OnionSwap

← Blog

Is Monero traceable?

The short answer is that Monero is not traceable on-chain the way Bitcoin is, and there is no public demonstration of anyone breaking its current cryptography. The longer and more useful answer is that almost every real Monero deanonymisation you will ever read about happened off the chain — at an exchange, on the network layer, or through a mistake the user made. Understanding which is which is the whole point, because it tells you where to actually spend your caution.

What "traceable" means for Bitcoin, and why Monero is different

Bitcoin is a public ledger. Every transaction shows the input addresses, the output addresses and the exact amount, forever. Given one identified address, an analyst can walk the graph in both directions and cluster related addresses with heuristics that are, in practice, extremely effective. This is deterministic tracing: the data is all there, and the work is in connecting it to a name. That is why a swap payout landing on a KYC exchange address is such a common failure — the identity is already attached to that address.

Monero was built specifically to remove the three ingredients that make this possible. It hides all three, and it does so on every transaction by default rather than as an opt-in.

The three things Monero hides

The sender — ring signatures. When you spend, your real input is signed alongside a set of decoy inputs pulled from the chain. An observer sees a group of possible sources and cannot tell which one actually moved. Every transaction becomes one of many plausible histories rather than a single traceable line.

The receiver — stealth addresses. Every payment goes to a one-time address derived on the fly, even if you hand out the same public address a thousand times. Nothing on the chain links those one-time addresses back to your published address, which is why address reuse — fatal for Bitcoin privacy — leaks nothing in Monero.

The amount — RingCT. Transaction amounts are cryptographically committed rather than shown in the clear, so the network can verify that inputs equal outputs without anyone learning the figures. This closes the amount-correlation attacks that work well against transparent chains.

So what do the "we can trace Monero" claims mean?

Every so often an analytics firm or a court filing implies Monero has been cracked. Read closely, and these fall into a few categories, none of which is a break of current cryptography:

Off-chain data. The overwhelming majority. An exchange handed over records tying a name to a deposit or withdrawal. That identifies the endpoints of a transfer; it does not read the chain in between.

Old, weaker transactions. Monero's privacy has strengthened over the years — ring sizes increased, decoy selection improved, and RingCT was added in 2017. Some early analysis exploited spent-output leaks in transactions made before those upgrades. That research does not apply to how Monero works today.

Statistical heuristics. Vendors sell probabilistic guesses about which ring member is the real spend. These are contested, produce confidence scores rather than proof, and degrade as ring sizes grow. Marketing them as "tracing" is generous.

Network-level metadata. If you broadcast a transaction and an observer sees the IP it originated from, they may learn who submitted it — without breaking anything on-chain at all. This is a networking leak, and it is the one most within your control to fix.

Where Monero privacy actually leaks in practice

If you want to think clearly about your own exposure, ignore the cryptography — it is doing its job — and look at the edges:

The on-ramps and off-ramps. The moment Monero touches an identified account, that endpoint is known. This is why converting through a no-account swap rather than depositing XMR to a verified exchange matters: an instant swap has no account to attach your identity to and nothing to hand over later.

Your IP at broadcast. Running a transaction over Tor or through a remote node you trust removes the network-layer link between you and the transaction. Many wallets support this directly.

Amount and timing correlation. Monero hides the amount on-chain, but if a private payout is immediately followed by an identifiable spend of the same value, you have rebuilt the link yourself. Avoid round figures and let funds settle rather than forwarding them straight through.

What this means for a swap

When you move Bitcoin into Monero, you are crossing from a fully traceable chain into one that is not. The privacy you gain is real from the Monero side forward — but the Bitcoin history behind your deposit is unchanged, and if you later convert back to Bitcoin, the receiving address becomes the new visible endpoint. Monero being untraceable on-chain does not make the endpoints disappear; it makes the middle opaque. Plan around the endpoints, because that is where the visible information lives.

The honest bottom line

Is Monero traceable? As a protocol, in 2026, there is no public evidence that it is. As something people use in the real world, it is exactly as private as the weakest link in how it is acquired, transmitted and spent — and that link is almost never the cryptography. Treat the chain as the strong part and your own operational habits as the part that needs attention, and you will be reasoning about this the way the people who study it do.

Start a private swap →