Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Take action to mitigate the effectiveness of chainlysis's probabilistic attack to successfuly deanonimization monero users #1066

Open
Kreyren opened this issue Jan 5, 2025 · 0 comments

Comments

@Kreyren
Copy link

Kreyren commented Jan 5, 2025

Primary source (leaked original presentation) for ongoing de-anonymization attack through malicious nodes: http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/monero-chain.mp4

Secondary summary of the situation: dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/6de54b143e669e368af6

Originally posted by @GhostDog98 in #981 (comment)


TLDR

Chainlysis is able to deanonymize monero users by:
a. deploying malicious nodes that unaware to the blockchain set decoys from 16 to 1 and by tracking the IP addresses reducing the effectiveness of privacy measures
b. observe fee rate to try to connect it to known wallets and their behaviors
c. connect IP addresses by users who do not use their own nodes to have dandelion++ protection to known IPs in the world

List of Recommendations:

  1. Do not deploy stack monero node over clearweb, provide Tor only and deploy I2P and warn the user with a prompt to deploy their own node to have dandelion++ protection with explanation to why is that important
  2. Disable the ability to change fee rate for monero and set it to automatic only OR prompt the user with a warning if they want to change the fee rate
  3. Warn the user if they decide to use Monero over clearweb that it's bad idea and link the summary above
@Kreyren Kreyren changed the title Take action to mitigate the effectiveness of chainlysis's probabilistic attack to successfuly deanonimization monero users (happening right now) Take action to mitigate the effectiveness of chainlysis's probabilistic attack to successfuly deanonimization monero users Jan 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant