Deanonymizing Monero Transactions in Tor Network
Ruisheng Shi, Shihan Zhang, Yulian Ge, Lina Lan, Qingfeng Zhang, Qin Wang
cs.CR, cs.ET
Submitted: 2026-07-08
Code: https://github.com/monero-project/monero
License: http://creativecommons.org/licenses/by/4.0/
The gist: Monero is a privacy-focused cryptocurrency that deploys the Dandelion++ protocol and incorporates anonymity networks (such as Tor and I2P) to prevent malicious attackers from linking transactions
Terminology
Abstract
Monero is a privacy-focused cryptocurrency that deploys the Dandelion++ protocol and incorporates anonymity networks (such as Tor and I2P) to prevent malicious attackers from linking transactions with their source IPs. In this paper, we demonstrate that Monero's integration of the Tor network introduces a fundamental vulnerability: a Monero Tor node's originated transactions are exclusively forwarded to two outgoing Tor hidden service nodes (proxy nodes) prior to clearnet propagation, enabling an adversary to capture originated transactions by occupying the target node's outgoing connections. Based on this observation, we propose ProxyMark, a three-stage deanonymization framework for the Monero Tor network, comprising node role identification, originated transaction identification, and node location deanonymization. Through experiments on the live Tor network, Monero mainnet, and testnet, we empirically demonstrate the effectiveness of ProxyMark in successfully deanonymizing transactions originating from Monero nodes over Tor.
Sources
- Deanonymizing Bitcoin Transactions via Network Traffic Analysis with Semi-supervised Learning
- Friend or Foe? Identifying Anomalous Peers in Moneros P2P Network
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs