<oembed><type>rich</type><version>1.0</version><title>MAGIC INTERNET MONEY wrote</title><author_name>MAGIC INTERNET MONEY (npub10a…y5s6r)</author_name><author_url>https://njump.me/npub10a4heyt5gkz8twt8tx0gey08fk7unnuvyuf5rh02tdxcppkt0d8s3y5s6r</author_url><provider_name>njump</provider_name><provider_url>https://njump.me</provider_url><html>Most of this is wrong or applies equally to Monero.&#xA;&#xA;IP leakage isn&#39;t a Zcash problem, it&#39;s a network-layer problem. Run anything without Tor/I2P and your ISP sees it. Same for XMR. Tor is intergrated into ZODL&#xA;&#xA;&#34;Nobody uses shielded&#34; was true in 2020. As of March 2026 it&#39;s ~86% of activity and ~31% of supply is shielded. Zashi defaults to shielded.&#xA;&#xA;Trusted setup: Sprout is deprecated, holds 0.2% of supply. Orchard uses Halo 2, no trusted setup. Toxic waste enables counterfeiting, not deanonymization &#xA;&#xA;View keys aren&#39;t a backdoor. Monero has them too. They&#39;re user-controlled selective disclosure. If that&#39;s disqualifying, XMR is also disqualified.&#xA;&#xA;Dev fund was ~8 years not 10, and is now restructured. Fair critique of funding centralization, wrong numbers. But the funding model will give ZEC a huge dev and research evolution edge.&#xA;&#xA;On the actual crypto: Monero uses ring signatures — a mixer with a 16-member anonymity set per transaction. That&#39;s not &#34;superior privacy,&#34; it&#39;s a tiny anonymity set vulnerable to statistical heuristics, decoy-selection flaws, EAE attacks, and temporal analysis. Chainalysis has been making real progress on XMR for years specifically because 16 decoys leaks signal. Zcash&#39;s Orchard pool gives you an anonymity set of every shielded note in the pool — millions, not sixteen. That&#39;s a genuine cryptographic gap, not a marketing point.&#xA;&#xA;FCMP++ closes that gap on paper, sure — for chain-layer anonymity-set size after FCMP++ ships, yes. For privacy as an end-to-end practical property, it&#39;s still contested and depends on your threat model. Post quantum- no.&#xA;&#xA;And on quantum: ring signatures + Pedersen commitments are not post-quantum secure. A CRQC breaks XMR&#39;s anonymity retroactively — every transaction ever made becomes deanonymizable. Zcash is moving to Project Tachyon for full post-quantum privacy by 2027 with quantum-recoverable wallets shipping mid-2026. Monero is still researching it. If you actually care about long-horizon privacy, that matters.&#xA;&#xA;Things that are genuinely true: XMR dominates DNM/merchants, is more decentralized, no VCs.  Real point. The &#34;government op from A to Z&#34; framing is what people reach for when they&#39;ve run out of technical argument.&#xA;&#xA;The actual debate is mandatory vs optional privacy and the tradeoffs that flow from it.</html></oembed>