A Holistic Security Analysis of Monero Transactions
Cas Cremers, Julian Loss, Benedikt Wagner
Abstract
Monero is a popular cryptocurrency with strong privacy guarantees for users’ transactions. At the heart of Monero’s privacy claims lies a complex transaction system called RingCT, which combines several building blocks such as linkable ring signatures, homomorphic commitments, and range proofs, in a unique fashion. In this work, we provide the first rigorous security analysis for RingCT (as given in Zero to Monero, v2.0.0, 2020) in its entirety. This is in contrast to prior works that only provided security arguments for parts of RingCT.
To analyze Monero’s transaction system, we introduce the first holistic security model for RingCT. We then prove the security of RingCT in our model. Our framework is modular: it allows to view RingCT as a combination of various different sub-protocols. Our modular approach has the benefit that these components can be easily updated in future versions of RingCT, with only minor modifications to our analysis.
At a technical level, we split our analysis in two parts. First, we identify which security notions for building blocks are needed to imply security for the whole system. Interestingly, we observe that existing and well-established notions (e.g., for the linkable ring signature) are insufficient. Second, we analyze all building blocks as implemented in Monero and prove that they satisfy our new notions. Here, we leverage the algebraic group model to overcome subtle problems in the analysis of the linkable ring signature component. As another technical highlight, we show that our security goals can be mapped to a suitable graph problem, which allows us to take advantage of the theory of network flows in our analysis. This new approach is also useful for proving security of other cryptocurrencies.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get f2f2c078-4464-41b3-ba18-0ca56616d6d9Cited by top-tier papers1
Ask how each one uses itRelated papers
- Omniring: Scaling Private Payments Without Trusted SetupRussell W. F. Lai, Viktoria Ronge, Tim Ruffing, Dominique Schröder et al.CCS 2019 · 1 citation
- MatRiCT+: More Efficient Post-Quantum Private Blockchain PaymentsMuhammed F. Esgin, Ron Steinfeld, Raymond K. ZhaoS&P 2022 · 59 citations
- BulletCT: Towards More Scalable Ring Confidential Transactions With Transparent SetupNan Wang, Qianhui Wang, Dongxi Liu, Muhammed F. Esgin et al.USENIX Security 2025
- Leaking Arbitrarily Many Secrets: Any-out-of-Many Proofs and Applications to RingCT ProtocolsTianyu Zheng, Shang Gao, Yubo Song, Bin XiaoS&P 2023
- SMILE: Set Membership from Ideal Lattices with Applications to Ring Signatures and Confidential TransactionsVadim Lyubashevsky, Ngoc Khanh Nguyen, Gregor SeilerCRYPTO 2021 · 49 citations
