A memecoin where nobody is on the buyer list.
REDACTED trades like any other token. The difference is that the address holding the position is never the address that trades it. You sign an intent; a rotating set of third-party wallets executes it for you and settles the result back. The block explorer gets a complete, honest record of every swap — attached to wallets that are not yours.
Each hop adds a wallet that has to be subpoenaed, and roughly 1.8 seconds to the batch window. The second number is the one that actually buys you privacy: a longer window means more unrelated intents settle in the same block, and it is that crowd — not the number of possible routes — that bounds what an observer can conclude.
- Candidate routes
- 1.7K
- Anonymity set in window
- 20
- Settlement latency
- 8.6s
- Route fee
- 0.79%
Every holder is a third party. Including, from the chain’s point of view, you.
- The relay setTwelve funded NPC wallets per hop, rotated on a rolling schedule. None of them is controlled by a single operator — signing is 7-of-12 threshold.Custody model
- The nodeA fork of monerod 0.18.5.3 ‘Fluorine Fermi’, run in restricted mode, seeded from the 38 healthy German peers on monero.fail.Node set
- What it costsBetween 0.43% and 1.33% per route, depending on depth, plus a few seconds of settlement latency. That is the entire bill.Trade-offs
What the chain sees
Nothing is encrypted and nothing is hidden from the explorer. Amounts, timing, and counterparties are all public, exactly as they are for every other token. The single field that never reaches the chain is the one that links a position to a person.
Coordinatorin memory, 90s
- 7xKq…9mT4npc-0a41+412,900
- 4nBv…2wY8npc-17c9−88,140
- 9dRt…6kL1npc-0d82+1,204,330
- 2sHp…7qV5npc-2e05+96,500
- 8fZc…3bN2npc-11f7−530,775
- 5jWm…1xD9npc-3b6a+247,010
Block explorerpermanent
- npc-0a41+412,900
- npc-17c9−88,140
- npc-0d82+1,204,330
- npc-2e05+96,500
- npc-11f7−530,775
- npc-3b6a+247,010
The left panel is the only place the mapping exists, and it exists for roughly ninety seconds — long enough to assemble a batch, then discarded. We cannot produce a holder list on request because after the batch settles we do not have one.
How a buy is actually executed
The mechanism is deliberately boring. There is no new cryptography here — it is a mixnet with settlement attached, and the interesting engineering is in the parts that keep timing from giving the game away.
You sign an intent
Not a transaction. An intent names a side, a size, and a slippage bound, and it is signed with a key that never touches the pool. Your wallet does not broadcast anything, so there is no origin transaction to correlate against.
The NPC server batches it
Intents collect in a window of a few seconds. The coordinator fills the batch, shuffles it, and splits each order across the relay cohort. Batching is what creates the crowd — a route executed alone is a route that can be followed.
NPC wallets execute
Each leg is signed 7-of-12 by the relay cohort, so no single operator ever holds a key that can move your size or reconstruct your intent. The wallets buy and sell on the open pool like anybody else, because that is precisely what they are doing.
Settlement returns to a fresh output
The filled position lands on an address derived for that batch only. Reusing a settlement address across batches would rebuild the link we just spent four hops breaking, so the client never does.
Why it is called an NPC server
The relay wallets have no stake in the outcome and no strategy of their own. They execute somebody else’s order, hold the result for a block or two, and hand it on. They are background characters in a trade that belongs to someone else, and the whole design depends on them being indistinguishable from one another. Internally the coordinator is a multi-party computation: twelve parties, seven required, no single point that can be leaned on.
Why today, and why monerod 0.18.5.3
A relay network is only as private as the node it reads from. Ours is a fork of the Monero daemon released this morning — v0.18.5.3 ‘Fluorine Fermi’, 182 commits from 17 contributors — and we moved the moment it shipped, because most of what landed is restricted-mode privacy work that our threat model sits directly on top of.
| Area | Upstream change | Why it matters here |
|---|---|---|
| Daemon | Disable get_transaction_pool in restricted mode#10973 | A readable mempool is a timing oracle. An observer polling a restricted node could watch an intent appear and leave before it was ever mined, and line that window up against the relay that broadcast it. Closing the endpoint removes the pre-confirmation window entirely. |
| Daemon | Improve restricted RPC privacy filtering#11034#11147 | Restricted mode now strips more of the per-connection and per-transaction detail that previously differentiated one caller from another. Our relays all query through the same filter, so they look alike to the node they are talking to. |
| Daemon | Restrict get_public_nodes to public zone peers#11356 | Previously a caller could enumerate peers the node had learned about privately. Peer lists are a cheap way to fingerprint an operator who runs several nodes — which, inconveniently, is exactly what we do. |
| ZMQ | Hide request contents from logs in restricted mode#10971 | The subscriber socket is how the coordinator learns a relay's leg confirmed. Request bodies landing in a logfile is a disclosure channel that survives the process, and log files get backed up, shipped, and subpoenaed. |
| Daemon | Group public IPv6 connection limits by /64#11013 | A /64 is the smallest unit a residential or VPS customer is normally handed, so it is the correct granularity for 'one party'. Counting per-address let a single allocation open enough connections to census the network. |
| Wallet | Hardening against malicious remote nodes#10950#11320#11347#11444 | monero.fail opens with a malicious node advisory for a reason: a hostile remote node is the standard way users get deanonymised. These patches reduce what a lying node can extract from a wallet that trusts it. |
| Daemon | Reject deep block submissions on restricted RPC#11239 | Submitting a block at depth is a reorg probe. It is a cheap way to test whether two endpoints are the same machine behind different addresses. |
| Daemon | Fix P2P connection stalls and restore relay after restart#10918#10845 | Not a privacy fix, but a liveness one. A relay that stalls mid-route holds a leg open, and a leg that stays open longer than its cohort is the one that stands out. |
To be exact about what we forked
Monero has been open source since 2014 and the daemon was never closed — what arrived today is a release, not a licence change. The reason it mattered to us is narrower and more useful than a headline: before #10973, a node in restricted mode still answered get_transaction_pool, which leaves a pre-confirmation window in which a relayed order is visible but not yet buried. That window is the cleanest timing attack against a design like ours, and as of this release it is closed. We pinned monero-linux-x64-v0.18.5.3.tar.bz2 against the signed hash list and forked from there.
What we gave up to get here
Routing, speed, and self-custody of the in-flight order do not coexist. Most trading infrastructure keeps speed, because the people paying for it are measured in milliseconds. We are not, so speed is the one we sold.
Kept: unlinkability. This is the entire product. If a holder can be named from public data, there is nothing here worth shipping — every other property is negotiable against this one.
Kept: non-custodial settlement. The relay cohort can execute your order and cannot keep it. Seven-of-twelve threshold signing means a majority would have to collude to steal, and the position lands at an address only you can spend from.
Given up: speed. A route takes between three and thirteen seconds, and you pay under one and a half percent for it. If you are trying to front-run a listing, this is the wrong venue and you should use the pool directly.
Why a memecoin and not a protocol
Privacy infrastructure has a distribution problem, not a cryptography problem. The primitives have worked for a decade. What has never worked is getting them in front of people who are not already reading research forums, and the reliable way to fail at that is to ship a correct, carefully specified protocol that nobody has a reason to touch.
A memecoin has a reason to touch it built in. People want the position, and they want it for ordinary and slightly embarrassing reasons, and in the course of getting it they end up using a mixnet. The privacy is not the pitch. It is the plumbing, and that is the only configuration in which this kind of thing ever gets used at volume.
It also means the system is load-tested by adversaries who are genuinely motivated. Wallet-tracking bots, copy-traders, and the people who build dashboards of who is holding what are all pointed at exactly this surface already. If the holder set stays dark under that, it is dark under most of what matters.
We are not claiming this is the right way to build private markets. We are claiming it is a way to find out quickly, with real money and real adversaries, which is a thing the careful version of this project would not have done for another two years.
Parameters
Set at deployment. The relay cohort rotates; the thresholds do not.
| Relay depth | 1–6 hops, selected per intent |
|---|---|
| Cohort size per hop | 12 funded NPC wallets |
| Signing threshold | 7-of-12 |
| Batch window | 1.2s base, +1.8s per hop |
| Route fee | 0.25% base, +0.18% per hop |
| Settlement address reuse | None — fresh per batch |
| Coordinator retention | 90s in memory, never written to disk |
| Backing node | monerod 0.18.5.3 fork, --restricted-rpc |
| Peer discovery | 38 seed peers, public zone only |
| Published holder list | None, and none retained |
What could go wrong
This is a routing system holding real orders. These are the failures we think are most likely, in roughly that order.
The coordinator sees the link
For the length of a batch window, one process knows which intent belongs to which wallet. We hold it in memory and drop it, but “we promise we deleted it” is a trust assumption, not a guarantee, and it is the weakest part of the design.
Timing correlation
Path ambiguity is cheap; temporal ambiguity is not. In thin hours the batch window may contain two or three intents, and an observer with a full mempool feed can narrow a route to a handful of candidates. The anonymity set shown above is a live number for a reason.
Amount fingerprinting
An unusual size is its own identifier. Splitting across the cohort helps, but a sufficiently large or sufficiently odd order reassembles from the legs. Round numbers are safer than you would like them to be.
Relay collusion
Seven of twelve operators acting together can sign, and therefore can also compare notes. The cohort is rotated and geographically spread, but a well-funded adversary running a majority of relays defeats this outright.
Funding graph leakage
Routing the trade does not route the money that paid for it. If the wallet signing intents was funded by a KYC withdrawal, the graph still terminates at your name — one hop further out than before.
Hostile nodes
monero.fail opens with an advisory about chain-analysis firms running public nodes, and it is correct. We run our own and seed from a fixed peer list for exactly that reason, but a node we peer with is still a node we did not build.
Upstream
The node underneath this is not ours. It is the Monero daemon, forked at the release that shipped on October 06, 2026, and the privacy properties we lean on were designed, argued over, and implemented by people with no connection to this project.
Monero 0.18.5.3 ‘Fluorine Fermi’ released →getmonero.org · 182 commits · 17 contributors · 4,162 lines
REDACTED is an independent project. It is not affiliated with, endorsed by, or reviewed by the Monero Project or any of the contributors named in the release above. Routing a trade is not the same as being anonymous, and nothing on this page is a promise that you cannot be identified by other means. Nothing here is financial advice.