Bawdy:ZEC 对比 XMR、暗网市场、Monero 的多头逻辑及更多 | TG Podcast
Bawdy 的多头逻辑首先是采用,而不是叙事:XMR 从约200美元涨至250-300美元的过程中,很大一段涨幅早于隐私赛道整体启动,录制时 Monero 接近400美元。 他认为,这轮上涨靠的是默认隐私、真实消费和循环经济,而不是交易所驱动的投机。依他看,这让 XMR 不太容易出现“memecoin 式暴涨”,但也意味着其价格底部更硬、长期韧性更强。
Monero 的核心优势在于隐私是强制性的,而且无需复杂的操作。 Bulletproofs 隐藏金额,16人环签名隐藏发送方,隐身地址隐藏接收方,Dandelion++ 隐藏网络来源;Bawdy 表示,正是因为私密消费需要管理混币、输出、Tor 以及各种操作失误,Bitcoin 才把他推向了 XMR。对普通支付而言,“你根本不用操心”。
Bawdy 预计,未来6-9个月推出的全链成员证明,将填补 Monero 已知最大的隐私缺口。 目前 Zcash 的匿名集设计更强,因为屏蔽交易会对整个资金池的输出集合进行签名,而 Monero 使用的是16人环签名。FCMP 将让 Monero 采用类似的全集合方案;Bawdy 称,该方案规模更小、速度更快,还能批量验证,不过高威胁用户仍要面对元数据和启发式分析风险。
按 Bawdy 的说法,实际使用情况明显偏向 XMR,而不是屏蔽版 ZEC。 据称,Monero 多年来一直维持每日20,000-30,000笔私密交易;在与 BTC、ETH、LTC 或 USDT 同时提供的场景中,Monero 往往排名第一或第二。他估计,Zcash 历史上的屏蔽交易量大约是每日100笔或更少,但也承认自己不知道当前数字。最直接的证据来自真实商业场景:VPN、服务器、AI 服务、礼品卡,甚至还有“用 Monero 买冻干牛肉”。
所谓 Monero“遭遇敌意收购”既不是51%攻击,也没有成功控制网络。 Bawdy 称,Qubic 通过以约为正常 XMR 挖矿奖励2倍的代币支付矿工,最多获得了33%的算力,并制造了持续5-30分钟的链重组;但随着自身代币价格下跌,行动开始亏损,最终撤退。这次事件暴露了真实的自私挖矿漏洞,同时也说明,即使奖励翻倍,Monero CPU 挖矿基础中的约三分之二似乎仍然“不可收买”。
交易所排除既限制了分发渠道,也构成去中心化论点的一部分。 在美国除纽约州以外的大部分地区,Kraken 仍是可用的现货交易平台;钱包、原子交换、RetoSwap、Trocador 以及即时兑换聚合器,则帮助用户在下架后“绕开”交易所。XMR 永续合约仍可在 Binance、Bybit、dYdX 和 GTrade 等平台交易。由于没有基金会、预挖、开发者税或企业实体,Monero 的开发依靠社区众筹。
Bawdy 既反对赢家通吃式的极端主义,也反对“隐私主要是给罪犯用的”这一说法。 经过多年审视后,他如今认为 Zcash 的密码学是可信的,但批评其实现方式和有限的屏蔽交易使用率;他认为,Monero 同样能保护用户免受监控、有毒币指控和非自愿披露。Thread Guy 将隐私视为表达自由的延伸:“沉默本身就是表达”,而每一条被拒绝披露的数据,都是“你重新夺回的一点自由、一点主权”。
1. Monero 作为隐私优先的货币诞生,没有企业赞助者
Bawdy 将问题追溯到 Bitcoin 诞生之初:Hal Finney 在第11天就已经在寻求更强的隐私,但十多年的实践证明,可选工具并不等同于“从底层开始构建”的隐私。
Monero 于2014年上线,没有已知创始人、预挖、开发者税、基金会或企业实体。在化名 Thankful_for_today 提出、但被社区否决了一系列修改后,贡献者从预发布的 BitMonero 代码库分叉出来,将其改名为 Monero,重新开始。
它的核心理念是可互换性:任何一个单位都不应携带一段可追踪的历史,从而改变它的可接受程度。正如 Bawdy 所说,没有人会问哪张100美元钞票曾经属于谁——“每张上面都有可卡因”。
2. 默认隐私消除了让 Bitcoin 变得繁琐的操作负担
Bawdy 试图私密地花费 Bitcoin 时,必须混币、管理输出、使用 Tor,还要避免地址关联错误,这一切让他觉得“太麻烦了”。他的解决方案是持有 XMR,只有在收款方不接受 Monero 时,才将其兑换成另一种资产。
Monero 使用 Bulletproofs 隐藏金额。Bawdy 称其具备抗量子能力,并且“完全盲化”。保护金额很重要,因为具有辨识度的支付金额可能成为元数据,被用来重构用户的活动轨迹。
发送方目前隐藏在16个历史输出组成的环签名中;接收方使用隐身地址,为每笔支付生成无法关联的目的地址。Dandelion++ 默认增加 IP 混淆,但 Bawdy 仍建议在威胁模型需要时使用 VPN 或 Tor。
他的保留意见很重要:无论 Monero 还是 Zcash,都无法免疫链下元数据、行为启发式分析或糟糕的操作安全。默认配置下的 Monero 对普通购买和捐赠来说“足够好”;暗网商家及其他暴露程度类似的用户,仍需研究各种边缘情况。
3. FCMP 将填补 Zcash 更具优势的技术缺口
Bawdy 承认,目前 Zcash 在发送方匿名性方面技术更强:屏蔽交易可以对整个资金池的输出集合进行签名,而 Monero 的环签名暴露的候选集合更小,攻击者可能通过启发式分析进一步缩小范围。
这最初是出于保守的工程选择。2014年,zk-SNARKs 还是“新鲜的月球数学”,运行成本高,真正理解它的人极少;Monero 选择了更早、更经审查、普通硬件也能支持的密码学原语,之后又将环签名规模从3个扩大到11个,再扩大到16个。
全链成员证明旨在替代这一妥协。Bawdy 预计 FCMP 会在6-9个月内推出,并称其实现会比 Zcash 的方案略快、略小,同时还可以进行批量验证:等待的价值在于,等数学理论成熟后,Monero 可以“选择最佳实现”。
4. 实际消费,而非密码学新奇性,拉开了 XMR 与 ZEC 的差距
在 Bawdy 见过 XMR 与 ZEC 同时提供的服务中,Monero 的使用量远高于 Zcash,后者往往“只占不到百分之几”。他称,Monero 多年来每天有20,000-30,000笔交易,而且默认全部私密;相比之下,Zcash 历史上的屏蔽交易量约为每日100笔或更少。
这个循环经济覆盖 VPN、服务器、捐赠、礼品卡、通过 Coincards 购买的 Airbnb、NanoGPT 服务,以及 XMRBazaar 上的点对点交易。他特意举了一个平淡无奇的例子——买冻干牛肉——以说明这个社区主要由普通用户组成,而不是“暗网市场大亨”。
Bawdy 坦率承认,这一比较存在局限:他几乎没尝试过花费 Zcash,也不确定 NanoGPT 当前是否接受 Zcash。他的判断依据是观察到的支付份额和屏蔽交易活跃度,而不是对 ZEC 商户进行全面审计。
5. Qubic 暴露了自私挖矿风险,但从未控制 Monero
这次攻击利用了研究者 Eyal 和 Sirer 描述的“自私挖矿”策略:矿工隐藏已经发现的区块,并在私下尝试延长自己的链,利用工作量证明中正常出现的连续出块现象获利。
按 Qubic 自己的说法,其峰值约占 Monero 算力的33%,而非51%。它用价值约为普通 XMR 挖矿奖励2倍的 Qubic 代币补贴矿工,并实现了持续约5-30分钟的短暂链重组;但 Bawdy 称,这场行动最终亏损,并在 Qubic 价格下跌后逐渐消退。
Bawdy 花了6周时间开发一个模拟器,可以在约40秒内模拟一整年的 Monero 区块,希望在测试对策时避免遗漏副作用。他自称只是“高级 pleb”,预计社区会进行有计划的研究,而不是仓促修复,并暗示解决方案可能要到明年才会出现。
6. 下架限制了访问,但没有让市场消失
Bawdy 不愿把交易所压力描述为已经证实的阴谋,但他怀疑,Monero 没有预挖,意味着交易所从未获得那些向交易所分发代币的项目能够提供的经济诱因。Kraken 早期得到 Jesse Powell 支持,目前仍在美国大部分地区提供 XMR,但已在欧洲下架,并且从未在列出 Monero 的情况下取得纽约州 BitLicense。
社区的应对方式,是通过 Bitcoin-XMR 原子交换、RetoSwap、钱包集成,以及 Trocador 和 OrangeFren 等聚合器,绕开中心化平台。Bawdy 称,用户可以通过即时兑换,在约30分钟内完成大约10,000-50,000美元的资金转移,而且并不困难。
对于更简单的入门方式,他推荐 Cake Wallet,其内置兑换功能可以将 BTC、ETH 和 SOL 等资产兑换成 XMR;桌面端用户可以从 GetMonero.org 下载软件或运行节点。现货渠道有限,但 XMR/USDT 永续合约仍可在数家大型衍生品平台交易。
Monero 的开发依靠 Community Crowdfunding System,而不是企业收入。Luke Parker 的 FCMP 提案“几乎一夜之间”就获得了资金支持,体现了这一理念:这里没有政府可以施压的基金会企业实体,而且许多贡献者都是匿名的。
7. 多头逻辑是持久效用,而不是某一种隐私币一统天下
Bawdy 表示,XMR 早期涨向250-300美元,发生在隐私热潮全面启动之前。他称 Monero 是2022年熊市中表现最好的币,并认为真实消费、有限的永续合约投机以及坚定的持有者,共同带来了稳定性,即便 Binance 和欧洲 Kraken 用户失去现货访问权限,情况也是如此。
他对极端主义的反驳来自历史经验:黄金、白银、铜、代币货币以及约200种法定货币一直可以共存,因为不同货币服务于不同目的。Monero 无需击败 Bitcoin、Zcash 或稳定币;他希望 Monero 在能够现实服务的使用场景中释放最大潜力。
他对 Zcash 的看法也发生了变化。经过多年审视,其密码学已经从可疑的“月球数学”变成了“相当不错的技术”;他真正批评的是实现方式和采用率,而 Monero 的社区在见证 Bitcoin 的2017年内战后,形成了“对激光眼极端主义的天然免疫”。
Bawdy 认为,透明币可能通过有毒的交易历史牵连无辜持有者,而 Monero 则可以通过共享查看密钥支持自愿披露。
Thread Guy 将隐私更广泛地定义为对披露范围的控制,并视其为表达自由的延伸。他的实际建议是循序渐进地改善隐私——使用 VPN、拦截 Cookie、换用更好的浏览器,以及采用其他隐私工具——因为每一次对监控数据的小幅拒绝,都“像是一笔自由与主权的小额储蓄”。
完整逐字稿
BawdyAnarchist, we’re live. What’s up, man?
Hey, what’s up, man? How’s it going?
Good. Did I say that right?
Yeah. Yeah, Bawdy.
Bawdy. I said “Body.” Bawdy. Welcome, dude. I appreciate you coming on. Sorry I’m 15 minutes late, but it’s going to make for a banger. How about this? Let’s start with a quick intro into who you are, what you do, and then we can get into some fun stuff.
Yeah, sure, man. I’ve been in crypto for a quick minute, definitely well before the 2021 blowoff top. I got interested in privacy, and I’ve always been interested in tech. I’m an engineer by trade.
These days I do trading and analysis, a little bit of coding, and a little bit of open-source stuff. Mostly, in the Monero community, I’m known for my price reports. Basically, every Saturday morning I do a live price report.
Mostly, we cover macro, big-picture crypto. We don’t really get into the deep-dive meme coins or the new projects. I just try to keep it high-level, overview kind of stuff. But yeah, man, I’m just chilling. I just exist out there in the ether and try to put forth a few good words, a few bits of good advice for the community out there.
So, you do price reports. I love that. How long have you been doing price reports for?
Oh, man. I think 2022 is when I got started, about three years ago.
Well, those price reports are looking pretty good right now.
I got really excited about Zcash probably around the same time everybody else got really excited about Zcash—maybe a month ago, give or take, maybe a month and a half, 45 days ago. I’m not a historical privacy guy, so this privacy coin scene is relatively fresh to me. By no stretch am I an expert, and I’ve primarily just been trading the charts.
I got really excited about Zcash. Things kind of got parabolic. I was trading the chart, and now, after things have calmed down a little bit, I kind of want to go back. I’m like, “Okay, we’ve covered Zcash, but I feel like I have a responsibility to cover everything else.”
Monero is one that I think is the only privacy coin I knew coming into this. Everyone, I think, hears about Monero, knows that it exists, and knows that it has the word “privacy” next to it. I think a significantly smaller proportion of people are familiar with how it works, why it works, where it sits, and its lore.
Can you set the stage a little bit for what Monero is, and then why do the die-hards view Monero as the only real privacy coin and sort of shun the rest?
Yeah, sure thing, man. Let’s go all the way back to the beginning, right? And the word was with God. No, I’m just kidding.
Day 11, Bitcoin launches. Day 11, Hal Finney is one of the first guys Satoshi brings on to help him develop this project. Day 11, Hal Finney posts to Twitter looking for ways to add more privacy to Bitcoin, because they knew from the beginning, “Hey, we’ve got some privacy properties.” They didn’t really understand the full scope, right?
It’s taken us over a decade to really understand the privacy landscape and the cryptography, to develop not just the cryptography, but the infrastructure—all of the supporting pieces and all of the implementations required. It became evident somewhere around 2015, 2017, or 2018 that Bitcoin really wasn’t doing that great a job at privacy.
There were privacy tools, but they weren’t really default, strong, developed-from-the-ground-up systems. Monero launched in 2014, and it tried to do a lot like Bitcoin did. We don’t know who the founder is—some guy named Thankful_for_today. It turns out he tried to do some weird stuff with the project, so we actually forked the project from him.
It used to be BitMonero, and now it’s just Monero. We launched a lot like Bitcoin. We don’t know who the founder is; he’s anonymous. There was no premine, no corporate mechanism behind it. It’s pure community-funded, no dev tax, nothing like that.
Basically, Monero chose to use conservative, well-vetted, well-reviewed cryptographic primitives that were within the reach of ordinary users, that you could run on regular hardware. Some of the really cool cryptographic stuff, like the ZK stuff that Zcash pioneered back in the day when they launched, was hard to run on your machine. It would take a long time to construct transactions and stuff like that.
Monero launched with the belief that money needs to be fungible, and to be fungible it has to be private, right?
Right.
Fungible meaning you can’t tell which $100 bill belongs to whom, right? You don’t care whose $100 bill it is. They all have cocaine on them, you know? [__] it.
So we decided, all right, we’re going to hold true to our principles. There are a lot of corporate coins out there and a lot of different ways to fund coins. There’s a lot of debate that goes back and forth, and we’re not necessarily going to hate on the corporately funded coins.
But we wanted one coin to at least be there that was pure community-driven, pure community-funded, and true to the cypherpunk ethos. That’s the people who eventually made their way into Monero.
What’s funny is that, when we talk about the bull case for Monero—you’ve got fundamentals, reputation, and organic adoption—after the whole civil war with Bitcoin in 2017, the only thing that the maxis and the Bcashers could agree on was Monero.
In Monero, we have people who are very Bcash-friendly. They maybe like some other coins as well. Then you’ve also got people who are almost total die-hard Bitcoin maxis, and Monero is okay as well.
Monero sits at this kind of nexus of cypherpunks and real organic adoption. We even have people who are anti-moon-boy. They’re like, “No, no, stop talking about the price pumps. It’s about the adoption, bro,” right?
They’re really about the principles and the philosophy. That’s the big, top-level overview of where Monero is.
All right, let’s do some history class then. [__] it, I’m down. I love this [__]. I love some good lore.
I was tweeting yesterday. I was getting clowned yesterday on the timeline because I tweeted, “I came into crypto in November 2020 for NFTs. I’m not an OG cypherpunk. I came to trade animal pictures in Top Shot NFTs.” I’ve since kind of worked backwards over the last five years, but I definitely started on that side.
I tweeted yesterday, “Why is Bitcoin Cash worth $12 billion?” A bunch of people were replying, and somebody replied, “Because Roger Ver.” I replied, “What’s that?” I’ve now done my homework and realize it’s a ridiculous thing to say, but I obviously have minimal context on this whole Bitcoin Cash war, if you will.
You said in 2017 the only thing the Bitcoin Cash people and the OG Bitcoin people could agree on was Monero. Give me as much light as you want to shine on that, please do. Then how does Monero come into play with that on the history side?
Yeah. It was actually a pretty bitter civil war that happened. It was effectively about the direction they were going to take Bitcoin. Some people wanted to increase the block size, and I’m sure your users have heard about the block size wars. That’s what that was.
Some people forked Bitcoin, and they called it Bitcoin Cash. For a while they were kind of pissed that we called it Bcash. I sort of sided with the maxis. I was even a little bit of a maxi myself back in the day, and eventually realized there are actually some good projects out there.
I found myself using Ethereum. I was like, “Well, [__], I can’t exactly be a maxi if I’m actually using Ethereum.”
Monero offered such a good use case for maintaining your privacy. The thing that really pushed me into Monero more than anything was trying to use Bitcoin privately. I was like, “All right, well, I need to follow all of these steps. I’ve got to mix my coins, then I have to be careful about my outputs, and I’ve got to do all this other stuff. I’ve got to go over Tor all the time.”
If you send one output to one person, make sure that you don’t send way too much. Eventually I said, “All right, you know what I’m going to do? If I need to spend funds privately, I’m going to keep a chunk of Monero. I’m just going to keep it on reserve.”
If they don’t accept Monero, then I’ll just flip Monero into something else, whatever they do accept, right? That’ll keep my privacy good. I don’t have to worry about doing all this crazy gymnastics on Bitcoin.
Over the years—it’s condensing a few years of timeline here—from 2017 to about 2020, there was a lot of development that happened on Monero that really advanced the project in ways that made it much more usable and made the privacy much stronger.
A lot of people saw that: the people who were truly interested in it for the digital freedom money use case. We saw maxis sort of coming over to Monero because some people need strong privacy.
Some of them were criminals. Mostly, honestly, the guys that I know in the Monero community—hardly any of us are darknet market extraordinaires. Most of us are just normal guys that pay for servers and VPNs, NanoGPT gift cards, donations—you name it, right?
There’s this big circular economy that’s developed around Monero for the digital freedom money use case. If I’m going to send you funds, bro, if I’m going to donate to you, it’s none of your business how much money I have in my bank account, crypto account, or crypto address.
When you start gaming out, “All right, well, I’ve got to do all this stuff to send a donation or send some money to someone that shouldn’t know how much crypto I have,” that could be because I’m an influencer and have so little, or because I’m a nobody and have so much, right? Either way, it’s nice because it’s default privacy. You don’t have to think about it. I’m just going to use Monero. Maybe I’ll run a VPN as well.
If I have a really strong use case, all right, there are a couple of little edge-case gotchas. Cryptocurrencies are sort of leaky in terms of heuristics, and neither Monero nor Zcash is any exception to that. If you have a really strong threat model, like you’re a darknet market vendor, you’re going to need to study a little bit. But for the rest of us, the average people just using Monero on a day-to-day basis for paying for stuff, it’s good enough. No one is trying to snoop on your VPN purchase.
So, I don’t know how technical you want to get. I don’t really have an in-depth understanding of how Zcash works. How does it work? How does Monero work? There’s all of this chatter that it’s not really fully private and that AI can pattern-match things like this. How does it work, and how do you guarantee privacy, if you will, on Monero?
Very classically, when it comes to a transaction system, you need to protect 3 things: the sender, the receiver, and the amounts. If you don’t protect all 3 of those things, you’re going to provide some kind of data that an adversary might be able to use.
Obviously, we’re in the days of big data, big tech, and AI, and chain analysis is a $10 billion industry. They’re working pretty hard to try and do this.
As far as the tech goes, the way that Monero protects the amounts—we’ll start with the amounts—is we actually use a bit of zero-knowledge proofs of our own. It’s called Bulletproofs. It started as a range proof, then evolved into Bulletproofs, and it’s effectively a quantum-resistant means of perfectly blinding the amount.
Amounts are super crucial to protect because when you purchase some very specific amount of something or transfer some very specific amount of funds, that usually betrays some kind of heuristic—sort of indirect stuff that you can use to put together a picture or a profile. We protect the amounts with Bulletproofs.
We protect the senders with something called ring signatures. Effectively, we have rings of 16. What you’re doing is taking 16 outputs from the entire chain—not exactly random—and hiding as one of those outputs. Once you receive funds, you’re going to receive those funds, and someone else is going to use your output as a decoy for theirs.
Even though, for your specific transaction, you have an anonymity set of 16, your anonymity set grows over time, but it’s not perfect. Zcash, in a very technical sense, does it better. They don’t use ring signatures. They sign over the entire output set of the shielded pool in Zcash.
This is a technological—I won’t call it a deficiency. It was actually an intentional choice by the Monero community not to use new math at the time. ZK-SNARKs were new math, and we weren’t too sure about how well-vetted they were. The other thing was that it was kind of slow, and the transactions were quite large. Monero people needed privacy then, right, in 2014.
The decision was made: mathematically speaking, rings of 3 are actually extremely good, and you just have to bump that up to give yourself some buffer zone. In 2018, Monero went to rings of 11, then we upgraded to rings of 16. Now, probably in the next 6 to 9 months, we’re going to upgrade to something called full-chain membership proofs, which is effectively similar to the means Zcash uses of signing over the entire output set.
That closes the most difficult, or most problematic, aspect of Monero privacy. As far as we know, you can’t unwind it. Mathematically and statistically speaking, this has been very well reviewed. You can’t mathematically unwind it.
You can use heuristics, metadata, and all the big resources of the big bad state and the corporate surveillance apparatus. They’ve got their means and their ways to reduce that set somewhat, but for most people, if you’re not purchasing drugs or operating a darknet market, they don’t care about you enough to go through the trouble to even try.
Even those people who are on dark nets—as long as you play your cards right, the ring signatures are still good, but it is less ideal. So, we’re going to that.
That’s how you protect the sender. Finally, the recipient is protected by something called stealth addresses. Every time that you receive Monero, you generate a new address, and it’s impossible to link the public address that you send someone—“Hey, send me money to this address”—to any of your other outputs on-chain.
One last thing: we also do IP obfuscation by default. It’s called Dandelion++. It was invented for Bitcoin, but they never implemented it. I guess they don’t like to upgrade very much. Monero ripped it off—we stole it—and dropped it on-chain, so it gives you default IP protection.
It’s better if you also use a VPN or Tor, but it’s still pretty good. So that’s the lowdown.
First of all, that was beautiful. Once this full-chain upgrade happens—in, I think you said, 6 to 9 months—is the FUD about ring signatures being cracked, or whatever the exact verbiage is, essentially going to go away completely? Will you have full private coverage?
Yeah, exactly. That’s the one thing that’s been a thorn in our side for a long time. “Hey, this could be a problem.” In some cases, it might be slightly a problem, right? Again, for high-threat-level actors, it’s a game of cat and mouse. The governments have their big data, and the corporations have chain analysis, so we need to always stay ahead of that.
That one last thing will close the gap between Monero and Zcash. The only thing that really is between Monero and Zcash—and as a side note, I’ll say that full-chain membership proofs, or FCMP, as we call it, are actually a little bit faster and a little bit smaller than the Zcash implementation.
We can do batching effectively, so you can batch-verify transactions. It’s actually a little bit faster. This is one of the benefits of taking the conservative approach: you can wait for the technology to evolve and mature, then choose the best implementation.
I don’t know if you have any data in front of you, but I’m curious. People always say that Monero is the chain that is actually being used. Who’s using it is relatively irrelevant for the sake of this conversation, versus Zcash being a nerd snipe, but no one’s actually using Zcash. Do you have any rough data on activity between Monero and Zcash?
Yeah. I’ve looked as much as I can. In all the places where we see Monero and Zcash offered alongside each other, we don’t see very much Zcash usage.
Where we see Monero offered alongside Bitcoin, Ethereum, Litecoin, Tether, and so on, Monero is literally number 1 or number 2. Anywhere that it’s offered alongside other options, it often beats Bitcoin. Zcash is usually less than a fraction—it’s a fraction of a percent.
We’ve also got Monero, very consistently for years and years now, having daily transactions in the 20,000-to-30,000 range.
Wow.
Again, all of those are fully shielded transactions because of the default privacy. The number of shielded transactions actually being done daily on Zcash—I don’t know what the numbers are right now because it’s a little bit in flux—but for the past few years, it’s been 100 or less. It’s been very low for a long time.
Where can you actually use Zcash? I’m not trying to go too deep, but I’m just—
Like, where are these? What is accepting Zcash?
Or—I mean, excuse me. I meant Monero, but both. I actually meant Monero, but—
Oh, okay.
Okay.
Yeah. Yeah. As far as Zcash, I haven't really tried to use it too much—really at all, to be honest. I think that it's offered at NanoGPT. So, okay, let's just start with Monero because I can talk to that.
You can buy VPNs for Monero. You can buy servers and gift cards. There's a new service called NanoGPT.com. If you want to access all of the latest AI—Gemini, OpenAI, Llama, and all the other ones, like DeepSeek—they've got all of the models on there, and you can pay with any cryptocurrency that you want. I think they have Zcash, so you could pay with Zcash there if you want. I'd have to double-check that, but they definitely accept Monero. It's their number-one-used coin.
CoinCards.com is useful if you want to use Monero to buy your Christmas presents, or maybe you want to get an Airbnb. You just get a CoinCards gift card and pay for your Airbnb that way. There are a couple of cool websites. XMR Bazaar is kind of like the Craigslist of Monero. You can go there and find all kinds of stuff. I've even bought freeze-dried beef for Monero on occasion.
Monerica is another one that lists all the different places that accept Monero.
Word. You know what was really difficult? Finding somebody who wanted to come on stream and talk about Monero.
Yeah. I don't think our communities intersect that much, to be honest. I use Solana. I've got a Phantom wallet, and I've played around with it and whatnot. But I don't think our communities intersect that much, to be honest.
You were hard to find.
Which is a shame. We pulled through, though.
Okay. So there was this FUD, if you will, that happened, I don't know, 3 months ago, 6 months ago, that there was a 51% attack—a hostile takeover—on Monero. I think it was kind of a troll. I watched a Hivemind episode on this and heard about it for 30 minutes, didn't pay much attention, and now I'm sort of pulling old references here. But I'm sure you're aware of what happened, how it happened, and why it happened. Can you break down the hostile takeover, how that was possible, and what the long-term effects are?
Yeah, 100%. I actually wrote a Monero simulator in response to this attack. I wrote a simulator because I wanted to study their strategies, their ideal strategies, and what kind of countermeasures we could deploy. I put that on GitHub, and it's got to be one of the best simulators we have to date. It's fast, too. You can simulate an entire year of Monero blocks in about 40 seconds.
What happened back in 2013—so, I guess, back to some more of the lore—is that two guys named Ittay Eyal and Emin Gün Sirer put out this really cool paper. They said that 51% isn't enough. You can actually conduct what they called a selfish-mining attack against any proof-of-work network.
Basically, when you find a block, you don't tell anybody about it, and you hope that you find the next block on top of that. If you think of proof-of-work mining like flipping a coin, sometimes you're going to flip heads 6 times in a row. As a miner, sometimes you're going to win 3, 4, or 5 blocks in a row before anyone else catches up. That's just natural statistical variation.
No one had ever really tried to implement a selfish-mining attack against a proof-of-work chain until Qubic came along a few months ago. By their own admission, they never got 51% of the hash power. What they said they got was a maximum of 33%. They were able to do some short-chain reorganizations between 5 minutes and 30 minutes. They were able to reorganize the chain on short timelines, which definitely caused some disruption.
But for them to be able to do that, they had to bribe the miners. They were paying people in their Qubic token, which at the time was trading at about 2 times higher than the actual mining reward you would get from mining Monero. They used their high token price as a subsidy for attacking Monero with the selfish-mining attack.
As it turns out, at best, 33% of Monero's hash power is for sale. The other 66%—the supermajority of Monero's hash power—apparently is not for sale, even if you're going to offer them 2 times the mining rewards for it.
It's definitely a little bit of a problem. All proof-of-work networks are a little bit vulnerable here. But ultimately, what we saw is that it's actually not that easy. These guys lost money trying to attack the network, and now their price has crashed, so they've gone away.
In a way, it was a good thing because it showed us that we're not totally invincible and need to start studying the ways we can adjust and make selfish-mining attacks much harder. The Monero developers are currently hard at work on that. Hopefully, with my simulator, I'm going to start testing different countermeasures because there are always side effects you might get from implementing things like this. We can simulate the outcomes, and hopefully, maybe next year we'll have a good solution for it.
But we never got a 51% attack. There was never a hostile takeover.
What happens if you get to 51%?
You can reorg it. It's totally possible for anybody to gain 51% of the hash power if they're willing to pay enough money for it. Monero is CPU-mined, so we have a very decentralized mining network, whereas most proof-of-work networks are ASIC-mined.
With ASICs, it's a double-edged sword. You get some protection because it's kind of like proof of stake: Who wants to buy an ASIC and then attack their own network? But at the same time, that's a heavily centralizing factor in mining, and now the ASIC miners are getting all the rewards.
There are many different proposed solutions for fixing this. It's just going to take some time. We want to be conservative and deliberate and make sure that what we implement is actually a good solution.
Are you a crack developer? Who built the simulator? Did you just code the simulator? How does this work?
Yeah. I've never really done development professionally, but I do my own development for other stuff. I've played around with an operating system called FreeBSD, and I do a little bit of statistical analysis for charts and stuff like that.
When this attack happened, I was working on something else, but it kicked off and I thought, “Man, I’ve got to do my part. I’ve got to save Monero.” So I spent about 6 weeks doing this simulator.
Are you actively a core contributor to Monero, or are you just a community member?
No, no. I'm just an advanced pleb. That's the best claim I could make.
Who is the core developer team at this point? Who's working on it?
We've actually got a pretty large developer team. One of the lead guys is named Rucknium. He's anonymous, but he seems to be the one who leads the Monero Research Lab meetings weekly.
Luke Parker is one of the big guys, too. We're always communicating daily about all kinds of stuff that comes up. KayabaNerve, also known as Luke Parker, is the one who developed full-chain membership proofs, so he's one of the big guys. He's on X. Sorry, Elon.
Who else do we have? We've got woodser, and we've got j-berman. We're on Matrix, so if you're interested, get into the Monero Research Lab on Matrix. They're friendly guys and they'll talk to you.
Matrix is a messaging app? It's kind of like Telegram or Discord?
Yeah. They've got their own app, and you can access it through a web browser as well. It's a messaging app where you can basically run your own server.
I've never even heard of that. That's awesome. Why is Monero not on any exchanges? I was trying to buy like [__] around and bid the other day.
Yeah, man, that's a good question. Maybe we should ask Brian Armstrong and the Gemini twins. Maybe we should ask CZ, although they removed it after they removed CZ.
It's on Kraken, though. You can get it on Kraken as long as you're not in New York. I don't know where you're located, but if you're in Europe—
I'm in L.A.
Oh, yeah, man. Get on Kraken. You can buy Monero.
Why is Kraken the only one that has it? Is it just that there are no legal guidelines, and people don't want to list it? What is that?
Yeah, we have our suspicions. We don't want to be lobbying all kinds of conspiracies at people.
But we have some suspicions that maybe there’s a financial incentive because Monero never did a premine. So we didn’t hand a fat stack of Monero or Zcash, for that matter, to some of the exchanges. But Kraken, from the very beginning—a guy named Jesse Powell, one of the OG guys—he launched Kraken, and he was adamant that they were always going to keep Monero.
So they delisted it in Europe under regulatory pressure, but in the United States, we haven’t really seen that pressure. In New York, they were never able to get the BitLicense with Monero listed, but Kraken has kept it listed the entire time. So we’ve been asking Brian Armstrong and the Gemini brothers, “Please put Monero on your exchanges.”
Ultimately, bro, we had to route around that shit, right? We have all these different decentralized solutions. Someone developed atomic swaps, and now there’s a wallet called IEN Wallet[?] that you can use to swap between Bitcoin and Monero with atomic swaps, all done in the background for you. THORChain is currently integrating it.
I don’t know if you’ve heard of Bisq. It was like the old Bitcoin. Bisq is a decentralized platform where you can trade your U.S. dollars, cash, Venmo, or whatever, to buy Bitcoin. We have ours called RetoSwap.
RetoSwap is the same kind of thing. You’ve got to install an app and do all this other stuff, but if you want the simple degen way to get into Monero, you just get on trocador.app or orangefren.com. These are aggregators of all the instant-swap exchanges, and there are 10 or 20 different instant-swap exchanges.
You can easily move $10,000, $20,000, or $50,000 into and out of Monero on these instant-swap exchanges with hardly any problem. You can do it in 30 minutes.
This might be a ridiculous question: Is it an L1?
Say it again.
Monero is an L1, or no?
An L1. Oh, yeah, yeah, yeah.
Okay, okay.
Yeah, it’s just the regular old blockchain.
Okay, okay. Someone in the chat is saying Kraken was really pressured to delist it, but Jesse Powell stood on business. That’s awesome. I fuck with that. That’s honestly sick.
Yeah, big salute to that guy, man.
Yeah, shout out Jesse Powell. Okay, so you’re the price guy. You post price updates every week. What is happening right now? Why is Monero kind of going crazy on the back end of the Zcash rally?
Actually, it was on the front end, believe it or not. If you check out the chart, the Zcash rally started a couple of months ago. That was when the privacy narrative really got into full swing, but most of Monero’s price action was built from, like, $200 to $250. It’s currently at about $400, but going up to $250 or $300, all of that came before the big privacy hype pump that just happened.
That’s just organic usage, man. The thing is, because the core of people who love Monero and use it so much have built this circular economy, there’s a reputation, fundamentals, and organic adoption. It didn’t even matter in a lot of ways that Monero was being delisted, right?
It got delisted from Binance, then Kraken, and in Europe it got delisted. It almost didn’t matter because we were like, “Fuck it, we don’t care. We’re just going to build these decentralized exchanges and continue using this in a circular economy.” There’s a lot of power in that.
You don’t get the memecoin kind of pumps. You don’t get that crazy hype pump. But Monero was the best-performing coin of the 2022 bear market. You get a kind of price stability because you’re not on exchanges. You don’t have the crazy speculation, and there’s not a huge market for the perpetuals.
I know you’re a perpetuals guy, which you can still do, by the way. You can trade Monero perpetuals on Binance, Bybit, dYdX, gTrade—all of them offer an XMR/USDT pair.
Generally speaking, our belief is that if you want price gains over the long term, fundamentals are a long-term consideration. Don’t get me wrong, bro, I’m a degen with the rest. I will trade stuff if it’s going to pump, if I think it’s going to pump. I’ll trade it just like anyone else.
But when it comes to long-term investment, I really consider myself more of an investor than a hype chaser, although I do a little bit of both. Monero, for me, is a long-term investment because the community is so dedicated to building these circular economies. That puts a floor on the price in a way that makes it hard to dump below certain levels.
Is there some sort of fee structure? Does the foundation, if you will, make money? Do transactions generate fees? How does that work?
No, bro, we don’t even have a foundation. There’s no corporation. There’s no corporate entity. There’s no foundation.
We have some systems set up. It’s called the Community Crowdfunding System, or CCS, and it’s how we fund, as a community, the stuff that we want to see. When Luke Parker came up with an implementation of full-chain membership proofs for Monero, he put his proposal out there, and then it got listed on the CCS. The community funded it practically overnight.
Everything that is funded in Monero, the community funds. There’s no corporation, there’s no dev tax, there’s no premine, nothing like that. It’s completely organic. No corporation. You can’t have any government come in there and start screwing with your corporate status and holding that sort of regulatory sword over your head. We’re like, “Yeah, we don’t care. We’re just going to keep going.” A lot of our developers are anonymous anyway. Good luck finding them.
So, yeah, we don’t even have a foundation.
What happened to this Thankful_for_today character? I’ve never honestly heard that name before today.
I don’t know. He kind of disappeared. He wanted to do some weird stuff with the implementation.
I don’t know. It wasn’t terrible. It just wasn’t ideologically or philosophically at the kind of purity level, you could say. Not to be culty about it, but I can’t remember, honestly. I need to go on, so bad—you don’t want to say it out loud.
No, no, it’s not like a dirty skeleton in the closet.
Yeah.
Got it. And so—
Was just like, “No, go ahead, sir.”
No, you—my bad. You go ahead.
No, no, please, sir.
So, he—an anonymous founder—starts doing some weird stuff with the Monero vision. You guys are like, “Fuck this shit.” Somebody forked it. Exactly what happened?
Basically, the entire community was like, “Nah, that’s not quite right.” It was BitMonero, and then they did a fork. The coin wasn’t even launched yet. They forked the GitHub repo, renamed it from BitMonero to Monero, and then launched the coin fresh.
Dash is one of the coins where—
They just launched and then they’re like, “Oh, well, this accidental premine—but the community doesn’t want us to revert that.” Bro, you just got 25% of the supply right out the gate. I don’t want to be a hater. I’m sorry.
No, no, it’s good context. I would have gotten off-stream and the chat would have been like, “Who was it?” I’d be like, “I have no fucking idea.”
Okay, how do you think it plays out from here? How big do you think the TAM is for Monero? Do you think it has to win the privacy wars, if you will, to get as big as you think it can get? Where do we go from here with Monero?
One of the things I told the Bitcoin maxis back in the day was that only one can win, right? They start singing Eminem at you: “You had one shot, one chance to win.” Guys, that’s a caricature.
Look at the historical, empirical reality. We’ve had gold, silver, and copper all traded simultaneously as money, depending on the use case. We’ve also had scrip, we’ve had fiat, and right now there are about 200 fiat currencies in the world. I know the U.S. dollar dominates, but there are all different types of promissory notes, et cetera.
There are so many different types of money, and none of these monies is perfect. That includes Monero, Bitcoin, Zcash, and Tether. They all serve different kinds of use cases.
I don’t think Monero has to vanquish everything. There doesn’t have to be one coin to rule them all. I do think Monero is a sleeper. I think it’s been quietly developing for a long time, and a lot of the community, as you said, you’re aware of it.
You know that it's out there, and you're kind of like, "I don't know, the criminals are all using Monero." But no, in fact, the fact that criminals are using transparent chains is actually a huge thing that fucks you up, because you accidentally come into contact with coins that have a nefarious origin—something you had nothing to do with—and now it looks like you had something to do with that, potentially.
Maybe you're hoping and praying that chain analysis was able to see, "No, no, I didn't do the bad thing. I just received the coins." But with Monero, you never have to worry about that. Once people start to compute this and think, "Wait a second, I can be free from false accusations by using a privacy coin," a squeaky-clean guy like me needs that protection, right? That's protection.
We have no shortage of stories of people who deposited coins to exchanges and got frozen over some AML problem. It still happened on MEXC the other day. Someone got frozen. White Whale got roughly $4 million frozen and can't get it off. If he wasn't some big, clouted trading account, who knows if they would have unlocked it.
Yeah. Yeah, exactly. That question just never comes up with Monero. If they accept Monero, they might ask you where you got it from. You'd be like, "I'm a trading degen, and I got a shitload of Monero because I traded whatever." They're not going to be able to demand anything, because there's no chain analysis they can do.
Even the IRS tried to put a bounty out a couple of years ago. They put a bounty out for Monero, like, "Any of you chain-analysis firms that can crack Monero, we're going to offer you a million-dollar reward for doing it." They just never paid out the bounty for cracking Monero.
Did somebody crack it?
No. No, that bounty never got paid out because no one was ever able to crack it.
I want to see it. Honestly, bro, I use Ethereum. I use some of this other stuff. I don't think Monero has to dominate. I think there's room for a lot of people, but I do want to see Monero's potential maximized, right?
We can't replace the dollar. Monero can't do a trillion transactions per second, or whatever the numbers people throw around. But I do want to see Monero maximized for what it can be used for. I think that's important.
Honestly, sick take. I guess, to bring it full circle, we never really talked about this privacy stuff prior to Zcash. Now I'm like, "Yeah, this is actually pretty fundamental to your human rights and the future of the world," based on where we're going.
I don't know if it's a coincidence or part of what fueled the narrative, but every day there's some new news headline out of the UK, and it's pretty scary—the direction this is headed. Can you set the stage on privacy as a human right, where we're going, and the direction this thing is headed toward surveillance and basically anti-privacy?
Yeah. There's a guy named James Corbett who has pretty good takes. One of the things that he said a few years ago is that data is the new oil.
Data is this rich, sticky substance that they process, and they use it for all kinds of power games. It's highly versatile. They can do anything they want with it. They don't have enough of it. We're awash in data, and they don't know how to analyze all of it.
It's only going to get worse from here, right? If you want any hope of preserving this fundamental human right—that is privacy—it's an extension of your freedom of expression. Your right to remain silent is freedom of expression. Silence itself is expression.
Your right to cryptography and your right to publishing are core concepts of a cooperative society. Without these things, you have straight-up tyranny. They've built systems that make it really easy for you to give up all of your privacy. Just sign up for Gmail, right? We've got this whole suite of stuff. Use our software. Use Windows, use Mac, use all of these things that have embedded spying mechanisms.
People get the wrong idea when they think about privacy. They're like, "Ah, yeah, but I'm not a hacker, and I'm not a ninja in the privacy realm. I don't know how to do this shit. Why should I try to do anything at all, then?" It's about taking little steps and making the cost a little bit higher, right?
If the government really wants to come after you, they're going to come after you. But if everyone's taking little steps to make it a little bit harder to get access to their data, suddenly Facebook isn't feeding you full of ads because they couldn't see the rest of your browsing history.
In a more general sense, privacy tools might mean you're running a good web browser blocker or blocking third-party cookies. Every little step helps. Every little piece of data that you deny these big corporate behemoths that are spying on everything you do is one little piece of your freedom and sovereignty that you've taken back.
It allows you the freedom and latitude to operate in a way that lets you make the choices you want to make. You get to choose when you want to reveal your data and reveal your information.
If, in Monero, I want to share—maybe we have an organization together and we want to all monitor our addresses—we can share the public view key for our Monero wallet so everyone can see all the funds coming into that wallet. But that's only because I choose to do it.
The thing I try to tell people is, just take little steps. Use a VPN. VPNs aren't hard. They're pretty easy to get connected to. Personally, I think IVPN is a good one, and I always forget the other one. It'll come to me later.
They're all somewhat questionable, but at a minimum, VPNs protect you from low-level black hats. They might not protect you from the NSA or whatever, but they'll protect you from public Wi-Fi and stuff like that.
So you want to use a VPN and take all those little steps. Take all the little steps that you can, and know that you're giving yourself a little bit of extra protection every moment. It's like a little savings account.
That was beautiful. Data is the new oil—that was a crazy line. Can you say the guy's name again? James Corbett?
Corbett.
Corbett. That's why I couldn't find it.
Corb or Corbett. C-O-R-B-E-T-T. Corbett.
Corb.
That was a crazy line. That's pretty wild.
Yeah, man. The guy's next level. He presents things in such a neutral way, too. I really love his presentation. He's not like Alex Jones, saying, "The gay frogs are coming to get you." He doesn't do all that shit. He just presents it like, "Okay, here's what I found in the public archives and Congressional Record," or whatever.
He presents a very non-crazy view of the conspiracy world.
Are you one of these people who's like, "Monero supremacy, everything else sucks"? It's crypto, right? Everyone has financial assets. Everyone has tribalism. Zcash versus Monero—do you think Zcash is good technology that people will actually use?
I do think that Zcash actually has pretty good technology. At first, I was pretty uncertain about it because it was kind of like—we called it "moon math" back in the day. "Yeah, this is unvetted. This is new moon math. There are three people in the world who understand this cryptography."
But over time, the more that something gets reviewed and the more opportunity people have to look at it and say, "Yeah, okay, this actually looks all right," the more confidence you get. So I think Zcash does have good technology.
My only complaint is the implementation. Like I said, I don't want to be a hater. I'm here to present Monero, not to hate on Zcash.
Monero does have some maxis—some true, hardcore maxis. That is true. I wouldn't call them the majority. I would definitely call them a pretty small minority of people in Monero.
The reason is that most of us came out of that civil war from 2017, and we saw the kinds of psychological mechanisms and failings of maximalism. We saw it happen with the laser eyes in Bitcoin, and we said, "Nah, that's not who we want to be."
So we have a kind of natural immunity to taking it too far.
That's fair, though. With the lore, it makes sense.
Dude, this was honestly sick. I had never heard you talk before and wasn't familiar with you prior to this. You came on and presented it fucking eloquently.
As a sign-off, what's your pro-Monero sign-off? What do you direct people to do? How do they protect themselves? How do they get exposure? Where should they go to tap into the community a little bit? Where do you guys hang out? What would you like to leave people with on that side?
Yeah.
So, for just getting Monero, right? Download Cake Wallet. It’s on Android and iOS, and it has swaps built in. If you have some Solana, Ethereum, or Bitcoin—and Cake Wallet also has Solana, by the way—you can flip those coins into Monero really easily.
We don’t have a browser wallet, unfortunately, but Cake is a great smartphone wallet. We have some desktop wallets as well. Go to getmonero.org if you want to run a node or download the software.
We hang out on Twitter, on X. Like I said, there’s a lot of activity on Matrix as well. There are a handful of Telegram channels out there, and probably some Discord channels. I haven’t really been on Discord, but I actually created a Discord just for this, so maybe I’ll be hanging out there a little bit more.
Overall, Monero is integrated into the crypto system. If you really want to buy on a centralized exchange, you can buy through Kraken, or you can use an instant-swap exchange. Again, Trocador.app just aggregates all the instant swaps, so I’ve used them quite a lot.
I hope to see you guys around. I think it’s a shame that the Solana and Monero communities haven’t really connected that much, but it was really great talking with you. I really—
They’re doing it now, man. I also think one of the reasons I like doing these streams and finding people like you is that a lot of this OG lore and war-story stuff just gets lost in the ether, never really to be heard from again. A lot of the people who are newer and coming in at later stages have no concept of it, and there’s not really any place where it’s documented in a legible transcript.
It’s sick to hear some lore. I just love some good lore, so I appreciate you coming on and sharing it with us.
Yeah, man. I really appreciate you inviting me. I really enjoyed sharing the opportunity.
Yeah, dude. Hopefully, maybe at $1,000 per XMR token, we’ll run part 2.
Honestly, I think that’s entirely achievable. The shitcoin privacy coins are going wild right now, so we’ve got good times ahead.
Let’s do it. It’s great to meet you, man. Pleasure. Thanks for coming on. I really appreciate your time. Thanks, bro.