Newly found Monero bug may impact transaction privacy, developers warn

Published at: July 27, 2021

Developers of privacy-oriented cryptocurrency Monero (XMR) have identified a bug that could potentially impact users’ transaction privacy.

On Monday, the official Monero Twitter account warned users of a “rather significant bug” that has been spotted in Monero’s decoy selection algorithm, a system designed to hide real output transactions among 10 decoys in a ring.

First identified by software developer Justin Berman, the bug causes a sufficient probability that users’ output transactions can be identified as the true spend among decoys if users spend funds immediately following lock time in the first two blocks, or 20 minutes after receiving funds.

The developers emphasized that the bug does not pose a risk to any information about addresses or transaction amount but rather only allows to trace the occurrence of an XMR transaction. “Funds are never at risk of being stolen. This bug persists in the official wallet code today,” Monero developers noted.

According to an XMR contributor on Reddit, the newly discovered bug impacts transactions that are from the past. To mitigate the potential privacy risks, Monero developers recommended waiting one hour or longer before spending newly received XMR until the community rolls out a fix in a future wallet software update to mitigate the potential privacy risks. A full network upgrade, or a hard fork, is not required to address this issue, the developers noted.

Related: Privacy coin Monero pumps 31% amid US taxation plans

Launched in 2014, XMR is a major privacy-focused cryptocurrency designed to support secure, private and untraceable transactions, using a special type of cryptography to ensure that all its transactions remain 100% untrackable and unlinkable. Monero is the 29th largest cryptocurrency by market capitalization and is the biggest privacy-centric digital currency by value. At the time of writing, XMR is trading at $222, down 3.8% over the past 24 hours, according to data from CoinGecko.

As previously reported by Cointelegraph, multiple global financial regulators have attempted to crack Monero’s privacy. Last year, the United States Internal Revenue Service offered a bounty of up to $625,000 to anyone who can trace Monero transactions.

Tags
Related Posts
Monero price rises 20% after Atomic Swap implementation
Monero (XMR), the largest privacy-focused cryptocurrency by market capitalization, has posted a 20% price surge following the launch of the Atomic Swap implementation program last week. On Friday, the Monero Project officially announced a rollout of the Atomic Swap implementation developed by the cross-blockchain protocol COMIT Network, aiming to simplify trades between XMR and Bitcoin (BTC). Following the launch of Monero Atomic Swaps, XMR has seen a notable surge, with its price rising from around $265 on the launch day to an intra-week high of $331. At the time of writing, the privacy-centric cryptocurrency is trading at $318, down around …
Technology / Aug. 24, 2021
Kraken to delist Monero for UK customers by the end of November
In an email quoted by Reddit users, Kraken, the world's eight largest cryptocurrency exchange by trading volume, announced it would be delisting privacy coin Monero (XMR) in compliance with regulations in the United Kingdom. The platform will cease all XMR trading activities, set XMR wallets to withdraw-only, and force-liquidate any existing XMR margin positions after the 26th of November. Through advanced cryptography, privacy coins like Monero obscure participants' public wallet addresses and payment amounts when their transactions appear on the blockchain, making it improbable, in the context of current technology, for forensic entities such as Chainalytics to digitally trace the …
Technology / Nov. 19, 2021
Monero community concerned as leading mining pool nears 51% of ecosystem's total hash rate
On Tuesday privacy coin Monero (XMR) mining pool MineXMR's hash rate surpassed over 1.4 GH/s, accounting for 44% of the hash rate of the XMR network. MineXMR has about 13,000 miners and charges a 1% pool fee. According to a screenshot from Archive.org, last August, the pool only contributed to 34% of the hash rate of the XMR network. The rapid rise in hash rate network has spooked some XMR enthusiasts, with Reddit user u/vscmm writing: "We need to talk with MineXMR to take some action right now! Please send an email for [email protected] to MineXMR admins to take action; …
Technology / Feb. 15, 2022
Monero community reaches consensus for July hard fork
As told by Monero (XMR) developers over the weekend, on July 16, the Monero network passed a community consensus to initiate a mainnet hard fork at block height 2,668,888. The popular privacy coin's hard fork will include increasing the chain's ring size from 11 to 16, adding view tags to outputs to reduce wallet scanning time, introducing bulletproofs and implementing fee changes. Raising the number of ring signatures is meant to ensure that transactions have a larger anonymity set, making it harder to reverse engineer the sources of a transaction. One developer pointed out that view tags could reduce network …
Adoption / April 18, 2022
BitBay Crypto Exchange to Delist Monero Due to Money Laundering Concerns
Cryptocurrency exchange BitBay will delist privacy-centric cryptocurrency Monero (XMR) due to money laundering concerns. The exchange announced the decision on Nov. 25, noting that the delisting will take place on Feb. 19, 2020. The exchange explained its decision “Monero (XMR) can selectively utilize anonymity features among projects. This feature of XMR is a subject to end of transaction support. The decision was made to block the possibility of money laundering and inflow from external networks.” On Nov. 29, the exchange will already stop accepting XMR deposits. Due to the upcoming Monero blockchain fork, XMR withdrawals will not be possible from …
Regulation / Nov. 26, 2019