Join Nostr
2026-05-15 19:48:47 GMT
in reply to

MAGIC INTERNET MONEY on Nostr: Most of this is wrong or applies equally to Monero. IP leakage isn't a Zcash problem, ...

Most of this is wrong or applies equally to Monero.

IP leakage isn't a Zcash problem, it's a network-layer problem. Run anything without Tor/I2P and your ISP sees it. Same for XMR. Tor is intergrated into ZODL

"Nobody uses shielded" was true in 2020. As of March 2026 it's ~86% of activity and ~31% of supply is shielded. Zashi defaults to shielded.

Trusted setup: Sprout is deprecated, holds 0.2% of supply. Orchard uses Halo 2, no trusted setup. Toxic waste enables counterfeiting, not deanonymization

View keys aren't a backdoor. Monero has them too. They're user-controlled selective disclosure. If that's disqualifying, XMR is also disqualified.

Dev fund was ~8 years not 10, and is now restructured. Fair critique of funding centralization, wrong numbers. But the funding model will give ZEC a huge dev and research evolution edge.

On the actual crypto: Monero uses ring signatures — a mixer with a 16-member anonymity set per transaction. That's not "superior privacy," it's a tiny anonymity set vulnerable to statistical heuristics, decoy-selection flaws, EAE attacks, and temporal analysis. Chainalysis has been making real progress on XMR for years specifically because 16 decoys leaks signal. Zcash's Orchard pool gives you an anonymity set of every shielded note in the pool — millions, not sixteen. That's a genuine cryptographic gap, not a marketing point.

FCMP++ closes that gap on paper, sure — for chain-layer anonymity-set size after FCMP++ ships, yes. For privacy as an end-to-end practical property, it's still contested and depends on your threat model. Post quantum- no.

And on quantum: ring signatures + Pedersen commitments are not post-quantum secure. A CRQC breaks XMR's anonymity retroactively — every transaction ever made becomes deanonymizable. Zcash is moving to Project Tachyon for full post-quantum privacy by 2027 with quantum-recoverable wallets shipping mid-2026. Monero is still researching it. If you actually care about long-horizon privacy, that matters.

Things that are genuinely true: XMR dominates DNM/merchants, is more decentralized, no VCs. Real point. The "government op from A to Z" framing is what people reach for when they've run out of technical argument.

The actual debate is mandatory vs optional privacy and the tradeoffs that flow from it.