis begins in Renaissance Florence with the gold Florin coin and a burgeoning banking culture, continues with the evolution of central banking, and concludes with a vision for the future of our international monetary system. As central banks around the world prepare to launch their own crypto-competitors, Bhatia illustrates how the invention of Bitcoin created a seismic shift in money and merged the monetary and cryptography sciences.

    Description via Amazon.com

    #4 – Bitcoin & Black America

    Bitcoin & Black America by Isaiah Jackson

    Book cover

    Book description:

    Bitcoin and Black America is a dynamic new book that explores the synergy between black economics, Bitcoin and blockchain technology. The global financial system is changing and the digital revolution will not be televised.

    We explore how to incorporate cryptocurrency in your business, job and educational institution. This book also outlines the need for separation from the racist banking system and a comprehensive list of black professionals actively working in the Blockchain industry.

    Description via Goodreads

    #5 – The Price of Tomorrow

    The Price of Tomorrow – Why deflation is the key to an abundant future by Jeff Booth

    Book cover

    The price of tomorrow makes the case for a better and more prosperous world simply by accepting the natural order of falling prices and fast-improving technology. The book is entirely free of jargon, ideology, and politics, yet pulls no punches when it comes to describing the fiscal and monetary mess we’re in. But it is an optimistic book, with a message for every worldview: deflation is a good thing, it is inevitable, and we should embrace it rather than fight it!

    Description via The Mises Institute

    Non-Bitcoin Related

    Next is Pomp’s #1 favorite book he’s ever read, that doesn’t mention a word about Bitcoin.

    The Dao of Capital – Austrian Investing in a Distorted World

    The Dao of Capital – Austrian Investing in a Distorted World by Mark Spitznagel

    If this is Pomp’s #1 favorite book – it seems worth a read. I’ve personally added it to my “to read” list.

    Book cover

    Spitznagel is the first to condense the theories of Ludwig von Mises and his Austrian School of economics into a cohesive and, as Spitznagel has shown, highly effective investment methodology. From identifying the monetary distortions and non-randomness of stock market routs (Spitznagel’s bread and butter) to scorned highly-productive assets, in Ron Paul’s words from the foreword, Spitznagel “brings Austrian economics from the ivory tower to the investment portfolio.”

    The Dao of Capital provides a rare and accessible look through the lens of one of today’s great investors to discover a profound harmony with the market process–a harmony that is so essential today.

    Description via Goodreads

    When Breath Becomes Air

    When Breath Becomes Air by Paul Kalanithi

    Book cover

    Written by a guy dying of cancer and dealing with his own mortality. Pomp found it helps focus one on time being scarce, and the importance of using time for enjoyment and happiness.

    At the age of thirty-six, on the verge of completing a decade’s worth of training as a neurosurgeon, Paul Kalanithi was diagnosed with stage IV lung cancer. One day he was a doctor treating the dying, and the next he was a patient struggling to live. And just like that, the future he and his wife had imagined evaporated. When Breath Becomes Air chronicles Kalanithi’s transformation from a naïve medical student “possessed,” as he wrote, “by the question of what, given that all organisms die, makes a virtuous and meaningful life” into a neurosurgeon at Stanford working in the brain, the most critical place for human identity, and finally into a patient and new father confronting his own mortality.

    What makes life worth living in the face of death? What do you do when the future, no longer a ladder toward your goals in life, flattens out into a perpetual present? What does it mean to have a child, to nurture a new life as another fades away? These are some of the questions Kalanithi wrestles with in this profoundly moving, exquisitely observed memoir.

    Description via Goodreads

    3 More Honorable Mentions

    Next are 3 books Pomp found impactful when he was 20 years old, sitting in the desert Iraq. He says at the time, he didn’t implement any of the content, but it helped catalyze a shift in how he thought about money, and what he wanted to do in his life.

    Roundup

    That ends the list of books that Pomp shared with Lex Fridman on his podcast. Hopefully it’s useful.

    Any questions, please leave them in the comments.

  • If Bitcoin eats the world… where does Monero fit in?

    If Bitcoin eats the world… where does Monero fit in?

    Recently Bitcoin has been reaching all time price highs, whilst Monero languishes behind at less than 1% of Bitcoin’s fiat value.

    Whilst I see clear value and use-cases in Monero, the market is clearly more bullish on Bitcoin currently.

    Therefore I wanted to ask myself, if things really go the direction of Bitcoin, which I see as a “worst case” (due to its lack of privacy and fungibility), is there still utility and value left in Monero?

    In this post we look at a scenario where Bitcoin takes over globally, and ask how this affects Monero.

    The Bitcoin Vision

    To begin, let’s look at what could be “the Bitcoin vision” for the future. This is my understanding:

    • Phase 1: Bitcoin goes through a price discovery phase over a number of years. Whilst its price keeps going up, it’s primarily used as a store of value, and isn’t used for daily transactions. This is where we are now.
    • Phase 2: Eventually, the Bitcoin price growth starts to plateau, volatility decreases, and it becomes more logical to use it as a medium of exchange.
    • Phase 3: With the price growth more stable, it’s now more logical to use Bitcoin as a medium of exchange. Bitcoin establishes itself as the dominant global settlement layer for payments. Then for day to day transactions, which the Bitcoin network is too busy and expensive to support, some combination of the below are used:\
      • Bitcoin second layers / sidechains
      • Other cryptocurrencies
      • Fiat currencies

    Where could Monero fit in?

    A Bitcoin pacman eating the world, and a monero logo with questionmark

    Bitcoin has a number of large flaws currently, including:

    1. Lack of privacy when transacting (even when you do complex and expensive coin joins, you still have less privacy than a standard Monero transaction)
    2. Lack of fungibility
    3. Lack of on-chain scalability (each block is limited ~2MB of data – which equates to around 2,600 transactions maximum per 10 minute block)
    4. High fees for making transactions
    5. Ability for miners to reject individual transactions (also known as miner censorship), using a black-list, due to the lack of fungibility

    As long as these issues persist, there will be an opportunity for a decentralized currency, such as Monero, to fill the gap.

    In particular, privacy and fungibility are critical for a currencies use as a medium of exchange.

    The 5 items above can be thought of as a simple, but non-exhaustive checklist of features to follow in Bitcoin.

    If the Bitcoin project is able to solve/ameliorate the above issues through upgrades or second layer solutions, it will gradually reduce the utility lead that Monero has over Bitcoin.

    How can Bitcoin solve these 5 issues?

    It’s my understanding that there are at least 2 main paths Bitcoin can take to solve these issues – network upgrades and off-chain solutions:

    1. Network upgrades are both the easiest, and hardest ways to improve things. Easiest, because it would solve the issues on the base layer, hardest because it requires accepting trade-offs and getting consensus from the developers and network participants.
    2. Off-chain solutions such as side chains and second layers are ways to abstract the transfer of Bitcoin, allowing you to later “settle” on-chain. Ultimately it’s not Bitcoin, but for many use-cases that may not matter.
      1. Side-chain example**:** Blockstream’s Liquid network is used by exchanges, who can make faster, cheaper transactions, where the amounts transferred are hidden.
      2. Layer 2 example: Lightning network is currently used by some online stores / betting sites to accept Bitcoin (see directory), without the high fees or slow confirmation times.

    Let’s look at the subject of network upgrades in more detail.

    Network Upgrades

    In the past, there was a narrative in the Bitcoin community that all altcoins were testnets for Bitcoin, and if any of the altcoins found a technology that was sufficiently useful, it would be adopted on Bitcoin.

    In practice however, this doesn’t appear to be happening.

    For example, the idea of confidential transactions has been around for a long time, and adopted by both Monero and Blockstream’s liquid sidechain. It’s great because it hides the amounts being transacted on the blockchain. So far the idea has been rejected by the Bitcoin community, because it makes auditing the supply more difficult, and the concept of “only 21m Bitcoins” is paramount.

    To audit a blockchain using confidential transactions, you can only sum up the inputs of new coinbase transactions (which is where miners find a block and get the block reward), and then you have to trust the maths that no Bitcoins were created or destroyed during transactions.

    So the narrative is shifting towards the discussion of trade-offs. Meaning that Bitcoin can’t adopt all the new technology, because it has to consider the trade-offs involved. Specifically with confidential transactions, losing the ability to 100% audit the supply seems too big a trade-off.

    That is likely to be the case for other potential upgrades also.

    So, next let’s look at an upgrade that *does* appear to be going ahead…

    Taproot

    Bitcoin art Taproot image via tbstat

    The Taproot upgrade may specifically help ameliorate issues #1 and #2 – privacy and fungibility.

    It will create a new type of Bitcoin transaction called P2TR (Pay 2 Taproot). These transactions will stick out on the blockchain, compared to the existing types. However, the cool thing about it, is that all Pay 2 Taproot transactions will then look the same, whether they’re a typical 1 in 2 out, 2 in 2 out transaction, or they’re a multisig transaction. Previously if you did a multisignature transaction, it was evident on the blockchain.

    This would theoretically allow you to use a privacy enhancing protocol such as CoinSwap (which utilizes multisig) and an observer would not be able to discern on the blockchain that the transaction used multisig.

    My guess is that this is only a partial privacy solution, and will still be far inferior to a regular Monero transaction. But I’m keen to keep learning and see what comes of it.

    Off Chain Solutions

    Bitcoin art - lightning inspired

    I’ve yet to see an off-chain Bitcoin solution that substantially enhances privacy and fungibility – but they may be coming.

    For example, Blockstream’s Liquid network is too centralised to be considered private.

    For now, the main thing off-chain solutions improve are the issues of poor on-chain scalability (#3) and high on-chain fees (#4). They do so by offering faster transaction confirmations, at lower fees.

    Conclusion

    I started this thought experiment with some concern that Monero may be squeezed out by Bitcoin.

    However, after looking at what Monero does better than Bitcoin, and surveying the Bitcoin landscape for solutions, I currently think that Monero is in a strong position to survive.

    Going forward I will keep the above 5 issues in mind, and try to keep tabs on how Bitcoin is addressing them.

    Currently I hold a small position in Monero, and thus have a financial interest in it surviving. But I’m aware that bag holding leads to tribalism, that can be a net negative for society and the cryptocurrency community overall.

    Ideally we should be focused on creating good, working solutions to problems, and not be distracted about where those solutions come from.

    Therefore, personal interests aside, if Bitcoin can actually solve these issues, then that’s a good thing for humanity as a whole.

  • Money is Time

    Money is Time

    You’ve heard the phrase – time is money.

    Well, money can also be thought of as time. More specifically, money is a way to represent people’s time.

    • $20 can buy you an hour of cheap labor on a building site
    • $30 can buy you an hour of someone’s time to clean your house
    • $200 can buy you an hour of an expensive programmers time
    • Etc etc

    Life in modern society without money is near impossible. So if you don’t have money, you need to spend your time getting hold of it.

    Once you have it, you can avoid spending time procuring it, and instead control to a greater degree what you spend your time doing.

    Money is time art
    Kudos to Zach Macey for the cool book cover illustration.

    Hopefully that’s fairly easy to conceptualize.

    If money is time, then we also need a way to price our time. But this is difficult in a society that has a monetary system where the quantity of money is constantly changing (typically increasing).

    Let’s say you were an electrician in USA, and you priced your time at $70 per hour.

    But then the US government create a $2.2 Trillion CARES Act stimulus package in 2020, and a $1.9 Trillion American Rescue Plan Act in 2021.

    These stimulus packages increase the price of stocks you were planning to buy – which were going to form part of your retirement plan.

    Now, in retrospect, maybe you should have been charging $75 per hour – but the size of the pie (monetary supply) changed beneath your feet.

    Illustrating the effect of money printing
    Money pie increase *not* to scale – but just meant as an illustration

    How could this mis-pricing of time be avoided?

    If there was a money pie with a fixed size, that couldn’t be expanded at the whim of bureaucrats, then this mis-pricing scenario could be avoided.

    Cryptocurrency offers this possibility.