Search

Search for projects by name or address

Privacy

Monero via Cake Wallet logo
Monero via Cake Wallet

This route has no Ethereum contracts. Real-time monitoring is not supported.

About

A round trip from Ethereum into Monero and back through the swap screen of Cake Wallet, which hands each leg to a centralized instant exchange. Monero's ledger serves as the privacy pool.


  • Metrics
    Not trackedData tracking is not available for this project.

  • Trusted setup
  • Exit window
  • Privacy
    Link privacy
  • Reproducibility

  • Tracked on
    Ethereum logo
  • Attributes
    BridgedTransfersAny amount

  • About

    A round trip from Ethereum into Monero and back through the swap screen of Cake Wallet, which hands each leg to a centralized instant exchange. Monero's ledger serves as the privacy pool.

    Monero via Cake Wallet can be abstracted as a privacy pool with Ethereum as its base: a centralized swap service takes Ethereum assets and pays out XMR into Monero. To come back, XMR goes to a swap service that pays out to any Ethereum address. Cake Wallet, a self-custodial multi-currency wallet, holds both wallets and embeds both swaps. No Ethereum contract is involved. The service is a custodian for the duration of each swap.

    Flow

    1. Quote. EVM asset to XMR: the app polls every enabled service and takes the best rate unless the user forces one.
    2. Ethereum to the service. The app sends amount, Monero payout address, the Ethereum wallet address as refund address, and Cake’s API key, for some providers with a markup. The service returns a deposit address it controls. The deposit is a plain, public transfer from the user’s wallet, sent first to the Blink Labs private mempool (on by default), then to the RPC.
    3. Into Monero. The service sends XMR to the payout address. The transaction hides sender, recipient and amount.
    4. Inside Monero. Every spend names 16 earlier outputs, the real one and 15 decoys picked by the wallet. Outputs unlock after ten blocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over..
    5. Back to Ethereum. From the Monero wallet the user picks XMR to the Ethereum asset. The app sends a subaddress not used for a swap before as refund address, and the Ethereum exit address, receives a Monero deposit address from the service and pays it from the Monero wallet. The service pays the Ethereum address from its hot wallet.

    Architecture

    Monero hides which output a transaction spends with ring signatures: each input names 16 outputs and proves that one of them is spent, without saying which. The rings stay public forever. This works against observers who do not know where the coins came from. It fails against anyone who knows one of the outputs, because they only have to look for it in the rings behind a later transaction.

    A privacy pool entry is always such a known output. Here the swap service creates the payout. With an onchain bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. as base, everyone would know it. The exit is known as well: the exit service receives the Monero transaction and sees its rings. So a party holding both legs, or a screening vendor both services use, finds its payout output in the ring of the exit transaction if the XMR is paid straight back, and the payout amount minus the public fee if all of it is paid. Self-transfers in between only widen the search, by about 30 times per transaction. Over the week to block 3,772,293 (September 2026), a service creating one in a hundred Monero outputs is left with about 6 candidates after one self-transfer and about 180 after two, before it uses amounts, timing, IP or Cake’s API key.

    Shielded pools such as Tornado Cash, Privacy Pools or Zcash’s shielded pool prove membership in the whole pool without naming any deposit, so a party that knows a deposit, but not its secret, cannot find the withdrawal onchain.

    Privacy considerations

    Both Ethereum legs are public. The entry service knows everything about its leg: addresses, amounts, IP and Cake as the integrator. The exit service knows the Ethereum exit address, amount and IP.

    ClientSometimes labelled interchangeably as a “node”, they are tasked with processing transactions and managing the blockchains's state. They run the computations for each transaction according to the rollup's virtual machine and protocol rules. If comparing to Ethereum clients, these would be execution clients such as Geth, as opposed to consensus clients. defaults weaken this. An EVM wallet in Cake has one address: it is sent as refund address on entry, and exiting to the same wallet pays the very address that deposited, so entry and exit are publicly linked unless the exit goes to a new in-app wallet from a fresh seed. On entry, picking an in-app Monero wallet pays to its primary address every time. Built-in Tor is off by default, so swap APIs, Blink, Etherscan, the RPC, Cake’s price API and Moralis, which cannot be switched off, see the user’s IP. With Tor on, all calls share one SOCKS port without isolation, so calls within ten minutes can share a circuitA program written for the purpose of being proven within a proving system. A circuit is a mathematical representation of the computation to be executed, arithmetic circuits and zkVM execution trace are examples of circuits. Circuits can be written in different languages, ranging from low-level to high-level., and the Ethereum client only uses Tor after a restart.

    Custody, fees and compliance

    Both legs are transfers to and from custodial exchange-controlled wallets. The centralized swap providers used by Cake can automatically freeze funds while in-flight and hold them for KYC and compliance checks, as documented in their terms of service. Cake ships its API keys, and for some providers a markup, as build secrets, so the fee cannot be verified from source. Cake Labs holds no keys and proxies nothing.

    Anonymity setIn privacy protocols, anonymity set denotes all users, to which a particular withdrawal could be plausibly attributed. Anonymity set depends on a particular withdrawal, the size of the anonymity set is a metric for level of user's privacy.

    Each spend hides among its 16 ring members, and the rings behind them. Against a party that knows the entry output, the effective set is the number of its own payouts in those rings. Against everyone else, entry and exit amounts are public on Ethereum, so the set is the entries that could match an exit in amount and time.

    What the protocol promises: Hides which funds leaving Ethereum come back as which, by passing them through Monero between two custodial swaps. Both Ethereum legs are public.

    On public blockchains like Ethereum, all actions transparent by default. A privacy protocol can at best cut the link between addresses or offer privacy while deposited. The colour says whether a careful user can keep the link, amount or recipient private against that adversary: green yes, yellow only outside supported options or by accepting another leak, red no. Fields marked at risk stay private only under the condition in their note.

    Link private

    Nothing public ties the deposit into a swap service to the later payout from a service hot wallet, because the Monero transactions in between hide sender, recipient and amount. Both Ethereum transfers show address, token and amount.

    Advice: Exit to a new in-app Ethereum wallet created from a fresh seed, never the wallet that deposited.

    InsideSenderprivateRecipientprivateAmountprivateAssetexposedLinkat risk
    Link private

    Only amount and timing can pair the two Ethereum legs: a deposit into a swap service and a payout from a hot wallet that serves every asset the service trades.

    Advice: Withdraw common amounts rather than everything at once. Wait before exiting and pick a different time of day than the deposit. Exit to a fresh address every time and spend from it with a different wallet than the one that deposited.

    Compared with a public observer
    InsideAssetexposedLinkat risk
    Link exposed

    With Tor and own nodes, the two legs stay apart unless they run in the same app/tor session. Cake's Tor has one SOCKS port without isolation, so Moralis, which cannot be switched off, and Blink and Etherscan, if left on, can see both Ethereum wallets on one circuit.

    Advice: Turn on Tor, switch off Blink and Etherscan, set your own Monero node and Ethereum RPC, then restart the app, since the Ethereum client keeps its first connection. Wait and restart it again between the legs.

    Compared with a public observer
    InsideAssetexposedLinkat risk
    Link exposed

    The swap-in service that pays your XMR knows that output, and the service you exit with sees the rings of your Monero transaction. One party holding both finds its output in the rings behind the exit. Each service also holds the addresses, amounts, IP and Cake's API key of its leg, screens them and can hold the funds until KYC.

    Advice: Force different services for entry and exit. Self-transfer the XMR several times, hours to days apart, and never pay the exit service the whole amount.

    Compared with a public observer
    InsideSenderat riskAssetexposedLinkat risk
    Link exposed

    A quantum computer recovers the key of every ring member from the chain alone, recomputes its key image and so finds the real spend of every ring, which turns the XMR's path from payout to exit into a public trail. The services' records of payout and deposit then join the Ethereum legs.

    Compared with a public observer
    InsideSenderexposedRecipientat riskAmountat riskAssetexposedLinkexposed

    Funds can be stolen if

    1. a swap service does not pay out.
    2. a service’s hot wallet is compromised during the trade.

    Funds can be frozen if

    1. a service holds the deposit pending identity verification.
    2. a service refunds minus fees and blacklists the deposit address.

    Privacy can be lost if

    1. one party sees both legs: one service, Trocador or a vendor the services share. It finds its own payout output in the rings behind the exit transaction, and self-transfers in between only widen that search.
    2. the exit is paid to the same Ethereum wallet that deposited, since an EVM wallet in Cake has only one address.
    3. the XMR is swapped back in a matching amount and time.
    4. the same Monero payout address is reused on entry, the default for an in-app receiver.
    5. swap APIs, Blink, Etherscan, Moralis, RPC and Monero nodeA software client that participates in the network. see the same IP. Tor is off by default and not circuitA program written for the purpose of being proven within a proving system. A circuit is a mathematical representation of the computation to be executed, arithmetic circuits and zkVM execution trace are examples of circuits. Circuits can be written in different languages, ranging from low-level to high-level.-isolated.
    6. elliptic-curve cryptography is broken, which reveals the real spend in every ring.

    No onchain governance, no contracts, instant change permissions. Three parties can change the swap routes.

    Cake Labs LLC (the wallet)

    MIT-licensed and self-custodial. Cake runs no swap backend. Privacy defaults, all user-changeable: Tor off, swap mode “Enabled”, Blink on, Etherscan on, Cake’s price API on, Cake’s Monero nodeA software client that participates in the network., publicnode’s Ethereum RPC. Moralis token discovery is always on.

    The swap services (the custodians)

    Fully centralized, custodial and intransparent.

    Monero (the chain)

    Rules change through scheduled hard forks. The mainnet table ends at version 16, active since blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. 2689608 (August 2022) with a ring size of 16.