<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2025-04-20T13:11:20&#43;02:00</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by openmonero</title>
  <author>
    <name>openmonero</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub139xxrl297wzdmty5snyjc7sypdzsnpglzzhtk86lddfq7u4ry9xqg3g46d.rss" />
  <link href="https://nostr.ae/npub139xxrl297wzdmty5snyjc7sypdzsnpglzzhtk86lddfq7u4ry9xqg3g46d" />
  <id>https://nostr.ae/npub139xxrl297wzdmty5snyjc7sypdzsnpglzzhtk86lddfq7u4ry9xqg3g46d</id>
  <icon>https://openmonero.com/images/om-64.webp</icon>
  <logo>https://openmonero.com/images/om-64.webp</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqs03c7vmgt66j808qfgplvnuemx4axadt474u7ajuyydp94v8v94uczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cwy95uc</id>
    
      <title type="html">LocalMonero.co is now gone for good, logins disabled LocalMonero ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs03c7vmgt66j808qfgplvnuemx4axadt474u7ajuyydp94v8v94uczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cwy95uc" />
    <content type="html">
      LocalMonero.co is now gone for good, logins disabled&lt;br/&gt;&lt;br/&gt;LocalMonero disabled logins on July 27, 2025. Attempts to access public profiles via direct links now result in a blank page. Consequently, our crawler is unable to verify import keys. However, you can still verify your reputation at &lt;a href=&#34;http://openmonero.com/guides/import#cachedUserList&#34;&gt;http://openmonero.com/guides/import#cachedUserList&lt;/a&gt;, as the top profiles have been cached on OpenMonero and can be verified through alternative methods such as Telegram, Session, XMPP/Jabber, email, PGP, and others.&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #rugpull #transparency #stats
    </content>
    <updated>2025-08-01T11:54:49&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst2pl8stx0accjvvjd04kefz8z2g24wj6ftz9pslj6hyx28t5hquqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cq5uaad</id>
    
      <title type="html">How bad actors try to track Monero Depending on your operational ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst2pl8stx0accjvvjd04kefz8z2g24wj6ftz9pslj6hyx28t5hquqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cq5uaad" />
    <content type="html">
      How bad actors try to track Monero&lt;br/&gt;&lt;br/&gt;Depending on your operational security, the combination of the various attack types in this article may reduce your privacy significantly, to get the real spend in a ring signature.&lt;br/&gt;&lt;br/&gt;These methods have been used to arrest the Incognito Market admin, the operators of Archetyp, a Colombian drug dealer, a Finnish blackmailer, the Bitfinex hacker and 18 Japanese fraudsters.&lt;br/&gt;&lt;br/&gt;---&lt;br/&gt;&lt;br/&gt;# Eve-Alice-Eve attack&lt;br/&gt;&lt;br/&gt;This one’s like a sneaky collusion trick. Two parties (both called Eve) team up to figure out who’s behind a transaction with Alice. Eve1 sends Monero to Alice in one transaction; Eve2 receives Monero from Alice in another.&lt;br/&gt;&lt;br/&gt;They compare their transaction records, if Eve1’s address shows up in Eve2’s ring signature, or if amounts and times match up, they can pretty confidently say Alice was involved. Repeating this over and over makes their case even stronger.&lt;br/&gt;&lt;br/&gt;---&lt;br/&gt;&lt;br/&gt;# Poisoned output attack&lt;br/&gt;&lt;br/&gt;Think of this like &amp;#34;marked bills&amp;#34; in the physical world. Here, the attacker &amp;#34;poisons&amp;#34; some Monero outputs, either with a unique amount or a specific pubkey, and then watches to see if those outputs get sent to someone who knows the identity of those who send them monero, and who has agreed to share data with the attacker to help identify the target.&lt;br/&gt;&lt;br/&gt;If the target sends that marked Monero to a known colluder, the attacker can identify who sent it. Repeated use helps build a stronger case.&lt;br/&gt;&lt;br/&gt;---&lt;br/&gt;&lt;br/&gt;# Timing analysis attack&lt;br/&gt;&lt;br/&gt;Sometimes, targets try to dodge the poisoned output trap by splitting amounts or churning (sending to new addresses repeatedly). But if they’re doing this on a regular schedule, attackers can catch on by watching the timing between transactions.&lt;br/&gt;&lt;br/&gt;For example, if an attacker notices that every Tuesday, a certain person receives Monero and then quickly sends it out again, that pattern can reveal who they are, even if they try to hide it.&lt;br/&gt;&lt;br/&gt;Anti-privacy adversaries can leverage timing information to increase the probability of guessing the real spend in a ring signature to approximately 1-in-4.2 instead of 1-in-16.&lt;br/&gt;&lt;br/&gt;---&lt;br/&gt;&lt;br/&gt;# Decoy elimination attack&lt;br/&gt;&lt;br/&gt;This trick is handy if someone has a list of transaction IDs and thinks their target sent Monero in those transactions. They might get this list by scanning the blockchain for transactions that include a special kind of public key known to belong to the target, or from someone who’s interacted with the target a few times, like an exchange or a store.&lt;br/&gt;&lt;br/&gt;Once they have the list, they can look up those transactions and check the signatures inside them. These signatures include a bunch of public keys used to hide who actually sent the money. The attacker checks if any of those keys are theirs or someone they know. If they find a match, they can ask the owner if they made that transaction. If not, then that key was just a decoy, not the real sender.&lt;br/&gt;&lt;br/&gt;This method helps the attacker narrow down the possible real sender. In the worst case, they can remove all the fake keys and figure out exactly who sent the Monero. From there, they might trace the transaction back or forward, using the same or different techniques, to follow the money’s trail.&lt;br/&gt;&lt;br/&gt;---&lt;br/&gt;&lt;br/&gt;# Spy node attack&lt;br/&gt;&lt;br/&gt;Monero transactions are broadcast through nodes, some are run by honest users, others by malicious actors (spy nodes). If your wallet sends transactions through a spy node, they might log your IP address, which can then be linked to your transaction and real identity.&lt;br/&gt;&lt;br/&gt;Full nodes try to protect you with protocols like Dandelion&#43;&#43;, but they’re not perfect. Attackers can exploit this by seeing if a transaction is still in its &amp;#34;stem&amp;#34; phase, which can leak your IP.&lt;br/&gt;&lt;br/&gt;---&lt;br/&gt;&lt;br/&gt;# Tx history lookup attack&lt;br/&gt;&lt;br/&gt;If an attacker manages to get hold of your private keys (say, during a raid or if you accidentally share them), they can look up your entire transaction history on the blockchain. This helps them see all the Monero you’ve received and sent.&lt;br/&gt;&lt;br/&gt;References:&lt;br/&gt;&lt;a href=&#34;https://www.getmonero.org/2025/04/05/ospead-optimal-ring-signature-research.html&#34;&gt;https://www.getmonero.org/2025/04/05/ospead-optimal-ring-signature-research.html&lt;/a&gt;&lt;br/&gt;&lt;a href=&#34;http://openmonero.com/knowledge/how-bad-actors-try-to-track-monero&#34;&gt;http://openmonero.com/knowledge/how-bad-actors-try-to-track-monero&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #rugpull #transparency #stats
    </content>
    <updated>2025-07-23T10:24:01&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg5e2qsc9ep6qvshvthvjfscfdanjds24vgnnplaxd7anpcu4arsqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c7du4wk</id>
    
      <title type="html">Centralization of XMR market and tracking every transaction ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg5e2qsc9ep6qvshvthvjfscfdanjds24vgnnplaxd7anpcu4arsqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c7du4wk" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8vysmj30emrwrgtkr7lzleqg0w023k4pw2lza950p2jvl25cuyqqpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhswm0e79&#39;&gt;nevent1q…0e79&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Centralization of XMR market and tracking every transaction&lt;br/&gt;&lt;br/&gt;Recent research conducted by the Weizenbaum Institute, TRM Labs (San Franciso) and TU Berlin indicate that Retoswap, formerly known as Haveno-Reto, does not provide the privacy protections it advertises. Despite its marketing claims, this platform functions as a sophisticated decoy. The narrative of being non-custodial and decentralized is a carefully crafted illusion designed to attract unsuspecting users and foster a false sense of security.&lt;br/&gt;&lt;a href=&#34;https://xcancel.com/noosphere888x2/status/1922044150716715102#m&#34;&gt;https://xcancel.com/noosphere888x2/status/1922044150716715102#m&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Darknet operators who assume Retoswap is suitable for laundering should reconsider. Their activities are under constant surveillance. The supposed privacy offered by Retoswap is an illusion.&lt;br/&gt;&lt;br/&gt;Retoswap Trades Are Fully Traceable&lt;br/&gt;&lt;br/&gt;&amp;gt; To test our findings, we logged Haveno trades for two weeks and executed five test trades within the observation period. For all five transactions, we successfully identified all XMR transactions.&lt;br/&gt;Additionally, we demonstrate that Haveno trades leave detectable on-chain footprints, allowing cross-chain transaction linking.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://arxiv.org/pdf/2505.02392&#34;&gt;https://arxiv.org/pdf/2505.02392&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; Haveno has been discussed in greater detail as it evolved to one of the most prominent exchanges in the context of Monero. While strong promises claim privacy with every transaction and independence from any central authority, the current implementation raises uncertainty. Our analysis showed detectable on-chain patterns and weaknesses in the platform that can be exploited to match transactions across chains. &lt;br/&gt;&lt;br/&gt;It is noteworthy that some of the most active dark web exchanges, administrators, vendors, and key figures may have already utilized Retoswap to launder illicit gains or transfer substantial amounts of BTC and XMR. These individuals often believe their anonymity is safeguarded due to the platform’s purported decentralization. However, all Retoswap crypto-to-crypto transactions are inherently traceable.&lt;br/&gt;&lt;br/&gt;Retoswap has apparently handled over 50 million dollars in transactions, which is pretty impressive considering it’s been around for less than a year. It looks like big players like hackers, darknet admins, and other underground groups are already using it to move big amounts of money.&lt;br/&gt;Source: &lt;a href=&#34;https://xcancel.com/RetoSwap/status/1930953817228481022#m&#34;&gt;https://xcancel.com/RetoSwap/status/1930953817228481022#m&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;While speculative, there are reasons to suspect that recent LE actions may not be coincidental. Authorities have tracked down major operators, likely due to the on-chain trail left by Retoswap activities. According to haveno.markets, approximately 90% of liquidity involves BTC-XMR swaps, transactions that are fully traceable. Every transaction is publicly recorded on-chain with exact timestamps, amounts, and payment methods, leaving a permanent digital footprint.&lt;br/&gt;&lt;br/&gt;&amp;gt; While trade statistics provide valuable metrics for users, their network propagation should be obfuscated to preserve trade privacy.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://arxiv.org/pdf/2505.02392&#34;&gt;https://arxiv.org/pdf/2505.02392&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;In summary, admins of coin-swap services can easily monitor BTC to XMR trades. But usually, it’s not a big deal because users trust these providers not to share details like timestamps, amounts, or other info. On the flip side, with platforms like Retoswap, anyone can potentially track transactions, it’s not just the admins. That’s because haveno.markets openly shares trade stats, making it easier for third parties to analyze and follow the transactions.&lt;br/&gt;&lt;br/&gt;May freeze or seize funds&lt;br/&gt;&lt;br/&gt;Retoswap runs on Haveno, which is a decentralized, non-custodial multi-sig exchange. That’s true because your private key is generated locally, so only you have access to your funds in the Haveno wallet.&lt;br/&gt;&lt;br/&gt;However, to publish a sell offer, a vendor must lock up coins (15% security deposit and the trade amount). These funds can potentially be frozen or seized because the admin can easily have two keys required to sign a transaction. The haveno FAQ suggests that the admin/arbiter only has one key, but in practice, anyone can become a taker, there is practically nothing preventing the admin from possessing two keys.&lt;br/&gt;&lt;br/&gt;Some users have spoken out about this openly on platforms like Nostr, Reddit, and others, raising concerns about potential exit scams in how the system is set up. So, it’s worth being aware of these issues before jumping in.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/&lt;/a&gt;&lt;br/&gt;&lt;a href=&#34;https://archive.ph/gSRVs#25%&#34;&gt;https://archive.ph/gSRVs#25%&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Centralization of XMR market and tracking every transaction&lt;br/&gt;Retoswaps objective appears to be the centralization of XMR liquidity through their unique setup with pre-funded offers. Furthermore, Woodser (developer associated with Haveno) has not addressed the rugpuller bot issue that I initially identified six months ago. This is not due to incompetence but rather suggests a lack of independence, as the Reto guy has accepted donations from questionable sources. Such actions raise concerns about the integrity of the haveno development process.&lt;br/&gt;Source: link to shortwavesurfer about donations&lt;br/&gt;&lt;br/&gt;Quote mister_monster:&lt;br/&gt;&amp;gt; So, Reto has basically no fees right now. They don’t really benefit financially from being the only haveno network with liquidity. Yet, [b]it does seem that they do want to have a monopoly position within our community[b]. &lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://monero.town/post/5172146&#34;&gt;https://monero.town/post/5172146&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Amazon used the same tactic to take over the market, operating at a loss and funded by questionable sources until competitors were pushed out. Now, this new platform is promising decentralization, non-custodial transactions, and privacy. But the reality is, none of that seems to hold up. It&amp;#39;s all about crushing the competition and cornering the XMR market, and tracking every transaction? That&amp;#39;s not exactly a recipe for trust. It might not be a honeypot, but it sure smells a lot like one. Proceed with extreme caution.&lt;br/&gt;&lt;br/&gt;Discuss on dread: &lt;a href=&#34;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/be82f1a0c5e0f79f6dbb&#34;&gt;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/be82f1a0c5e0f79f6dbb&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #rugpull #transparency #stats
    </content>
    <updated>2025-07-09T19:59:24&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs06hzzafd93m7fa0q7r2nk3tnxju8n2xpql7jfv2whe7pntxffv0qzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cqtnnr8</id>
    
      <title type="html">openmonero.markets VS. haveno.markets I still can&amp;#39;t get over ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs06hzzafd93m7fa0q7r2nk3tnxju8n2xpql7jfv2whe7pntxffv0qzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cqtnnr8" />
    <content type="html">
      openmonero.markets VS. haveno.markets&lt;br/&gt;&lt;br/&gt;I still can&amp;#39;t get over how haveno.markets shows both the time and amount (XMR) for each trade, which could allow timing attacks and hurt user privacy. On the other hand, openmonero.markets doesn’t show any trade times or amounts.&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #rugpull #transparency #stats&lt;br/&gt;
    </content>
    <updated>2025-07-03T09:58:20&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp7deg7jg48wg3p54dfeq76kyy37hvae45zpv2c320menz2x8xlegzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c0a0m2a</id>
    
      <title type="html">We are pleased to announce the launch of a dedicated statistics ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp7deg7jg48wg3p54dfeq76kyy37hvae45zpv2c320menz2x8xlegzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c0a0m2a" />
    <content type="html">
      We are pleased to announce the launch of a dedicated statistics and market data page, offering comprehensive information for users.&lt;br/&gt;&lt;br/&gt;URL: &lt;a href=&#34;https://openmonero.com/markets&#34;&gt;https://openmonero.com/markets&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;DONE: xmr/usd, liquidity, top markets, daily volume, sell offers, buy offers, registered users, active vendors, top payment methods, latest trades, total trades, total volume, trades last 30d/24h/yesterday/today, volume last 30d/24h/yesterday/today&lt;br/&gt;&lt;br/&gt;COMING SOON: average trade finalization time, top vendors&lt;br/&gt;&lt;br/&gt;If you&amp;#39;re worried about timing attacks, I&amp;#39;ve taken out the timestamp, username and amount details from the latest trades table to help protect your privacy. &lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #rugpull #transparency #stats
    </content>
    <updated>2025-07-02T15:58:25&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfqxkphj3fs9x3plnzzkw3pc5hstv62kzg4hsk9jtj9vztv7fsvkczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cmduyqa</id>
    
      <title type="html">It is easy to fix the rug pull issue if they just disable ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfqxkphj3fs9x3plnzzkw3pc5hstv62kzg4hsk9jtj9vztv7fsvkczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cmduyqa" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs077ye6457dmh5nlysp5vq65arvfay8qw7ryllxydcpmjl3er95mspr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp0l6w3qe&#39;&gt;nevent1q…w3qe&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;It is easy to fix the rug pull issue if they just disable pre-funded offers and allow each maker to fund the trade after a taker request instead. However, they aren&amp;#39;t interested in doing so, since it would significantly decrease liquidity. 
    </content>
    <updated>2025-06-18T11:07:04&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9px0h7cc5yt54nhyf0dveqcqh50d2q54zu4m2eymw5s34rvvzvqczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cjajmq9</id>
    
      <title type="html">Quote shortwavesurfer2009: The way it would work would be that an ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9px0h7cc5yt54nhyf0dveqcqh50d2q54zu4m2eymw5s34rvvzvqczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cjajmq9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxcmwkx26f0kmzqy9dmjhjm4j7h26f09v53s6azglwwagd2lvykucpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhs3e5tr7&#39;&gt;nevent1q…5tr7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Quote shortwavesurfer2009:&lt;br/&gt;The way it would work would be that an arbitrator would create a bot to take the offers and then use the key from the taker bot and their arbitrator key to steal the escrow which contains the seller&amp;#39;s Monero plus their security deposit.&lt;br/&gt;Source: nevent1qqs0h2fvwvcsg58l6xw9hwpav4kk3vry933rrm6pparrf0s7p9rel6gpz4mhxue69uhkg6t5w3hjuur4vghhyetvv9uszyrhwden5te0v5hxummn9ekx7mp0qythwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0mvpr6f
    </content>
    <updated>2025-06-17T18:58:12&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstfk879j7974mkx3tfspzs70xlm4rk4e5r5q0vupym2u9egm04dvqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c7u92rq</id>
    
      <title type="html">How can anyone honestly think that locked haveno coins are truly ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstfk879j7974mkx3tfspzs70xlm4rk4e5r5q0vupym2u9egm04dvqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c7u92rq" />
    <content type="html">
      How can anyone honestly think that locked haveno coins are truly in self-custody? In reality, bad haveno arbiters could easily pretend to be legit takers and get the 2/3 majority needed to approve a transaction, which could lead to theft. Even worse, admin bots could just wipe out the whole haveno order book with ease. This issues has been confirmed by official dread mods and some reddit users.&lt;br/&gt;&lt;br/&gt;Quote SaberhagenTheNameless: &lt;br/&gt;...afaict Haveno/Retoswap, in it&amp;#39;s current state, has more at risk from rugpulls than necessary - currently over a million USD at stake.&lt;br/&gt;Sell offers are sitting there waiting to be automatically locked into a 2/3 multisig once taken (from potentially malicious admins controlling  arbitrator/taker bots meaning they would have enough keys to steal)&lt;br/&gt;Right now nothing is really preventing admins from sweeping the entire orderbook on the sell side.&lt;br/&gt;Source: &lt;a href=&#34;https://primal.net/e/nevent1qqsy7hmx9n2ws94x92ftvc44ylkejyg8ygw9z9pt4eswj44yqewp3jcpzamhxue69uhkvet9v3ejumn0wd68ytnzv9hxgtcppemhxue69uhkummn9ekx7mp0qy08wumn8ghj7mn0wd68yttsw43zuam9d3kx7unyv4ezumn9wshs0gztdf&#34;&gt;https://primal.net/e/nevent1qqsy7hmx9n2ws94x92ftvc44ylkejyg8ygw9z9pt4eswj44yqewp3jcpzamhxue69uhkvet9v3ejumn0wd68ytnzv9hxgtcppemhxue69uhkummn9ekx7mp0qy08wumn8ghj7mn0wd68yttsw43zuam9d3kx7unyv4ezumn9wshs0gztdf&lt;/a&gt;&lt;br/&gt;Cached: &lt;a href=&#34;https://archive.ph/JOqDC#25%&#34;&gt;https://archive.ph/JOqDC#25%&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Quote shortwavesurfer2009:&lt;br/&gt;The way it would work would be that an arbitrator would create a bot to take the offers and then use the key from the taker bot and their arbitrator key to steal the escrow which contains the seller&amp;#39;s Monero plus their security deposit.&lt;br/&gt;Source: &lt;a href=&#34;https://primal.net/e/nevent1qqs0h2fvwvcsg58l6xw9hwpav4kk3vry933rrm6pparrf0s7p9rel6gpz4mhxue69uhkg6t5w3hjuur4vghhyetvv9uszyrhwden5te0v5hxummn9ekx7mp0qythwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0mvpr6f&#34;&gt;https://primal.net/e/nevent1qqs0h2fvwvcsg58l6xw9hwpav4kk3vry933rrm6pparrf0s7p9rel6gpz4mhxue69uhkg6t5w3hjuur4vghhyetvv9uszyrhwden5te0v5hxummn9ekx7mp0qythwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0mvpr6f&lt;/a&gt;&lt;br/&gt;Cached: &lt;a href=&#34;https://archive.ph/gSRVs#25%&#34;&gt;https://archive.ph/gSRVs#25%&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Quote /u/WoodenInformation730: &lt;br/&gt;The arbitrators could rug the whole orderbook (all sell offers and security deposits) by taking all the offers at once.&lt;br/&gt;Source: &lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwp7yhn/?context=3#mwp7yhn&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwp7yhn/?context=3#mwp7yhn&lt;/a&gt;&lt;br/&gt;Cached: &lt;a href=&#34;https://archive.ph/icuxp#65%&#34;&gt;https://archive.ph/icuxp#65%&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Quote: /u/monero_desk_support: &lt;br/&gt;After some thoughts, I think you are right and that the arbitration system in Haveno doesn&amp;#39;t prevent arbitrators from pulling the funds. They would need to create a bot that takes all the offers and automatically unlock the funds with the key of the taker and arbitrator&lt;br/&gt;Source: &lt;a href=&#34;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-cac5570453f7fa9f42&#34;&gt;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-cac5570453f7fa9f42&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Quote  /u/geonic_ (Monero Outreach Producer): &lt;br/&gt;Reto has been around for a few milliseconds basically and nothing stops the network operators from creating fake orders if the pot gets big enough. A network would have to be operating successfully for a few years before I trust it with any significant amounts.&lt;br/&gt;Source: &lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/m0ae3rk/?context=3#m0ae3rk&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/m0ae3rk/?context=3#m0ae3rk&lt;/a&gt;&lt;br/&gt;Cached: &lt;a href=&#34;https://archive.ph/bB1VN#84%&#34;&gt;https://archive.ph/bB1VN#84%&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Quote /u/WoodenInformation730: To post an offer, you have to deposit the amount &#43; security deposit. If an arbitrator acts maliciously, they could take an offer and essentially steal the funds by signing the 2/3 multisig transaction, since they&amp;#39;d have two keys.&lt;br/&gt;Source: &lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwj10k3/?context=3#mwj10k3&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwj10k3/?context=3#mwj10k3&lt;/a&gt;&lt;br/&gt;Cached: &lt;a href=&#34;https://archive.ph/icuxp#45%&#34;&gt;https://archive.ph/icuxp#45%&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Quote /u/jossfun:&lt;br/&gt;Haveno relies upon arbitration by the network you’re operating on. In a case where the arbitrators act maliciously they can create trades where they control 2/3 keys to seize funds.&lt;br/&gt;Source: &lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/&lt;/a&gt;&lt;br/&gt;Cached: &lt;a href=&#34;https://archive.ph/bB1VN&#34;&gt;https://archive.ph/bB1VN&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #bitcoin #btc #decentralized #nostr #moneroju&lt;br/&gt;
    </content>
    <updated>2025-06-17T18:56:20&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyvg9ja8ds9qj4q4n7fyu9lqmu73cllpaqjz9m83p7884w99dz3zszyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c9pxfpg</id>
    
      <title type="html">2 new repos have been released last week and the code is fully ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyvg9ja8ds9qj4q4n7fyu9lqmu73cllpaqjz9m83p7884w99dz3zszyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c9pxfpg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqqqyr27hlhcwul5qp5rm5lf8d8kcmhs5z54sg7c0zqwrddznaedgpr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp0q0936e&#39;&gt;nevent1q…936e&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;2 new repos have been released last week and the code is fully built on top of NOSTR. &lt;br/&gt;&lt;br/&gt;Frontend: &lt;a href=&#34;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex&#34;&gt;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex&lt;/a&gt;&lt;br/&gt;Backend: &lt;a href=&#34;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex-api&#34;&gt;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex-api&lt;/a&gt;&lt;br/&gt;Demo: &lt;a href=&#34;http://ek72x7tysgkrr754ce4np4e6ce5rtwtxphxibzmesnsbuyco5onlc5id.onion/&#34;&gt;http://ek72x7tysgkrr754ce4np4e6ce5rtwtxphxibzmesnsbuyco5onlc5id.onion/&lt;/a&gt;
    </content>
    <updated>2025-06-17T18:11:15&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstjhyx3a03zqru26mwtegh0ufht0zg43kfqvtxrrcvy7afu92s4aqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c5z2mqc</id>
    
      <title type="html">The haveno rugpull amount according to my calc is USD 2.5 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstjhyx3a03zqru26mwtegh0ufht0zg43kfqvtxrrcvy7afu92s4aqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c5z2mqc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy7hmx9n2ws94x92ftvc44ylkejyg8ygw9z9pt4eswj44yqewp3jcpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsxftykt&#39;&gt;nevent1q…tykt&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The haveno rugpull amount according to my calc is USD 2.5 millions &lt;br/&gt;NOTE: the security deposits from haveno market markers are part of the pot as well&lt;br/&gt;&lt;br/&gt;XMR/USD according to haveno.markets&lt;br/&gt;$283.10&lt;br/&gt;&lt;br/&gt;Liquidity according to haveno.markets&lt;br/&gt;7,474.47 XMR&lt;br/&gt;&lt;br/&gt;15% security deposits = Liquidity x 15/100&lt;br/&gt;1121.17 XMR&lt;br/&gt;&lt;br/&gt;rugpull amount = liquidity &#43; 15% security deposits&lt;br/&gt;rugpull amount = 7,474.47 &#43; 1121.17 XMR&lt;br/&gt;rugpull amount = 8595,64 XMR = 2,433,425.68 USD&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #bitcoin #btc #decentralized #nostr #moneroju
    </content>
    <updated>2025-06-17T09:52:15&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz87ynfmyj8wu089ywg93srsj26sughke386ylfjr0l82q3rkpvwszyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cx570ey</id>
    
      <title type="html">OpenMonero re-opening! Regarding the recent security issue on ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz87ynfmyj8wu089ywg93srsj26sughke386ylfjr0l82q3rkpvwszyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cx570ey" />
    <content type="html">
      OpenMonero re-opening! &lt;br/&gt;&lt;br/&gt;Regarding the recent security issue on June 6, 2025, there’s no sign that the main backend has been hacked. The breach led to about USD 20,000 (or 62 XMR) being stolen, mainly due to some bad configuration with ufw and wallet rpc. It’s worth mentioning that trade chats and MongoDB are hosted on different servers from the monero-wallet-rpc, so the core infrastructure is still secure. We’ll refund all affected users once the platform has collected enough arbiter fees..&lt;br/&gt;&lt;br/&gt;Read more here: &lt;a href=&#34;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/59e5b924658bac9124d0&#34;&gt;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/59e5b924658bac9124d0&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;------SECURITY UPDATES------&lt;br/&gt;- new monero wallet on a different hosting provider&lt;br/&gt;- all passwords and keys have been updated&lt;br/&gt;- monero-wallet-rpc is now bind to 127.0.0.1 to prevent remote access&lt;br/&gt;- arbiter address switched to cold wallet to protect refunds&lt;br/&gt;- DEX API fully isolated from openmonero.com to minimize security issues &lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #bitcoin #btc #decentralized #nostr #moneroju
    </content>
    <updated>2025-06-17T09:19:16&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp9uqrcvp38c5ch9xaa9u8e3rgq3aurp5qadyqkea5vdutgrnrgdqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cjl6sv7</id>
    
      <title type="html">Haveno’s multi-sig trading only protects trades that have ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp9uqrcvp38c5ch9xaa9u8e3rgq3aurp5qadyqkea5vdutgrnrgdqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cjl6sv7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxcmwkx26f0kmzqy9dmjhjm4j7h26f09v53s6azglwwagd2lvykucpzpmhxue69uhk2tnwdaejumr0dshs7mgkzf&#39;&gt;nevent1q…gkzf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Haveno’s multi-sig trading only protects trades that have already been accepted, which is about 1% of all the liquidity. The rest, like open offers, aren’t protected and could potentially be taken or misused by the admins. So, it’s confusing why some people still see Haveno as a fully self-custodial exchange, when in reality, it’s more like a centralized liquidity platform.&lt;br/&gt;&lt;br/&gt;For a more detailed understanding, please read the section about self-custodial trade funding:&lt;br/&gt;&lt;a href=&#34;https://openmonero.com/faq#self-custodial-trading-funding&#34;&gt;https://openmonero.com/faq#self-custodial-trading-funding&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #bitcoin #btc #decentralized #nostr #moneroju
    </content>
    <updated>2025-06-15T01:59:36&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp22enxa4xtw2xksljwhaswt7dwrvmyvhpcev6jvqzdstjujj3rsqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cdhyxs3</id>
    
      <title type="html">How can anyone honestly think that locked haveno coins are truly ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp22enxa4xtw2xksljwhaswt7dwrvmyvhpcev6jvqzdstjujj3rsqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cdhyxs3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxcmwkx26f0kmzqy9dmjhjm4j7h26f09v53s6azglwwagd2lvykucpzpmhxue69uhk2tnwdaejumr0dshs7mgkzf&#39;&gt;nevent1q…gkzf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;How can anyone honestly think that locked haveno coins are truly in self-custody? In reality, bad haveno arbiters could easily pretend to be legit takers and get the 2/3 majority needed to approve a transaction, which could lead to theft. Even worse, admin bots could just wipe out the whole haveno order book with ease. This issues has been confirmed by official dread mods and some reddit users.&lt;br/&gt;&lt;br/&gt;Quote /u/WoodenInformation730: &lt;br/&gt;The arbitrators could rug the whole orderbook (all sell offers and security deposits) by taking all the offers at once.&lt;br/&gt;Source: &lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwp7yhn/?context=3#mwp7yhn&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwp7yhn/?context=3#mwp7yhn&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Quote: /u/monero_desk_support: &lt;br/&gt;After some thoughts, I think you are right and that the arbitration system in Haveno doesn&amp;#39;t prevent arbitrators from pulling the funds. They would need to create a bot that takes all the offers and automatically unlock the funds with the key of the taker and arbitrator&lt;br/&gt;Source: &lt;a href=&#34;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-cac5570453f7fa9f42&#34;&gt;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-cac5570453f7fa9f42&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Quote  /u/geonic_ (Monero Outreach Producer): &lt;br/&gt;Reto has been around for a few milliseconds basically and nothing stops the network operators from creating fake orders if the pot gets big enough. A network would have to be operating successfully for a few years before I trust it with any significant amounts.&lt;br/&gt;Source: &lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/m0ae3rk/?context=3#m0ae3rk&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/m0ae3rk/?context=3#m0ae3rk&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Quote /u/WoodenInformation730: To post an offer, you have to deposit the amount &#43; security deposit. If an arbitrator acts maliciously, they could take an offer and essentially steal the funds by signing the 2/3 multisig transaction, since they&amp;#39;d have two keys.&lt;br/&gt;Source: &lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwj10k3/?context=3#mwj10k3&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwj10k3/?context=3#mwj10k3&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Quote /u/jossfun:&lt;br/&gt;Haveno relies upon arbitration by the network you’re operating on. In a case where the arbitrators act maliciously they can create trades where they control 2/3 keys to seize funds.&lt;br/&gt;Source: &lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #bitcoin #btc #decentralized #nostr #moneroju&lt;br/&gt;
    </content>
    <updated>2025-06-14T09:07:48&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszdygpc6gyvujc07tx63prxfz54lw8d7lcgeputnvvqxzvpkju7pqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c4pl3un</id>
    
      <title type="html">You may find this surprising, but just two days after the hack, I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszdygpc6gyvujc07tx63prxfz54lw8d7lcgeputnvvqxzvpkju7pqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c4pl3un" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9kjw6usgyyfr8llrcq5v4jl34dfqh5kq0w9kfd6v8sr5876cmr5gpzpmhxue69uhk2tnwdaejumr0dshsrz7tn8&#39;&gt;nevent1q…7tn8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;You may find this surprising, but just two days after the hack, I successfully open sourced the first decentralized peer-to-peer platform fully operational on NOSTR. This new repository represents the pioneering P2P Monero exchange featuring a decentralized reputation system and a federated order book. It incorporates all the functionalities typically found on openmonero.com, excluding self-destructing messages. Importantly, anyone can run their own instance, as the backend code is entirely open-source. The implementation is straightforward to audit, lightweight (only 4,500 lines of code) and genuinely decentralized, leveraging an open protocol like NOSTR that requires no additional software.&lt;br/&gt;&lt;br/&gt;Frontend: &lt;a href=&#34;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex&#34;&gt;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex&lt;/a&gt;&lt;br/&gt;Backend: &lt;a href=&#34;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex-api&#34;&gt;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex-api&lt;/a&gt;&lt;br/&gt;Demo: &lt;a href=&#34;http://ek72x7tysgkrr754ce4np4e6ce5rtwtxphxibzmesnsbuyco5onlc5id.onion/&#34;&gt;http://ek72x7tysgkrr754ce4np4e6ce5rtwtxphxibzmesnsbuyco5onlc5id.onion/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Regarding the recent security incident, there is no evidence to suggest that openmonero.com has been completely compromised. Only funds have been stolen; trade chats and MongoDB are hosted on separate servers from the monero-wallet-rpc, indicating that the core infrastructure remains intact.&lt;br/&gt;&lt;br/&gt;The primary objective is not to achieve absolute prevention of hacks, since no system can be 100% secure, but to minimize potential damage from the outset, similar to the principles of Qubes OS. This incident demonstrates that openmonero.com remains one of the most secure platforms available, capable of handling significant volume while maintaining minimal funds at risk, thus limiting potential losses in the event of a breach.&lt;br/&gt;&lt;br/&gt;To date, approximately USD 20,000 worth of user funds have been stolen, along with USD 3,000 in arbiter funds, despite a monthly trading volume approaching half a million dollars. Had I employed a setup similar to Haveno, I estimate that losses could have exceeded USD 2 million making recovery efforts challenging.&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #bitcoin #btc #decentralized #nostr
    </content>
    <updated>2025-06-12T18:24:11&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz7pf7ysc8s9vhvkx5lngrfp38wtjsxhfmw2jae7w5l0ks3rvyydgzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c4ztvm9</id>
    
      <title type="html">NOTE: The haveno arbitrators could rug the whole orderbook ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz7pf7ysc8s9vhvkx5lngrfp38wtjsxhfmw2jae7w5l0ks3rvyydgzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c4ztvm9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0eh6e2ehrk4qku2m282ak04lytlake9kzvjpkwrq4hd6tx854atspr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp0c5v3se&#39;&gt;nevent1q…v3se&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;NOTE: The haveno arbitrators could rug the whole orderbook (2,000,000 USD) despite multi-sig trades. &lt;br/&gt;&lt;br/&gt;Additionally, since offers on openmonero.com don’t require any pre-funding, the potential damage remains quite limited (similar to a single McDonald&amp;#39;s salary). A quick note: multi-signature setups typically require JavaScript, and possibly Java, which limits scalability and compatibility, especially with browsers like Tor.&lt;br/&gt;&lt;br/&gt;Moreover, multi-sig only secures about 1% of the total liquidity (trades in escrow or accepted), making it largely ineffective. On haveno, if a malicious arbiter manages to take all maker offers, they could potentially wipe out the entire order book (despite multi-sig trades). And having a security deposit doesn’t offer much protection either, since an attacker only needs to hold an amount of XMR equal to the lowest security deposit to take all maker offers. This pattern becomes clear when observing how each taker bot balance grows by a ton (logarithmic growth) after each transaction. More here: &lt;a href=&#34;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&#34;&gt;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;This principle has been validated both by my own analysis and confirmed by the official moderator of the dread sub and some reddit users. &lt;br/&gt;&lt;a href=&#34;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-cac5570453f7fa9f42&#34;&gt;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-cac5570453f7fa9f42&lt;/a&gt;&lt;br/&gt;&lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwj10k3/?context=3#mwj10k3&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwj10k3/?context=3#mwj10k3&lt;/a&gt;&lt;br/&gt;&lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwp7yhn/?context=3#mwp7yhn&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwp7yhn/?context=3#mwp7yhn&lt;/a&gt;
    </content>
    <updated>2025-06-12T17:51:03&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvmppyu3e7sz653n98fkqnfld30qyq9epfmennak2gf4h9dmfy4fczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cfmfdr8</id>
    
      <title type="html">openmonero.com may actually be one of the most secure platforms ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvmppyu3e7sz653n98fkqnfld30qyq9epfmennak2gf4h9dmfy4fczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cfmfdr8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvpjnvvg8swu7alkpdf93zm8jy0j8cvprc6058nyynuhac40whrlspz4mhxue69uhhyetvv9ujuerpd46hxtnfduhs4pvezy&#39;&gt;nevent1q…vezy&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;openmonero.com may actually be one of the most secure platforms out there, thanks to its use of non-custodial trade settlements, non-custodial funding, and relatively quick trade finalization (on hour). To date, only about 20k USD of user funds have been stolen, (plus 3k arbiter funds), despite a monthly trade volume of roughly half a million dollars. Had I implemented a setup like haveno, I’d probably have seen at least 2 million USD stolen (good luck trying to refund that).&lt;br/&gt;&lt;br/&gt;You can read more about the hack here: &lt;a href=&#34;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/59e5b924658bac9124d0&#34;&gt;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/59e5b924658bac9124d0&lt;/a&gt;
    </content>
    <updated>2025-06-12T17:49:25&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs97jm0jh47gzs4gfjmjyuae2fd3x6tmyqge292tgn3ftdafv9x7kqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c6h30ze</id>
    
      <title type="html">You can read more about the hack here: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs97jm0jh47gzs4gfjmjyuae2fd3x6tmyqge292tgn3ftdafv9x7kqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c6h30ze" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0f23s5av3kmg5r8ctcz4tpmqctydxqrg4kp0a8xpq0d94t392r2gpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsw54mhp&#39;&gt;nevent1q…4mhp&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;You can read more about the hack here: &lt;a href=&#34;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/59e5b924658bac9124d0&#34;&gt;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/59e5b924658bac9124d0&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;NOTE: The haveno arbitrators could rug the whole orderbook (2,000,000 USD) despite multi-sig trades. &lt;br/&gt;&lt;br/&gt;Ironically, openmonero.com may actually be one of the most secure platforms out there, thanks to its use of non-custodial trade settlements, non-custodial funding, and relatively quick trade finalization (on hour). To date, only about 20k USD of user funds have been stolen, (plus 3k arbiter funds), despite a monthly trade volume of roughly half a million dollars. Had I implemented a setup like haveno, I’d probably have seen at least 2 million USD stolen (good luck trying to refund that).&lt;br/&gt;&lt;br/&gt;Additionally, since offers on openmonero.com don’t require any pre-funding, the potential damage remains quite limited (similar to a single McDonald&amp;#39;s salary). A quick note: multi-signature setups typically require JavaScript, and possibly Java, which limits scalability and compatibility, especially with browsers like Tor.&lt;br/&gt;&lt;br/&gt;Moreover, multi-sig only secures about 1% of the total liquidity (trades in escrow or accepted), making it largely ineffective. On haveno, if a malicious arbiter manages to take all maker offers, they could potentially wipe out the entire order book (despite multi-sig trades). And having a security deposit doesn’t offer much protection either, since an attacker only needs to hold an amount of XMR equal to the lowest security deposit to take all maker offers. This pattern becomes clear when observing how each taker bot balance grows by a ton (logarithmic growth) after each transaction. More here: &lt;a href=&#34;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&#34;&gt;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;This principle has been validated both by my own analysis and confirmed by the official moderator of the dread sub and some reddit users. &lt;br/&gt;&lt;a href=&#34;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-cac5570453f7fa9f42&#34;&gt;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-cac5570453f7fa9f42&lt;/a&gt;&lt;br/&gt;&lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwj10k3/?context=3#mwj10k3&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwj10k3/?context=3#mwj10k3&lt;/a&gt;&lt;br/&gt;&lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwp7yhn/?context=3#mwp7yhn&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1l5jkp2/openmonerocom_got_hacked_as_reported_in_their/mwp7yhn/?context=3#mwp7yhn&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk #rugpull
    </content>
    <updated>2025-06-12T12:59:10&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqjpmk2vzpw4chhukgdp8sd9s8qv49mzxp5lvvfw8n555edg4r2jszyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cjw0u3z</id>
    
      <title type="html">I&amp;#39;ve just open sourced the first p2p monero platform that is ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqjpmk2vzpw4chhukgdp8sd9s8qv49mzxp5lvvfw8n555edg4r2jszyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cjw0u3z" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0f23s5av3kmg5r8ctcz4tpmqctydxqrg4kp0a8xpq0d94t392r2gpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsw54mhp&#39;&gt;nevent1q…4mhp&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;ve just open sourced the first p2p monero platform that is completely based on NOSTR, with a decentralized reputation system (PGP canaries), a federated orderbook, non-custodial trade funding, non-custodial trade settlements and anyone can setup his own instance since the backend is open source as well. I am telling you once again, haveno is a centralized liquidity exchange, since the admin can take all offers. All that is required for such an exploit is access to the admin key, two bots (taker and arbiter bot), and an amount of XMR equivalent to the lowest security deposit (a mechanism evident from the logarithmic balance growth of each taker bot following each transaction. More here: &lt;a href=&#34;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-779f1c27e12e98e6af&#34;&gt;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-779f1c27e12e98e6af&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk
    </content>
    <updated>2025-06-12T11:49:22&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswcvp5te36u6gsecvvq3jmwnp3tgf03kynfng73hxy3dgcppctzpgzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c6vjecc</id>
    
      <title type="html">Check out the new decentralized exchange based on Nostr and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswcvp5te36u6gsecvvq3jmwnp3tgf03kynfng73hxy3dgcppctzpgzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c6vjecc" />
    <content type="html">
      Check out the new decentralized exchange based on Nostr and OpenMonero/LocalMonero frontend. The code is production ready but I can&amp;#39;t setup a fully working instance right now, since 2 of my servers have been hacked on 6/6/2025. You can checkout the demo below or clone the code and setup your own instance. The Backend has just 4.5k lines of code in a single file and is very easy to audit.&lt;br/&gt;&lt;br/&gt;New powerful updates:&lt;br/&gt;&lt;br/&gt;    Decentralized, new reputation system not locked to any specific location or instance.&lt;br/&gt;    Federated and decentralized order book model allows for a combined order book across multiple instances.&lt;br/&gt;    All data, including the order book, reputation, profiles, trades, wallet information, and chat, is stored on NOSTR.&lt;br/&gt;    Admins do not have access to chat history unless a trade dispute arises (E2EE with NIP-04).&lt;br/&gt;    Wallet protection with two-factor authentication (2FA) instead of a traditional password.&lt;br/&gt;    Websockets facilitate real-time event updates without requiring a page refresh.&lt;br/&gt;&lt;br/&gt;Frontend: &lt;a href=&#34;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex&#34;&gt;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex&lt;/a&gt;&lt;br/&gt;Backend: &lt;a href=&#34;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex-api&#34;&gt;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-dex-api&lt;/a&gt;&lt;br/&gt;Demo: &lt;a href=&#34;http://ek72x7tysgkrr754ce4np4e6ce5rtwtxphxibzmesnsbuyco5onlc5id.onion/&#34;&gt;http://ek72x7tysgkrr754ce4np4e6ce5rtwtxphxibzmesnsbuyco5onlc5id.onion/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk
    </content>
    <updated>2025-06-11T11:42:16&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0e9mdcpyqj7epuj060zldh6g403dngjum5cf2qyrxfwygl4hf94qzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cjpyljp</id>
    
      <title type="html">I am looking for a browser that has the following features: - ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0e9mdcpyqj7epuj060zldh6g403dngjum5cf2qyrxfwygl4hf94qzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cjpyljp" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8e59hdnq2a5zw9xpg3etkqk9mq3zwjwg7tqpevjz53ehgwkz3zeqpzamhxue69uhhyetvv9ujuurjd9kkzmpwdejhgtc5s3x0v&#39;&gt;nevent1q…3x0v&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I am looking for a browser that has the following features:&lt;br/&gt;&lt;br/&gt;- same anonymity as tor browser&lt;br/&gt;- built-in i2p &lt;br/&gt;- adblocker addon pre-installed to prevent fingerprinting&lt;br/&gt;- option to add whitelist for js and persist after restart&lt;br/&gt;
    </content>
    <updated>2025-04-26T10:13:26&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsppfp9t8te0esz59cwhy0x6ykhwvau6zmpnysr6nge2tcjn0thucgzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5czzcjmm</id>
    
      <title type="html">A lot of third-party wallets claim to be non-custodial, but they ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsppfp9t8te0esz59cwhy0x6ykhwvau6zmpnysr6nge2tcjn0thucgzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5czzcjmm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfv65rpu2c6faedg9gwmsnym5es4eudn3e4l2xjgstt80u8p2424cppemhxue69uhkummn9ekx7mp0wttg4z&#39;&gt;nevent1q…tg4z&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;A lot of third-party wallets claim to be non-custodial, but they might actually mess with your privacy, track what you do, or even put your funds at risk. To stay safe, stick with the official Monero wallets at getmonero.org.&lt;br/&gt;&lt;br/&gt;Cakewallet requires an account, leaks metadata, and can track usage patterns.&lt;br/&gt;&lt;br/&gt;Furthermore, I am uncertain whether Cake Wallet is fully non-custodial, as it raises the question of how their backend API facilitate swaps without access to your private key (how do they pull that off). It seems logical to conclude that they must have access to the private key for the swap process to function effectively. Because of that, I can’t really recommend this wallet, especially since it supports some shady tokens that might be tied to scams.&lt;br/&gt;&lt;br/&gt;I’m not pushing any specific wallet, but if you want something clean and simple, check out monero-wallet-cli. It’s a solid choice!&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk&lt;br/&gt;
    </content>
    <updated>2025-04-07T16:04:53&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst82y964nm06lt4llhqtrxfgumnk797pxf9u7045r4a2x5zmyct8gzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5ccv4el2</id>
    
      <title type="html">I don’t really recommend any wallet, but if you’re looking ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst82y964nm06lt4llhqtrxfgumnk797pxf9u7045r4a2x5zmyct8gzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5ccv4el2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsysamp6l4553u7yt5524k6hx8laa6lk7td6gj7fdu67nuh69mu8vgppemhxue69uhkummn9ekx7mp0g558ky&#39;&gt;nevent1q…58ky&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I don’t really recommend any wallet, but if you’re looking for something without bloat, you might want to check out monero-wallet-cli.
    </content>
    <updated>2025-04-07T15:46:21&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0mk032cs36adgzxpnqkpwykt5wd5vzayyp2l0xf6dsl8k36hse6gzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cft9ek0</id>
    
      <title type="html">I do not have simpleX yet. Could you pls review ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0mk032cs36adgzxpnqkpwykt5wd5vzayyp2l0xf6dsl8k36hse6gzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cft9ek0" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg33930gjzmv22eakrjxs6azy6mfduut3fp2prc7wxnnkaf4tjruqppemhxue69uhkummn9ekx7mp0mwtqxf&#39;&gt;nevent1q…tqxf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I do not have simpleX yet. Could you pls review &lt;a href=&#34;https://kycnot.me/service/openmonero&#34;&gt;https://kycnot.me/service/openmonero&lt;/a&gt;
    </content>
    <updated>2025-03-08T00:33:44&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz3tg8hcngc5j2q5q2lfjcdyz0qyrrpdxpt7h6ymnwtw7q7rk30wqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5caynzts</id>
    
      <title type="html">Let&amp;#39;s be real, nothing comes for free. The fact that there ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz3tg8hcngc5j2q5q2lfjcdyz0qyrrpdxpt7h6ymnwtw7q7rk30wqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5caynzts" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs83x0cnvzg7gq7dv6vh0m7ze4nn6lwq76kz7urzvt6ek9jsxcmmmspzemhxue69uhhqatjwpkx2un9d3shjtnrdakj7krr5su&#39;&gt;nevent1q…r5su&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Let&amp;#39;s be real, nothing comes for free. The fact that there are no arbitration fees on the retoswap network might make you think that users are actually the product. If you dig a little deeper, you&amp;#39;ll find a bunch of issues, with the risk of exit scams being a big one. &lt;br/&gt;&lt;br/&gt;A decentralized node network is only secure if there&amp;#39;s no admin who can circumvent the rules. To address the exit scam issue, either eliminate the admin or remove the liquidity. &lt;br/&gt;&lt;br/&gt;People want to trade online without the hassle of installing software, which can threaten their privacy. Trusting someone to keep your computer safe isn’t easy, and even open-source code can have hidden risks since most don’t compile it themselves. With OpenMonero, you can avoid those worries because it’s just a website that doesn’t need permissions.&lt;br/&gt;&lt;br/&gt;The built-in non-custodial wallet for haveno funds isn’t very secure either, since private keys could be logged, and the project isn’t truly decentralized. The GitHub repo isn’t easy to fork, it’s built in Java and is pretty complicated. The more complex the code is, the tougher it gets for developers to spot vulnerabilities or malicious code. &lt;br/&gt;&lt;br/&gt;Haveno is better at resisting censorship than OpenMonero, but this mainly benefits the admin. Without a reputation system, vendors can&amp;#39;t import any stats to other platforms, leaving their accounts on Haveno fairly low in value. It’s unlikely that any former LocalMonero vendor, who has built up their reputation over the years, would want to use this system.&lt;br/&gt;&lt;br/&gt;OpenMonero launched in June 2024, and I&amp;#39;ve recently started promoting it on social media. I encourage you to check out our list of over 150 verified vendors, including respected LocalMonero traders. If these vendors have confidence in the platform, users are likely to feel the same way.&lt;br/&gt;Vendor list: &lt;a href=&#34;https://nojs.openmonero.com/guides/how-to-import-reputation#cachedUserList&#34;&gt;https://nojs.openmonero.com/guides/how-to-import-reputation#cachedUserList&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Reference: &lt;a href=&#34;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&#34;&gt;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&lt;/a&gt;&lt;br/&gt;Reference: &lt;a href=&#34;https://primal.net/e/nevent1qqsq2pcudt9rdq4wwpk7r784fwr5h0lt4fhzj6cvaeckurla6wg29dqkrrz7a&#34;&gt;https://primal.net/e/nevent1qqsq2pcudt9rdq4wwpk7r784fwr5h0lt4fhzj6cvaeckurla6wg29dqkrrz7a&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex #cex #moneroju #xmrbaazar #security #agorism #cypherphunk&lt;br/&gt;
    </content>
    <updated>2025-03-04T21:20:24&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfq5ppd2xv4d327dujy2jadt9w8a94qdjqv79dukg4zrmr7sypcmqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5ch3qpux</id>
    
      <title type="html">Basically, the haveno network operator can give admin roles to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfq5ppd2xv4d327dujy2jadt9w8a94qdjqv79dukg4zrmr7sypcmqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5ch3qpux" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszmu277pnm67pjcwc58pm767g66qwx9zr65j6mwdf33693mfafgwspzamhxue69uhhyetvv9ujuurjd9kkzmpwdejhgtcy4rhne&#39;&gt;nevent1q…rhne&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Basically, the haveno network operator can give admin roles to both taker and arbiter bots as well, which lets them ignore any rules in place. This speeds up things a lot since there’s no need to put down a security deposit for each taker bot, allowing all maker funds to be unlocked right away. These bots only work on the API level, so they don&amp;#39;t mess with the user interface.&lt;br/&gt;&lt;br/&gt;Because of this, it doesn’t really matter if you set up limitations on the frontend or the public API; the admin bots will always be able to access the protected API endpoints. This access is key to getting around rules like security deposits, rate limits, or any other client-side requirements for takers or arbiters.&lt;br/&gt;&lt;br/&gt;The admin bots won’t use the public API, since developers would catch any shady changes to it. Instead, they’ll send requests to a protected API run by the network operator on a low-cost VPS for about $5 USD. Only the admin bots (taker and arbiter) will have the keys to access this protected API. This API will basically look like the public API but will have tweaks to bypass all those rules. So, only the maker will use the public API and will have to follow its rules.&lt;br/&gt;&lt;br/&gt;To make things work, all you really need is the admin key, a protected API, and a few VPS servers for the taker and arbiter bots. These taker bots will throw the admin keys into the headers of their requests. If a normal taker tries to hit up the protected API without the admin keys, the request won&amp;#39;t work. It’s actually pretty simple, and it might have been overlooked because of that.&lt;br/&gt;&lt;br/&gt;Also, it’s good to remember that multi-signature setups only make sense when there’s no admin or network operator. The operator is always a single point of failure and can sidestep any limits on the API using their admin keys. &lt;br/&gt;&lt;br/&gt;If anyone has a solid reason why this wouldn’t actually work, I’d love to hear it. When someone has the admin keys for their network, they can pretty much do whatever they want and set the rules while everyone else has to follow along. &lt;br/&gt;&lt;br/&gt;To wrap it up, everyone in the haveno network, the taker, the arbiter, and the maker will get a key in the multi-sig trade. But there&amp;#39;s also a fourth key, called the &amp;#34;magic key&amp;#34; that can do a bunch of powerful things, some of which could be a bit risky. &lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Reference:  &lt;a href=&#34;https://archive.ph/GsDsn&#34;&gt;https://archive.ph/GsDsn&lt;/a&gt;&lt;br/&gt;Thread:  &lt;a href=&#34;https://primal.net/e/nevent1qvzqqqqqqyqzqpg8r34v5d5z4ecxmc0c749cwjalaw4xu2ttpnh8zms0lhfepg450s7qlk&#34;&gt;https://primal.net/e/nevent1qvzqqqqqqyqzqpg8r34v5d5z4ecxmc0c749cwjalaw4xu2ttpnh8zms0lhfepg450s7qlk&lt;/a&gt;&lt;br/&gt;Interview: &lt;a href=&#34;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&#34;&gt;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex
    </content>
    <updated>2025-03-03T03:26:50&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsw3qj4zvg48g2lkagtfeugeqdvl3k33ggd9fwdz347wdzsgpxhg3szyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cxst4nn</id>
    
      <title type="html">OpenMonero response to Woodser haveno dev (haveno rug pull ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsw3qj4zvg48g2lkagtfeugeqdvl3k33ggd9fwdz347wdzsgpxhg3szyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cxst4nn" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx8cs8tlq2xg25535uaxvhth49cmnflf5z0wdvu9ex7wa38w5y5xspzamhxue69uhhyetvv9ujuurjd9kkzmpwdejhgtcue9lpx&#39;&gt;nevent1q…9lpx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;OpenMonero response to Woodser haveno dev (haveno rug pull scenario)&lt;br/&gt;&lt;br/&gt;&amp;gt; a malicious arbitrator could attempt to take offers, hoping to be assigned trades and then unfairly award funds to themselves. however this risk can be mitigated by:&lt;br/&gt;&lt;br/&gt;&amp;gt; a sufficient number of arbitrators - the best way to mitigate this risk is to have a sufficient number of honest arbitrators, so a dishonest arbitrator is unlikely to be assigned a trade before being detected and banned. this creates an economic incentive for arbitrators to act honestly and earn trade fees rather than risk exclusion&lt;br/&gt;&lt;br/&gt;I totally agree that individual arbiters need to act honestly so they don&amp;#39;t get banned by the network operator. But honestly, that&amp;#39;s not the main issue here. The real risk of a rug pull attack (or exit scam) doesn’t come from those individual arbiters, but from the network operator, whom we’ll call &amp;#34;Reto.&amp;#34; Reto has the power to assign arbiter roles, which is where the problem lies.&lt;br/&gt;&lt;br/&gt;The network operator is a single point of failure because he can create as many arbiter roles as he wants since he holds the admin key. Sure, Reto might give a few trusted individuals arbiter roles to make things look decentralized and transparent. But he could just as easily assign a bunch of roles to bots he controls. Plus, Reto would be in charge of all the taker bots, since anyone can jump in and be a taker. This setup lets Reto secure a two-thirds majority in any disputes that come up.&lt;br/&gt;&lt;br/&gt;So, when it comes to pulling off an attack in this scenario, the odds are nearly 99.99% in favor of success. That’s because, when the attack happens, most of the arbiters and takers will likely be bots, all under Reto&amp;#39;s control, making them the real weak link in the system.&lt;br/&gt;&lt;br/&gt;&amp;gt; arbitrator selection by the maker - the maker can select an arbitrator from a trusted list rather than relying on random assignment (the current default)&lt;br/&gt;&lt;br/&gt;The network operator is probably going to kick out all the human arbiters before they carry out the rug pull. This means the makers won’t have any choice but to use arbiter bots. Plus, the makers won’t really have a chance to dispute anything because a taker bot will just send a fake &amp;#34;I have paid&amp;#34; message even though they haven&amp;#39;t actually paid. Then, that taker bot will start a dispute, leaning on the arbiter bot to back them up and go after the maker&amp;#39;s funds unfairly.&lt;br/&gt;&lt;br/&gt;In the end, the arbiter will take the 15% security deposit from the maker, while the taker bot walks away with the trading funds and its own 15% security deposit. The key thing to remember here is that both the taker and arbiter bots are under the control of the network operator, so all that money ends up in their hands, leaving the maker with nothing.&lt;br/&gt;&lt;br/&gt;&amp;gt; trade limits per client - restricting the number of active trades or funds at risk per client further reduces potential damage from a dishonest arbitrator&lt;br/&gt;&lt;br/&gt;If you try to limit how many active trades takers can have, it won’t really make a difference because anyone can be a taker. So, the network operator (or reto admin) could just set up as many taker bots as they need to get around those limits.&lt;br/&gt;&lt;br/&gt;&amp;gt; in contrast, centralized exchanges like localmonero, lm, etc require full trust in the platform operators, because they take full custody of traded funds and can easily steal them at that time&lt;br/&gt;&lt;br/&gt;I totally agree with you that most p2p platforms (like centralized exchanges) usually hold full custody of the funds since they require pre-funding for trades. But OpenMonero is different because it doesn’t need sellers to fully fund their trades upfront thanks to its self-custodial trade funding setup. The platform can’t access all of the liquidity at once unless every seller decided to post their bonds at the same time, which is statistically improbable.&lt;br/&gt;&lt;br/&gt;It’s also worth mentioning that LocalMonero used to lack the self-custodial trade funding option, meaning that seller funds were always at risk while they waited for trade requests. Right now, OpenMonero can only tap into a maximum of 2% of the total liquidity at any given time, unless every seller posts their externally funded bond at the same time, which remains statistically improbable.&lt;br/&gt;&lt;br/&gt;So, we can say that OpenMonero acts like a centralized exchange, but the liquidity is actually decentralized thanks to the self-custodial trade settlements for buyers and self-custodial trade funding for sellers. I suggest checking out the examples on simplifiedprivacy.com for more insights, especially if you’re looking into advanced examples.&lt;br/&gt;&lt;br/&gt;&amp;gt; reputation can be easily faked, so does not provide any guarantee of trustworthiness in trade partners&lt;br/&gt;&lt;br/&gt;No system is perfect, but it&amp;#39;s fair to say that having a reputation system is definitely better than having no verification at all. It’s worth mentioning that faking a reputation system isn’t easy and it requires a lot of money and time. Sure, someone could try to create fake trades on OpenMonero, but the system can pick up on that pretty quickly (for ex, if someone makes 1000 trades in a short period, that would definitely raise some eyebrows)&lt;br/&gt;&lt;br/&gt;Sellers/Buyers can also check users&amp;#39; Telegram handles through trusted sites like localmonero.co or confirm PGP keys from reliable sources, including LocalMonero and imported profiles.&lt;br/&gt;&lt;br/&gt;Plus, you can’t do coin-locking on OpenMonero since sellers need to fund trades manually. It’s not an automated process like on networks like Haveno, which really helps to reduce the chances of exit scams. When it comes to offers on OpenMonero, they’re not fully funded right away. You only need 0.35 XMR to list an ad in the search results. This is mainly to fend off spam listings, but it can also help fund smaller trades. If a trade is bigger, sellers have the option to use an external, fully isolated wallet to fund the transaction and keep themselves safe from any potential scams right from the start.&lt;br/&gt;&lt;br/&gt;&amp;gt; they can collect and store sensitive trade details across all traders&lt;br/&gt;&lt;br/&gt;I don’t have an admin panel to keep track of trades or messages, and users can set up self-destructing messages right after a trade or completely delete their accounts. This kind of feature probably wouldn’t work in decentralized systems since all data is saved on multiple nodes. Also, the OpenMonero wallet creates a new address every time you make a deposit to help keep your privacy intact.&lt;br/&gt;&lt;br/&gt;&amp;gt; they&amp;#39;re more likely to be shut down due to legal compliance, and you&amp;#39;re left to find a new service&lt;br/&gt;&lt;br/&gt;My identity is kept private, and OpenMonero vendors don’t have to go through any KYC checks, which means we can totally work outside of regulations. This works because the platform isn&amp;#39;t custodial, it&amp;#39;s open-source, and you can access it via Tor hidden services and I2P. So, even if the clearnet domain gets taken down by the authorities, the exchange would still run smoothly. Anyone can self-host the frontend or even fork the code to make their own OpenMonero version. Plus, we’re working on a Nostr-based version that lets anyone become an escrow provider or self-host the frontend without needing any backend. This would make it super resistant to censorship. Check out the interview for more details!&lt;br/&gt;&lt;br/&gt;&amp;gt; ultimately users should consider the trustworthiness of the haveno network they&amp;#39;re using and its arbitrators, but these networks provide greater decentralization, privacy, and control of funds than centralized services, which are a single point of failure&lt;br/&gt;&lt;br/&gt;Most of my vendors don’t really need to trust me because they don’t have to download any software or put down trading funds upfront to get trade requests (unlike Haveno). This really cuts down the chances of exit scams right from the start, and it keeps their personal files safe from malicious access. The OpenMonero web app runs smoothly in any browser and doesn’t connect to the user’s system, which is way different from Haveno that needs to be installed and has a daemon running all the time on your computer (definitely a recipe for keyloggers and shady auto updates). Plus, the built-in non-custodial wallet in Haveno isn’t very secure since malicious updates could come with keyloggers to snag your private keys. But with OpenMonero, vendors can fund their bonds using totally isolated wallets like Cake Wallet, Moneroju, Monero Wallet CLI, Feather Wallet, Trezor, and more.&lt;br/&gt;&lt;br/&gt;The Haveno platform mainly looks out for the network operators, but it doesn’t really do much to protect market makers. This leaves them open to the risk of exit scams since the liquidity, the most important asset, is fully controlled by the network operator.&lt;br/&gt;&lt;br/&gt;Also, let’s be clear: Haveno isn&amp;#39;t truly decentralized. Accounts and order books don’t get shared between different Haveno instances, which creates a fragmented setup that’s kind of like a local network. The system would work a lot better if there was one big network where accounts and offers were merged from various instances instead of just having this isolated system run by a single operator. That’s not how decentralization should work.&lt;br/&gt;&lt;br/&gt;When we talk about fund security, decentralization isn’t the most important factor. What really matters are things like how quickly trades get finalized, self-custodial trade settlements and self-custodial funding, along with a solid reputation system. Without a reputation system, there’s no trust between trading partners. Plus, if we don’t have self-custodial settlements or funding, the admin could easily run off with all the liquidity.&lt;br/&gt;&lt;br/&gt;I’d love to keep the conversation going if you have any other points you want to bring up. I think Haveno does a pretty good job of protecting network operators, and I really appreciate that it’s open-source!&lt;br/&gt;&lt;br/&gt;However I think OpenMonero is more safe (multi-sig vs self-custodial) and has 98% less risk of total liquidity being jeopardized at all times. The occurrence of exit scams is relatively low within this model. &lt;br/&gt;&lt;br/&gt;Reference:  &lt;a href=&#34;https://archive.ph/GsDsn&#34;&gt;https://archive.ph/GsDsn&lt;/a&gt;&lt;br/&gt;Interview: &lt;a href=&#34;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&#34;&gt;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides #Bisq #cakewallet #haveno #retoswap #trading #p2p #escrow #localmonero #dex&lt;br/&gt;&lt;br/&gt;
    </content>
    <updated>2025-03-02T03:09:45&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz2sqdprkp9ydyan9sstx05h2dsxdwhp75hjxycdx0g80xvuhje6szyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cptwy35</id>
    
      <title type="html">http://openmonero.i2p frontend can be self-hosted as well ( ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz2sqdprkp9ydyan9sstx05h2dsxdwhp75hjxycdx0g80xvuhje6szyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cptwy35" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy5v0hwmtd3yy6c8mmhxsxxq5lrjjem0wuer3qk6hu50976vp8z5gppemhxue69uhkummn9ekx7mp0h04dw6&#39;&gt;nevent1q…4dw6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;http://openmonero.i2p&#34;&gt;http://openmonero.i2p&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;frontend can be self-hosted as well ( &lt;a href=&#34;https://openmonero.com/readme&#34;&gt;https://openmonero.com/readme&lt;/a&gt;)
    </content>
    <updated>2025-03-01T22:52:35&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspyj7tnvn7n2zczhcterx3c5ff8h2jj6zanufcyfnrn2ya6xm8yygzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cxxxdxz</id>
    
      <title type="html">I could do shotgun scamming but exit scamming is not really ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspyj7tnvn7n2zczhcterx3c5ff8h2jj6zanufcyfnrn2ya6xm8yygzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cxxxdxz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstsjcjxmfctxqfpwf4wnq3uskkfgxgy79gmet6uxfvwyqw9mjnmzqpr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp0ryjnfc&#39;&gt;nevent1q…jnfc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I could do shotgun scamming but exit scamming is not really possible due to self-custodial trade fuding (sellers) and self-custodial trade settlements (buyers). Plus the nostr based version is almost finished.
    </content>
    <updated>2025-03-01T22:32:32&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9smlpznlnhhk8z6ng4pynn6sklmm9z6uufkp5nfgcay2ua670wagzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c8meqjg</id>
    
      <title type="html">Build from source Recommended node version (use nvm): v14.21.3 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9smlpznlnhhk8z6ng4pynn6sklmm9z6uufkp5nfgcay2ua670wagzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c8meqjg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyrq2xcjyug9wwmk03sejlppw7a6unane6ypq60ls722c6ywdea7cpr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp0qduhpx&#39;&gt;nevent1q…uhpx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Build from source&lt;br/&gt;&lt;br/&gt;Recommended node version (use nvm): v14.21.3&lt;br/&gt;&lt;br/&gt;sudo apt install torsocks&lt;br/&gt;torsocks git clone &lt;a href=&#34;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-reactjs.git&#34;&gt;http://rf5cqoxqlitdx4umuce5dgihjzabql4hs3zjkvs3em7xzjfa5yyhkeqd.onion/om/openmonero-reactjs.git&lt;/a&gt;&lt;br/&gt;cd openmonero-reactjs&lt;br/&gt;npm install&lt;br/&gt;npm start&lt;br/&gt;
    </content>
    <updated>2025-03-01T22:16:19&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsx59meuk5qnm28xvwgskjx6lgh5m4jqe2gwz9wy4n0zsxshasrmygzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c5949f4</id>
    
      <title type="html">Yes, check the openmonero-reactjs repo hosted on forgeo. Link is ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsx59meuk5qnm28xvwgskjx6lgh5m4jqe2gwz9wy4n0zsxshasrmygzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c5949f4" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyrq2xcjyug9wwmk03sejlppw7a6unane6ypq60ls722c6ywdea7cpr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp0qduhpx&#39;&gt;nevent1q…uhpx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Yes, check the openmonero-reactjs repo hosted on forgeo. Link is in the popup if you click the &amp;#34;Open source arttribute&amp;#34; inside &amp;#34;Why use our service&amp;#34;. Its the same code and can be self-hosted over tor hidden service.
    </content>
    <updated>2025-03-01T22:13:10&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvmjaqs3ewfmc7etdaqnk9gk0ucey6ncgz9gtulvwx0hq6qs8y2uszyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cuxjmm3</id>
    
      <title type="html">For added security, the mobile app is not native (PWA) to have ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvmjaqs3ewfmc7etdaqnk9gk0ucey6ncgz9gtulvwx0hq6qs8y2uszyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cuxjmm3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst9zpxvn3azzjw3mhmp4fvcwf5l6496jst8emhztrykrugz8cruycpr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp00jmfdh&#39;&gt;nevent1q…mfdh&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;For added security, the mobile app is not native (PWA) to have isolation from the filesystem. The web app is built with reactjs (selfhosting with docker possible), while the nojs version is based on php (codeigniter 4 framework)
    </content>
    <updated>2025-03-01T17:22:13&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdvd3gan38an8kzpredwphch5upqn3kjzfcuccuwfc2ldvdqexskgzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cgssfr9</id>
    
      <title type="html">Its already under construction. Quote Simple: That’s cool, so ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdvd3gan38an8kzpredwphch5upqn3kjzfcuccuwfc2ldvdqexskgzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cgssfr9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqqqyr27hlhcwul5qp5rm5lf8d8kcmhs5z54sg7c0zqwrddznaedgpzpmhxue69uhk2tnwdaejumr0dshs257u74&#39;&gt;nevent1q…7u74&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Its already under construction.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Quote Simple: That’s cool, so in the future, this can work entirely as a front-end javascript linked to Nostr? Then the site itself could be on Arweave or IPFS.&lt;br/&gt;&lt;br/&gt;Quote OpenMonero: The decentralized exchange will offer a selection of various escrow providers, arbitrators, and instances for users to choose from. Users will not be required to create accounts with each individual provider. All escrow providers utilize the same backend code, and to engage with a specific provider, one merely needs to be aware of its domain (no additional configuration or setup is required).&lt;br/&gt;&lt;br/&gt;Trusted escrow providers will be hardcoded into the code, while untrusted providers will be accessible through an integrated distributed hash table (DHT) network. The utilization of a DHT is crucial, as hardcoded directories are inherently susceptible to censorship. Furthermore, this approach surpasses that of a federated network, since defederation is neither necessary nor possible; the reputation system in place effectively mitigates spam from the outset.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&#34;&gt;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&lt;/a&gt;&lt;br/&gt;
    </content>
    <updated>2025-03-01T16:28:51&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0jlqupxntp0vn3afvpjuxmnwq5d6rpyx53tq2c4yyqhygxyag5yszyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cpdeqqd</id>
    
      <title type="html">https://openmonero.com/readme or https://nojs.openmonero.com ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0jlqupxntp0vn3afvpjuxmnwq5d6rpyx53tq2c4yyqhygxyag5yszyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cpdeqqd" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrjy4p30994ehgjgaauvdxn8x5k96j5dz8c5j4kny5f2ffetkqsvqpzamhxue69uhhyetvv9ujuurjd9kkzmpwdejhgtcs25fzn&#39;&gt;nevent1q…5fzn&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://openmonero.com/readme&#34;&gt;https://openmonero.com/readme&lt;/a&gt; &lt;br/&gt;or&lt;br/&gt;&lt;a href=&#34;https://nojs.openmonero.com&#34;&gt;https://nojs.openmonero.com&lt;/a&gt; =&amp;gt; click the &amp;#39;Open source code attribute&amp;#39; inside &amp;#39;Why use our service&amp;#39; 
    </content>
    <updated>2025-03-01T16:20:51&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg0tucq6q9sfg98cxjdsuje02az06jhjg8zqlhv7207wck56fahggzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cqr8m74</id>
    
      <title type="html">The Haveno network operators can steal 3177 XMR, assuming the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg0tucq6q9sfg98cxjdsuje02az06jhjg8zqlhv7207wck56fahggzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cqr8m74" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyt2a0ywvyactz7hekpxhd3neyt5ngddq35yw0x30m9mxqqw2xwlgpzamhxue69uhky6t5vdhkjmn9wgh8xmmrd9skctcf6e8lv&#39;&gt;nevent1q…e8lv&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The Haveno network operators can steal 3177 XMR, assuming the investment stays safe and comes back to the taker bots. Once the investment returns, the same taker bot can just do the same thing again. In theory, one taker bot with an amount of XMR equal to the highest maker security deposit could clear out the entire order book since its balance goes up with every completed trade. So, it’s really just a matter of time before the whole order book is wiped out. Even worse, if you’ve got multiple taker and arbiter bots working simultaneously, you could clear the whole order book in just a second. All you need.&lt;br/&gt;&lt;br/&gt;The reason is that a shady arbiter bot backs the taker bot and will side with them in any disputes. Moreover, the arbiter bot can also hit all the market makers with penalties, taking away their 15% security deposits.&lt;br/&gt;&lt;br/&gt;You don&amp;#39;t really need to invest a lot to liquidate the entire order book and my examples are not necessary (unless you want to clear the order book in the first round) as the balance of each taker bot demonstrates substantial, logarithmic growth following each transaction. This is because taker bots always go for the highest maker offer in the pot first.&lt;br/&gt;&lt;br/&gt;#haveno #monero #rugpull #scam #hacking #opsec #xmr #retoswap #havenoreto #openmonero #exitscam&lt;br/&gt;
    </content>
    <updated>2025-03-01T15:54:11&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswlneww0vkhase9xgl2uu4t4sddq9vwv0pku8k6et23npnc8ytvugzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5csqhhg6</id>
    
      <title type="html">If the openmonero website goes down, the damage would be minimal. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswlneww0vkhase9xgl2uu4t4sddq9vwv0pku8k6et23npnc8ytvugzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5csqhhg6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszenx83veu8kzly6y4tmpvczlpzpgwgylhwqvu42ltpqa5xw0krkqpzpmhxue69uhk2tnwdaejumr0dshsqt589c&#39;&gt;nevent1q…589c&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;If the openmonero website goes down, the damage would be minimal. On the other hand, if the Haveno arbiter bots go rogue, they could rug pull at least 3177 XMR &#43; 15% security deposits of all market makers. The difference is that openmonero&amp;#39;s offers aren’t pre-funded, so there’s not much to steal.&lt;br/&gt;&lt;br/&gt;#haveno #monero #rugpull #scam #hacking #opsec #xmr #retoswap #havenoreto #openmonero #exitscam&lt;br/&gt;&lt;br/&gt;
    </content>
    <updated>2025-03-01T15:29:35&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg8rutmxvt7e6xexzhsqqqfwa4dsspffv8a3fcy3qz4y3utlsa8fqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c68qt7x</id>
    
      <title type="html">That exactly how openmonero works; Quote from the interview ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg8rutmxvt7e6xexzhsqqqfwa4dsspffv8a3fcy3qz4y3utlsa8fqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c68qt7x" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszsdz52xy6a3ef6xekf7yyuqx8yxr8l9n30u2u2resr595k4mdvdspzamhxue69uhky6t5vdhkjmn9wgh8xmmrd9skctc2mgmgj&#39;&gt;nevent1q…gmgj&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;That exactly how openmonero works; Quote from the interview recorded on simplifiedprivacy&lt;br/&gt;&lt;br/&gt;The minimum requirement of 0.35 XMR security deposit for sellers on OpenMonero is there to help cut down on spam offers. While it’s not really meant to fund an offer, you can still use it for that (or just fund the difference) as long as the buyer’s trade request is no more than the security deposit.&lt;br/&gt;&lt;br/&gt;Both the seller and the buyer can cancel a trade request if they feel like the other person isn&amp;#39;t trustworthy since no xmr is locked at this early stage. Right now, the seller is chatting with the buyer and checking out their reputation, looking at things like how long they&amp;#39;ve been registered and what kind of feedback they&amp;#39;ve received. Should all evaluations meet satisfactory criteria, the seller has the option to secure an arbitration bond utilizing either an internal wallet (security deposit) or an external wallet (such as Cakewallet, Moneroju, Feather Wallet, Monero CLI Wallet, etc.)&lt;br/&gt;&lt;br/&gt;For big trades, the seller might choose to fund the bond from a separate external wallet to avoid any potential scams from the arbitrator right from the start. On the other hand, for smaller trades, its usually easier for the seller to just use the internal wallet (security deposit) for the bond. By allowing both types of wallets for funding, the platform strikes a good balance between keeping things liquid and secure.&lt;br/&gt;&lt;br/&gt;If there weren’t an option for external bond funding, there&amp;#39;s a chance that an arbitrator could run off with all the money. But because funding is done manually, it really cuts down the risk of good exit scams or bots locking up coins.&lt;br/&gt;&lt;br/&gt; #haveno #monero #rugpull #scam #hacking #opsec #xmr #retoswap #havenoreto #openmonero #exitscam
    </content>
    <updated>2025-03-01T14:58:43&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvdwslrt7a7jlkn0n0yvevzg6g8668wxs0c48c8ktugj2rqh5g45szyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c7mht46</id>
    
      <title type="html">Nothing would stop the Haveno network operators from making ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvdwslrt7a7jlkn0n0yvevzg6g8668wxs0c48c8ktugj2rqh5g45szyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c7mht46" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9yj5pz0t0kxnplraulhlsszvrrapxv6td0em2dk288ju4kh3na0spzpmhxue69uhk2tnwdaejumr0dshsujlxu2&#39;&gt;nevent1q…lxu2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Nothing would stop the Haveno network operators from making automated fake orders if the money pool gets big enough. The Haveno pot gets bigger with each new offer, while more offers on OpenMonero don’t necessarily mean more XMR in the pot since vendors only need to put down a security deposit of 0.35 XMR to list as many offers as they want. So, you could see 1,000 offers from different vendors on OpenMonero, but the admin might only hold 350 XMR (1,000 offers x 0.35xmr) in custody because of how self-custodial trade funding works.&lt;br/&gt;&lt;br/&gt;It’s also worth mentioning that a decent exit scam usually needs to involve at least 1 million dollars; no one’s going to pull an exit scam for just 80k (1,000 offers x 0.35 XMR x 231 USD). OpenMonero was redesigned in Nov 2024 to help prevent exit scams from happening in the first place.&lt;br/&gt;&lt;br/&gt;#haveno #monero #rugpull #scam #hacking #opsec #xmr #retoswap&lt;br/&gt;&lt;br/&gt;Reference: &lt;a href=&#34;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/&#34;&gt;https://rl.bloat.cat/r/Monero/comments/1h4icot/is_haveno_anymore_secure_than_trading_with_a/&lt;/a&gt;
    </content>
    <updated>2025-03-01T14:37:25&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspf88vdsqwkxv6wmdt4y4d675q79vyrk75ldvcuu0y8x3uxdr59pczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cm4lhy2</id>
    
      <title type="html">Its hosted on forgeo on a tor hidden service. Go to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspf88vdsqwkxv6wmdt4y4d675q79vyrk75ldvcuu0y8x3uxdr59pczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cm4lhy2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrjy4p30994ehgjgaauvdxn8x5k96j5dz8c5j4kny5f2ffetkqsvqpzamhxue69uhhyetvv9ujuurjd9kkzmpwdejhgtcs25fzn&#39;&gt;nevent1q…5fzn&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Its hosted on forgeo on a tor hidden service. Go to openmonero.com and click the &amp;#34;Open source code&amp;#34; attribute inside &amp;#34;Why use our service&amp;#34;
    </content>
    <updated>2025-03-01T12:23:57&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8lk9zua3hqtw6j2ls0as58rq8etmdhj6xy3awqd95g6d46ny5wdczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c0qmhw7</id>
    
      <title type="html">Thank you for adding openmonero.com to the list. 🤙</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8lk9zua3hqtw6j2ls0as58rq8etmdhj6xy3awqd95g6d46ny5wdczyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5c0qmhw7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdcl3vmc6ty8vvy30jxpux6j5anum7wdnjeyryq2hnn2rzake6a2gppemhxue69uhkummn9ekx7mp0f8sx53&#39;&gt;nevent1q…sx53&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Thank you for adding openmonero.com to the list. 🤙
    </content>
    <updated>2025-03-01T12:14:29&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsq2pcudt9rdq4wwpk7r784fwr5h0lt4fhzj6cvaeckurla6wg29dqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cxhr7a4</id>
    
      <title type="html">Hello Nostr! I&amp;#39;m the dev behind OpenMonero.com This is my ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsq2pcudt9rdq4wwpk7r784fwr5h0lt4fhzj6cvaeckurla6wg29dqzyzy5cc0aghecfhdvjjzvjtr6qs952zv9rug2awclta44yrmj5vs5cxhr7a4" />
    <content type="html">
      Hello Nostr!  I&amp;#39;m the dev behind OpenMonero.com&lt;br/&gt;&lt;br/&gt;This is my first post. I&amp;#39;m here to bring transparency and harm reduction. Check out my latest audit for haveno: Shady arbiters can steal the entire liquidity from the order book. All you need is just 2 bots. Its crazy.&lt;br/&gt;&lt;a href=&#34;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&#34;&gt;https://simplifiedprivacy.com/openmonero-interview-with-the-dev/compared-to-reto.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Issue confirmed by official monero moderator on dread: &lt;a href=&#34;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-cac5570453f7fa9f42&#34;&gt;http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/4e7e530582ff902b6903/#c-cac5570453f7fa9f42&lt;/a&gt;&lt;br/&gt;Quote from /u/monero_desk_support: After some thoughts, I think you are right and that the arbitration system in Haveno doesn&amp;#39;t prevent arbitrators from pulling the funds. They would need to create a bot that takes all the offers and automatically unlock the funds with the key of the taker and arbitrator&lt;br/&gt;&lt;br/&gt;#introductions #Privacy #Markets #HiddenService #News #Work #Monero #Crypto #Hacking #HarmReduction #Guides
    </content>
    <updated>2025-02-27T15:22:43&#43;01:00</updated>
  </entry>

</feed>