Timing & Transaction-Graph Analysis
Temporal heuristics, the guess-the-newest guess, merge and change-output heuristics, amount leaks in the transparent era, and the residual statistical risk that remains.
40 lessons with this tag.
Temporal heuristics, the guess-the-newest guess, merge and change-output heuristics, amount leaks in the transparent era, and the residual statistical risk that remains.
Historical weaknesses when rings were optional or small — zero-decoy cascade deanonymization and transparent amounts — and how mandatory RingCT and enforced decoys fixed them.
How a private view key exposes incoming transactions read-only, and how payment proofs let you prove a specific payment for records or disputes.
How Monero is private by default yet the owner can choose to reveal specific information — privacy is not the same as being unable to prove anything.
Bitcoin, Ethereum, Zcash and Monero side by side: the shared foundation, the Zcash-vs-Monero assumption trade-off, why mandatory privacy matters, and the FCMP++ roadmap.
Pedersen commitments C = xG + aH, the homomorphic balance check, the overflow loophole, and how Bulletproofs+ prove amounts in range with no trusted setup.
Stealth addresses via ECDH (P = Hs(rA)G + B), ring signatures that hide which key signed, and key images I = x·Hp(P) that stop double-spends without naming the output.
What a transparent transaction reveals, why pseudonymity isn't privacy, the three things a private chain must hide, and the two schools that solve it.
How all blockchain signatures descend from Schnorr, why ECDSA names the spender, and how Monero generalizes one signature into a privacy-preserving ring.
Why Bitcoin and Ethereum use secp256k1, Monero uses Ed25519, and Zcash adds pairing curves — and how the curve choice follows from each chain's goals.
SHA-256 vs Keccak across Bitcoin, Ethereum and Monero, the hash-to-scalar and hash-to-point maps Monero adds, and how hashing becomes commitment.
The four ideas every cryptocurrency is built from — finite fields, groups and the discrete-log problem, one-way hashes, and signatures — and why Monero invents almost no new math.
The daemon's JSON-RPC and legacy endpoints — get_info, get_fee_estimate, get_outs, send_raw_transaction — the read-and-broadcast layer of the chain.
Where the protocol is heading: full-chain membership proofs via curve trees that replace ring signatures, the Seraphis transaction protocol, and the Jamtis addressing scheme.
Generators, the Fiat-Shamir transcript, the weighted inner-product that shrinks the proof, batch verification, and the transaction-weight clawback.
The aggregation coefficients, the domain-separated challenge hashes, and how one ring proves both key ownership and commitment opening — with the round-robin written out.
Ed25519 has cofactor 8, so points can carry a torsion component. Why key images must be checked for the prime-order subgroup, the hash-to-point map, and the bugs that ignoring this caused.
The PoW VM that keeps mining on CPUs, plus the dynamic block-weight penalty and the fee formula that derive Monero's adaptive, low fees.
A byte-level tour: inputs with key images, outputs with one-time keys and view tags, ecdhInfo, the range proof, tx_extra, fees and the balance proof.
Hiding amounts with commitments C = aH + xG, the balance equation, and how Bulletproofs+ prove a value is in range without revealing it.
How Monero proves you own one ring member without revealing which — LSAG → MLSAG → CLSAG — and how the key image I = x·Hp(P) stops double spends.
One-time output keys via ECDH: R = rG, P = Hs(rA)G + B, how the receiver recovers the one-time private key, subaddresses, and view tags.
The twisted-Edwards group Monero is built on, scalars mod ℓ, points, and how spend/view keypairs and addresses are actually derived.
There's no 'coin' file — what you own is a set of unspent transaction outputs. The mental model that makes the rest of Monero click.
How blockchain pruning works, what it keeps and drops, when to prune, and how to run a pruned node that still fully validates.
Read the Monero network live — current transaction fees, block reward, difficulty and the total circulating supply — straight from your node or a block explorer.
How Monero's RandomX algorithm lets ordinary CPUs secure the network and earn rewards.
Using view keys and watch-only wallets to audit funds without exposing spend ability.
What churning is, when it helps, when it doesn't, and the misconceptions to drop.
How to prove you sent (or received) a specific payment without exposing your whole wallet.
Monero has no public explorer for your funds — how to verify payments using your wallet, tx keys and view keys.
Follow a Monero transaction from your wallet to confirmation, tying all the pieces together.
How Monero keeps fees low with an adaptive block size, and how transaction priority works.
Why received Monero is locked for 10 blocks, and what confirmations mean for your funds.
How Monero obscures which node a transaction came from, and why network-level privacy matters.
How Confidential Transactions hide the amount while still proving no money was created from nothing.
How mixing your spend with decoys hides which output is really being spent — protecting the sender.
How one-time addresses hide the receiver so your address never appears on the blockchain.
Monero's unusual two-key design: spend keys and view keys, and what each one can do.
How a blockchain works as a shared, tamper-resistant ledger that no single party controls.
π Graduate from Monero Academy
Create a free account, ace every quiz across all courses, and earn your place on the Graduates wall β with your own Monero address for donations. An account also tracks your progress through the courses, and graduating is the prize for finishing.