2

Someone's Monero address can still be linked if one was to use it for a withdrawal from an exchange and then reuse it again. I like how the mimblewimble address works, where addresses are generated on the spot. Is there something in the works for Monero to have only on the spot addresses?

jtgrassie
  • 19,601
  • 4
  • 17
  • 54
Patoshi パトシ
  • 4,608
  • 4
  • 27
  • 69

2 Answers2

1

Someone's Monero address can still be linked if one was to use it for a withdrawal from an exchange and then reuse it again.

No. Monero uses stealth addresses for the outputs. Therefore sending from an exchange to your wallet, the exchange knows the address it sent to, but the outputs in that tx are one-time stealth addresses. When you spend those one-time outputs, they are mixed in a ring of decoys for which an observer has no way of knowing which output is then being spent. At no point does your wallet address ever appear on the blockchain.

jtgrassie
  • 19,601
  • 4
  • 17
  • 54
0

Your concern was the very motivation for subaddresses, which is a technique that generates unique (slightly modified) stealth addresses for handing out to different parties, thus preventing off-chain linkability while keeping scanning times constant. See also this SE question and initial github discussion.

user141
  • 3,337
  • 14
  • 34