How Monero Privacy Works — And Where It Doesn't
You'll hear "Monero is private" everywhere, usually with no explanation. This page explains what that actually means: what the coin hides, how it does it, and what it can't hide no matter how well it's built.
Start With What a Normal Blockchain Shows
Bitcoin is the easy comparison. Every transaction sits on a public ledger forever. Anyone can see which address sent money, which address received it, and exactly how much. Addresses don't have names on them, but they don't need to. Once one address gets tied to a real person, say through an exchange account, you can follow the money in both directions. Whole companies exist to do that tracing at scale by grouping addresses that seem to belong to the same owner.
So "pseudonymous" is the honest word for Bitcoin. It's not anonymous, it's just not labeled. Monero was built to remove that trail at the protocol level.
Three Things Monero Hides
A payment has three pieces of information: who sent it, who received it, and how much. Monero uses a separate tool for each one. The Monero project's own glossary is the best place to check the official definitions.
Who sent it: ring signatures
When you spend, your transaction doesn't point at one single coin you own. It points at a group, made up of your real coin plus a set of other coins pulled from the blockchain as decoys. The signature proves that one of them is genuinely yours, without saying which. An outside observer sees a ring of possible senders and can't tell who among them actually sent it. Today the ring holds 16 members.
Who received it: stealth addresses
The address you give someone to pay you is never written to the blockchain. For each payment, the sender creates a fresh one-time address that only the recipient can recognize as theirs. Two payments to the same person look like payments to two unrelated strangers. That kills the address-clustering trick from the Bitcoin example.
How much: RingCT
Amounts are hidden too. The network still needs to be sure nobody creates money out of thin air, and it does that with math that checks the books balance without revealing the numbers. Hidden amounts have been required on the network since 2017.
What Monero Can't Do For You
This is the part the slogans skip. The protocol protects what's on the blockchain. It doesn't protect everything around it.
Your network connection
When your wallet sends a transaction, that message travels through the internet, and your IP address can be seen along the way. Monero includes a technique called Dandelion++ that makes it harder to tell where a transaction started, but it isn't a replacement for hiding your connection. Wallets can also route through Tor or I2P. That's a separate layer with a separate job.
What you do with it
Reusing the same identifying details, moving funds in a very recognizable pattern, or cashing out at the same moment you cashed in can all connect the dots without touching the cryptography. Timing tells stories too.
The edges of the system
Money has to come in from somewhere and go out to somewhere. Every time it crosses over to another currency or to a service that knows who you are, that point can be recorded. Privacy inside the chain doesn't erase what's known on the outside of it.
View Keys: Showing Only What You Choose
Monero wallets have a "view key" that lets someone see incoming payments to a wallet without being able to spend anything. It's a way to show a specific person, like an accountant or an auditor, exactly what you want them to see and nothing more. It's a deliberate middle ground between total secrecy and total transparency, and it means "private" doesn't have to mean "impossible to prove anything."
It Hasn't Always Been Airtight
Early versions of Monero let people use very small rings, even a single decoy or none at all. Researchers looked at the older chain history and showed that a chunk of those early transactions could be traced back with decent confidence. Later versions made rings mandatory, then larger, and tightened how decoys get picked so that fresh coins aren't easy to spot. The lesson is fair to state plainly: the design improves over time, and older transactions don't get retroactively fixed.
Work continues. A proposal called FCMP++ aims to replace today's rings with a much larger pool of possible senders, but at the time of writing it's still in development, so check the Monero research lab and current release notes rather than trusting any single article, this one included, for what's live.
Two Different Jobs: Payment Privacy and Network Privacy
People often mix up the coin and the network. Monero protects what the payment reveals. Tor protects who is connecting to whom. One does nothing for the other: a private payment sent from a traceable connection leaks one way, and a hidden connection sending traceable coins leaks the other way. That's why the two show up together so often in this corner of the internet. They're not the same tool, they cover different gaps.
For another example of separate layers doing separate jobs, see why PGP matters on Tor.