Promotion & Adoption Started Aug 11, 2026 6:20 PM

CMV: XMR + view-keys = ZEC

38 replies - 745 views - 1 thanks - 0 tippers - 9 watchers

Aug 11, 2026 6:20 PM
#1
zec zcash view-key view-keys carrot

Monero with optional privacy (frame it as optional transparency, if you prefer) is just zcash.

The reason that Monero works as a privacy coin while zcash fails is that zcash made deliberate design decisions that erode fungibility between "private" and "transparent" coins. Monero, with view-keys, is making that same decision, just without the deliberation.

Addendum: Suggestions for coins with mandatory privacy?

1 thanks - 0 tippers - 9 watchers

Replies

Page 4 of 4 - 38 total
Aug 18, 2026 7:47 PM
#32

It changes because if you have posess enough view-keys, you lose the fungible anonymity that Monero has. Right now, there is no way to know how much money you have in your wallet (you can provide some information, you cannot provide a view-key that the viewer is able to monitor the way carrot view-keys are monitorable). If you have 100% of the carrot view keys, you obviously know exactly who has what, and you also can see who sent and recieved what (perfect transaction information). But even with only a simple majority of view keys, it allows you to track most transactions and see who is paying who, if you're willing to dig into the data, examine timings, do statistical analysis, etc.

The reality is that the majority of users will go along with whatever the path of least resistance is. Most users are speculators, not idealogues. So the inevitability is that those speculators will reveal their view-keys in order to transact legally, and once enough view-keys are collected, you can separate XMR tokens into monitorable (transparent) and dirty (private). The speculators will no longer accept the dirty tokens from the idealogues because thir bank / CEX won't take them, and they don't care about privacy. The idealogues will retain their anonymity, but their tokens will be unusable with the majority of users.

0 thanks - 0 tippers
Aug 18, 2026 8:34 PM Edited Aug 18, 2026 8:35 PM
#33

@jeffro256
Listen I accept OVK as inevitable and not a threat to the value of monero.

Firstly, your initial point about all cryptographic secrets providing at best optional privacy is flawed.
At the moment for a wallet to be fully auditable in real time requires the auditor to hold private spend keys.
Giving up these keys is giving up custody of your funds; you grant the ability for an exchange to permanently deprive you of your moneroj. So users are strong incentived to never give out these keys.
In comparison, giving out OVK might reasonably be in the user's best interest if a CEX provides sufficient incentives for them to do so (liquidity/ discounts).

Secondly, you made a point that a CEX running a pool of transparent/ compliant wallets using IVK could prevent funds being smuggled in by demanding key images. Actually I think you are right, but they would have to require users to provide a key image for every transaction, which might be (slightly) harder to incentivise.

Over time I am seeing this as less and less of an issue. There was once a time that it kept me up at night! (what a fucking nerd) Its more nuanced than most people make it out to be.

Signature

You are the only light

chat: ezchat.site
evoverse: evoverse.onrender.com
postcode premium: https://pub-6199d7cd0f754c4f8987b0455ceb6161.r2.dev/index.html
github: moonboy420

0 thanks - 0 tippers
Aug 18, 2026 10:14 PM
#34

Right now, there is no way to know how much money you have in your wallet (you can provide some information, you cannot provide a view-key that the viewer is able to monitor the way carrot view-keys are monitorable

This is patently false. Do you know what a key-image proof is? It proves the association between a key image and a one-time address. They are used in hot/cold wallet interactions. The simplest form is a ring signature with 1 ring member: the true spend. IVKs + key-image proofs today have the same effect as OVKs.

If you have 100% of the carrot view keys, you obviously know exactly who has what, and you also can see who sent and recieved what (perfect transaction information).

Same thing with IVKs. If I have 100% of users' IVKs, I can trace all funds in perpetuity by linking txs together by their outputs, no OVKs needed. No cryptographic system is safe from an adversary have 100% knowledge of all secrets of all users lol.

So the inevitability is that those speculators will reveal their view-keys in order to transact legally, and once enough view-keys are collected, you can separate XMR tokens into monitorable (transparent) and dirty (private). The speculators will no longer accept the dirty tokens from the idealogues because thir bank / CEX won't take them, and they don't care about privacy.

Again, maybe this booeyman scenario happens, maybe it doesn't. But OVKs don't materially change the scenario. Same scenario could happen without OVKs.

The idealogues will retain their anonymity, but their tokens will be unusable with the majority of users.

If you make literally any stand for any cause in life, you will receive pushback from somebody. No action that causes good in the world comes without some cost. We shouldn't limit the features of the protocols we use simply because some people won't do it 100% right.

1 thanks - Stylus1063 - 0 tippers
Aug 18, 2026 10:26 PM
#35

At the moment for a wallet to be fully auditable in real time requires the auditor to hold private spend keys.

Wrong. See above.

In comparison, giving out OVK might reasonably be in the user's best interest if a CEX provides sufficient incentives for them to do so (liquidity/ discounts).

CEX's may also require government names, license numbers, phone numbers, geolocation, facial photos, fingerprint scans, virgin sacrifices, etc. Making terrible OPSEC decisions should be out of scope of the Monero protocol, and should not enforce a ceiling on users who don't do those things.

Here's the point that I am trying to make: people who are trying to make OVKs, an optional feature that doesn't apply to their wallet if they don't choose to generate a new wallet with OVKs, a boogymean/blocker for FCMP++/Carrot, are shooting themselves and their friend in the face to prevent their friend from stepping on a Lego.

0 thanks - 0 tippers
Aug 18, 2026 11:15 PM
#36

@jeffro256
Do you understand that key image proofs + proof of reserves can demonstrate the balance of a wallet but cannot guarentee that that balance was not spent on the following block?

On another note you seem to misunderstand the argument that optional privacy is harmful to everybody, not just those who give up their keys. Whereas I don't think that this argument is right, its not as trivial as you seem to think.

Signature

You are the only light

chat: ezchat.site
evoverse: evoverse.onrender.com
postcode premium: https://pub-6199d7cd0f754c4f8987b0455ceb6161.r2.dev/index.html
github: moonboy420

0 thanks - 0 tippers
Aug 18, 2026 11:41 PM
#37

Do you understand that key image proofs + proof of reserves can demonstrate the balance of a wallet but cannot guarentee that that balance was not spent on the following block?

  1. An IVK holder can see with 100% certainty when you are witholding key images from them. So they don't need an update every block, only when you receive XMR and/or send change to yourself. In this scenario where a user willingly gives up info upon request, the adversary knows exactly which information to request. You can't hide the fact that you're hiding information from them. For a compliant user who for some reason refuses to make a new wallet, is this not nearly identical levels of coercion?
  2. Software can be written trivially to share key image proofs with third parties in "real time". A user can be coerced into downloading this software one time. This is the same level of information as OVKs.
  3. In both scenarios (with and without OVKs), a user who now desires that third parties "cannot guarentee that that balance was not spent on the following block" can make a new wallet.

With some technical knowledge, and a bit of imagination, one can posit any number of schemes where people willingly dox themselves without OVKs, at different levels of UX.

1 thanks - Stylus1063 - 0 tippers
Aug 18, 2026 11:44 PM
#38

On another note you seem to misunderstand the argument that optional privacy is harmful to everybody, not just those who give up their keys.

At a technical level, this checks out with ring signatures, because optional privacy ruins your decoy health. It doesn't matter with FCMPs, since your anonymity set remains 100% of the "pool" of outputs which didn't dox themselves. If 50% of people publish their OVKs, with FCMPs, at worst your anonymity is as if those people didn't use Monero.

1 thanks - Stylus1063 - 0 tippers
Aug 19, 2026 1:14 AM Edited Aug 19, 2026 1:16 AM
#39

@jeffro256
re your first comment above:
I completely agree and thankyou for enlightening me because I didn't know that 'An IVK holder can see with 100% certainty when you are withholding key images from them'. I suppose I should brush up on 0 to Monero and stop relying on deepseek lol. Still though, the CEX might need users to use their proprietary reporting software, which is more likely to alienate them than just asking for an OVK key. Whereas I maintain that OVK keys might be a real change to the space, you've shown that its less of a change than I thought.

re the second one:
Its one problem that it decreases the anonymity set of all utxos, which might be more problematic for bigger transactions. But another problem is that it threatens fungibility, which is supposed to be one of monero's selling points as a monetary standard. Personally I think this is unrealistic because the markets are driven by demand for private transactions anyway so there is unlikely to be a premium on 'clean' coins even if they were distinguishable.

Signature

You are the only light

chat: ezchat.site
evoverse: evoverse.onrender.com
postcode premium: https://pub-6199d7cd0f754c4f8987b0455ceb6161.r2.dev/index.html
github: moonboy420

0 thanks - 0 tippers

Post A Reply

You must be logged in to reply. Login or register.