Coiniversity

Free crypto content for clarity, not hype.

← All articles

September 3, 2026Crypto Drood18 min read

What is Monero (XMR)?

  • Monero (XMR)
  • Privacy Coins

What is Monero (XMR)?


The Cash That Does Not Gossip: Why Monero Exists, and Why XMR Might Matter

Imagine paying for a book with a twenty-dollar bill.

The clerk takes the cash. The publisher never learns your name. Your landlord cannot see the purchase on a public board. The person who handed you that twenty last week cannot follow it into the shop and announce what you bought. The bill works because it is ordinary. One twenty is as good as another. That property has a dry name - fungibility - and it is one of the oldest features of money.

Now imagine the opposite.

Every payment you make is written on a wall that anyone can read. The wall does not print your legal name, but it prints an address that can be tied to you the first time you cash out through a company that asks for a passport. From that moment, a curious stranger - or a company paid to be curious - can walk backward through years of purchases. They can see what you earned, what you gave away, which clinic you paid, which newspaper you supported, which relative you helped. They do not need to hack anything. The wall was designed to be public.

That wall is Bitcoin’s ledger, and most of the coins that copied it. The design is honest, and for some jobs it is exactly right. It is a terrible design if what you wanted was digital cash.

Monero was built for the second job.


A fork born from a swindle

The story does not start with a company or a token sale. It starts with a paper and a mess.

In 2013, an author writing as Nicolas van Saberhagen published CryptoNote, a blueprint for electronic cash that treated Bitcoin’s transparency as a flaw rather than a feature. Bitcoin, the paper argued, fails a basic test of cash: you should not be able to follow a coin from hand to hand. The proposed fix was cryptographic rather than social. Hide the sender among a crowd. Give every payment a fresh one-time address. Do not put amounts in the clear.

The first coin built from that blueprint was called Bytecoin. When it was presented to a wider public, a large share of its supply - on the order of four fifths - already existed, mined in private before most people had heard the name. Dates on the early chain looked doctored. The launch that was supposed to prove CryptoNote honest instead proved that a clever protocol can still be wrapped around a dishonest distribution.

In April 2014 a Bitcointalk user known as thankful_for_today forked the code into something called BitMonero: bit as in Bitcoin, monero as in the Esperanto word for coin. There was no premine this time. Anyone could mine from the first block. Within days the same community that had wanted a clean start decided the founder was making unilateral choices they had not agreed to. They forked him too. The name shortened to Monero. The genesis block is dated April 18, 2014.

Both van Saberhagen and thankful_for_today remain anonymous. That is not a marketing flourish. It is the grain of the project. There was no ICO, no venture round, no company treasury sitting on a pile of coins reserved for insiders. New coins have only ever come from mining. Development is funded later, in public, by people who choose to donate - a Community Crowdfunding System rather than a corporate budget. Riccardo Spagni, better known as fluffypony, became the visible maintainer for a stretch of years and then stepped back. Much of the core team still prefers handles to faces.

The origin is unromantic on purpose. Monero is what you get when a cryptographic idea survives a crooked first implementation and a stubborn second one, and a volunteer crowd decides the idea is still worth running.


What “private by default” actually means

Most so-called privacy coins offer a curtain you can draw if you remember to draw it. Monero does not give you that choice. Every ordinary payment hides three things at once: who sent it, who received it, and how much moved.

Those three jobs use three different tools.

Stealth addresses protect the receiver. You can publish one Monero address on a website the way you might publish a mailing address. Incoming payments do not land on that published string. They land on one-time addresses the sender constructs for that payment alone. An outsider watching the chain sees outputs appearing. They do not see a running tally under your name.

Ring signatures protect the sender. When you spend, your wallet does not point at “this exact coin is mine.” It points at a small crowd of possible coins - today, sixteen outputs, fifteen of them decoys pulled from the chain - and proves that one of them is being spent, without saying which. The assurance here is weaker than the other two layers, and an honest article should say so. A ring of sixteen is plausible deniability, not invisibility. Early Monero used even smaller crowds and sloppy decoy selection. Academic work in 2017 showed that a shocking share of those old transactions could be unraveled after the fact. The protocol tightened the rules, mandated a minimum ring size so nobody could “opt out” into a smaller crowd, and kept raising the floor. The current design is much harder to pick apart with the old tricks. It is still a crowd of sixteen, not the whole history of the chain.

RingCT - Ring Confidential Transactions, switched on in 2017 - hides the amount. The network can still check that no coins were created from nothing, because the cryptography proves the books balance without opening the books. Before RingCT, amounts sat in the clear and gave investigators a second handle on the graph. After it, that handle disappeared for new payments.

Around those three sit quieter defenses. Dandelion++ tries to stop your transaction from announcing itself to the whole network from your IP address on the first hop. Serious users wrap their node in Tor or I2P anyway, because the network layer has always been the soft underbelly: cryptography can hide the payment and still leave a trail of packets. The chain itself is large - on the order of 250 gigabytes for a full copy in early 2026, about 100 if you prune it - which is the cost of writing so much camouflage into every transfer.

The design choice that matters most is not any one of those tools. It is that they are mandatory.

Optional privacy sounds kinder. In practice it splits the money into two castes. Coins that have passed through a transparent address pick up a history. Exchanges and investigators treat that history as a stain. People who want to look respectable avoid the stained coins. The private coins become a ghetto, and the ghetto is small enough to watch. Monero’s wager is the opposite: if every coin looks like every other coin, then “taint” has nothing to stick to. That is what fungibility means when the money is software.

It is also why Monero has no general-purpose smart-contract layer, no decentralized exchange baked into the base chain, no NFT circus. The project chose a narrow job and kept choosing it. Privacy first. Security first. Convenience second. That is not a slogan borrowed for a homepage. It is the reason the software is harder to use than an exchange app, and the reason the coin still exists as itself rather than as a feature flag on somebody else’s chain.


The token, in plain English

XMR is not a work token, a governance chip, or a coupon for a company’s API. It is the money.

There is no maximum supply printed on the door. That sentence alarms people who learned monetary policy from Bitcoin, so it needs unpacking.

From 2014 through May 2022, Monero followed a smoothly declining emission curve. By the end of that main emission, roughly 18.13 million XMR existed. On June 9, 2022, the curve hit a floor and stayed there. Every two-minute block now pays a tail emission of 0.6 XMR - about 432 coins a day, about 158,000 a year. As of early September 2026, a little under 19 million XMR are in circulation. The new coins added each year are less than one percent of the pile, and that percentage shrinks as the pile grows. In a century the inflation rate would still be falling toward zero without ever quite arriving.

Why refuse a hard cap?

Bitcoin’s bet is that after the last coin is mined, transaction fees alone will pay for the computers that defend the ledger. That bet might work. It might also leave a mature network with a thin security budget and a fee market that prices ordinary people out. Monero’s bet is more conservative about human nature and more pessimistic about fee markets. Miners, in this view, should always receive a small, predictable subsidy so that securing the chain does not depend on congestion. The tail is not an accident and not a leak. It is a permanent payroll for the people who keep the clock ticking.

The other half of the monetary design is how those coins are born.

Monero is mined with RandomX, a proof-of-work algorithm the project adopted in 2019 after earlier versions of its mining code attracted specialized chips. RandomX does not ask a machine to repeat one tidy hash. It asks the machine to run random little programs and lean on memory the way a normal computer already does. The point is to make a custom mining chip look less like a clever shortcut and more like an expensive, awkward replica of a CPU. Ordinary processors remain competitive. You can still mine Monero on a desktop in 2026. That does not make the network a cottage industry - large operators and pools exist, and we will come back to them - but it is a different picture from Bitcoin, where the work migrated years ago into warehouses of machines that do only one thing.

Who got the coins at the start? Miners. There was no founder allocation, no investor vest, no lab wallet waiting to unlock. Development does not take a cut of the block reward. When the project needs an audit, a researcher, or a difficult upgrade, someone writes a public proposal and the community funds it or it does not happen. That is a fragile way to build infrastructure. It is also how you avoid creating a class of people whose wealth depends on unlocking a treasury.

What is XMR for, then, besides existing?

You pay network fees in it. You receive it when you sell something, or when your computer finds a block. You can hold it because you want a bearer asset that does not gossip. There is no staking program that turns holders into outsourced security guards. There is no on-chain vote that lets token holders steer the lab. Use is the utility. That sounds too simple until you notice how many tokens are still searching for a reason to be used.


Why this token, among thousands?

Crypto is crowded with coins that borrowed Bitcoin’s ledger and changed the logo. A smaller crowd borrowed Bitcoin’s ledger and added an optional mixing step. A still smaller crowd tried to make privacy a default and then drifted into becoming platforms, complete with apps and governance tokens and a need to explain themselves to the same exchanges that fear privacy in the first place.

Monero’s claim is narrower and, if it holds, harder to copy at the last minute.

Digital systems keep getting better at remembering. Banks remember. Phones remember. Advertising networks remember. Public blockchains remember with a thoroughness that would have sounded like satire a generation ago: a permanent, globally mirrored log of who paid whom. In that world, cash is not a nostalgic habit. It is one of the last ways to buy a thing without also publishing a story about yourself.

Cash, though, is shrinking. Some countries have already made large cash payments awkward or illegal. Cards and apps are convenient, and convenience is how surveillance arrives without kicking down a door. A privately issued stablecoin can be frozen. A bank balance can be assigned. A transparent cryptocurrency can be followed. The remaining question is whether any electronic instrument can still behave like a bill in a pocket.

Monero is the most serious attempt at that instrument that has survived in public for more than a decade. It is not the only privacy design in cryptography. Zero-knowledge proofs have grown up, and other chains use them with real skill. What Monero has that a newly launched shielded pool does not is time, scars, and a user base that was forced to live with mandatory privacy when that choice made the coin harder to list, harder to explain, and easier to smear.

That last point is not incidental. If private digital cash works, it will be used by people you like and people you do not. It will move salaries in places where a public ledger is a targeting system. It will move donations that a government would rather watch. It will also move payment for things the law forbids. Cash already does all of that. The argument for Monero is not that crime vanishes. The argument is that a society which only permits money that can be inspected by default has given up something older than Bitcoin - the possibility of an ordinary, unremarkable payment.

Whether that argument is enough is not a technical question. It is the question the token exists to keep asking.


What can go wrong

It would be dishonest to stop at the wow.

Privacy is a moving target, not a trophy. Ring signatures of size sixteen are better than the early days and worse than a proof that says “this spend is one of every output that has ever existed.” Researchers have been building that next step under the name FCMP++ - full-chain membership proofs. In 2026 the work is on public test networks and in audits. It is not yet the live chain. Until it is, the old statistical games still have a smaller playing field to work with, and old coins from sloppier eras still sit in the history. Network-level observation - watching who talks to whom, running hostile remote nodes, correlating timing - can leak what the cryptography hid. A user who treats Monero like a magic cloak and then logs into a KYC exchange has not been failed by the math. They have been failed by the rest of their life.

The chain is useful to people the state would rather catch. That fact is not a rumor invented by critics. After Bitcoin payments became easier to follow, darknet markets and ransomware crews moved a slice of their traffic toward Monero. Law-enforcement agencies noticed. Exchanges noticed. The political result has been a steady exile from regulated platforms. Binance removed XMR. Kraken removed it for European customers. Japan and South Korea pushed privacy coins off licensed venues years earlier. Across 2024 and 2025, delistings piled up by the dozens. The European Union’s anti-money-laundering rulebook goes further still: from July 10, 2027, licensed crypto firms in the bloc are not supposed to service anonymity-enhancing coins. Owning Monero is not, in most of those jurisdictions, a crime. Buying it through a polite app with a help desk increasingly is not an option. A money that cannot touch the regulated on-ramps has to live on peer-to-peer rails, or it becomes a collectible.

Proof of work can still centralize. RandomX makes specialized chips less attractive. It does not make large miners impossible. In the summer of 2025 a project called Qubic redirected serious hashpower at Monero and claimed, in public, to have crossed a majority of the network. The precise percentages were disputed. The discomfort was not. A pool that large can orphan blocks, delay confirmation, or simply terrify holders. Qubic later pointed its machines at other work, including Dogecoin, and the immediate fever broke. The lesson did not: ASIC resistance is not the same thing as attack resistance, and a privacy coin with a modest security budget is a tempting arena for anyone who wants a headline.

The cryptography is not ready for a large quantum computer. Monero’s signatures, addresses, and commitments rest on elliptic curves. A machine that can run Shor’s algorithm against those curves would not only forge future spends. It could look backward. Privacy coins have a special version of this nightmare, sometimes called harvest-now-decrypt-later: copy the chain today, wait, and open it when the math allows. The research community around Monero knows this. Knowledge is not a migration. There is no deployed post-quantum shield, and a replacement would be a hard fork of unusual difficulty because the whole point of the system is that old outputs must remain spendable without being unmasked.

The project is built like a commons. That is the charm and the risk. There is no firm with a war chest mandated to finish FCMP++, pay for the next audit, or staff a quantum transition. Meetings are public. Funding is voluntary. Progress has been real and often slow. A commons can outlast a company. It can also stall while the world that wants to ban it does not stall.

You cannot audit the supply the way you audit Bitcoin. The emission formula is public, and independent sites reconstruct issued supply block by block. What you cannot do is look at every output and add up the amounts, because the amounts are hidden. The cryptography is supposed to make hidden inflation impossible. If that cryptography were wrong in a subtle way, the failure might not advertise itself. That is the tax you pay for confidential amounts. Most users will never think about it. The people who think about it professionally never stop.

None of these are secret. They are the price of trying to build cash after cash became a problem for institutions.


What would have to go right

Monero is easy to misunderstand because the best version of it looks like nothing happening.

A payment lands. Nobody writes an essay about the pipes. The receiver does not learn the sender’s whole life. The sender does not learn whether the receiver already had money. A third party with a copy of the chain learns that a transaction occurred and little else. That is a small miracle by the standards of the last twenty years of consumer technology, and it is supposed to feel boring.

For XMR itself to remain more than a relic of an earlier internet, a few things have to keep lining up.

The next privacy step has to ship. Full-chain membership proofs would take the sender’s crowd from sixteen decoys to the entire history of outputs - on the order of a hundred million, and growing. That would not silence every critic and would not fix the network layer, but it would retire a class of attacks that has hung over ring signatures since the beginning. Peer-to-peer ways of buying and selling XMR have to keep working as regulated exchanges step back, because a cash that cannot be acquired except through a surveillance on-ramp is cash in name only. Mining has to stay ugly enough that no single operator treats the chain as a stage. The quantum work has to become a plan with dates, not only a research interest. And enough ordinary people - journalists in hard places, workers who do not want their pay searchable, families who think a purchase is none of a stranger’s business - have to keep wanting a bill that does not gossip.

That is a narrow road. It is also a more interesting one than most of the tokens that will be launched this year.

The distinctive claim is not that Monero invented cryptography, or that XMR is scarce in the way Bitcoin is scarce. The distinctive claim is that money which remembers everything is a new kind of power, and that someone had to keep an electronic alternative alive after the first attempts at that alternative were captured, premine-stained, or watered down into optional modes. Monero took that job when it was still a forum argument. It is still doing that job, under regulatory weather that would have killed a less stubborn project, with an upgrade on the testnets that would make the old crowd of decoys look quaint.

Whether the coin remains usable when the polite doors close, or becomes a museum piece that only specialists can move, is the open question. The cash is real. The gossip is optional. The world that would prefer the gossip is not optional at all.

That is not a prophecy. It is a design, under load, in public.

Continue learning

Related articles you may find useful.

  • Sep 11, 2026

    Privacy Coins - The Right to Pay Without an Audience

    Privacy coins are not trying to make crime easier, they are trying to restore a property money already had for centuries - the ability to spend without inviting the neighborhood to watch.

  • Sep 1, 2026

    What is ZCash (ZEC)?

    Zcash was built to keep Bitcoin’s scarcity and settlement rules while giving users a way to move value without publishing the details.

  • Sep 5, 2026

    What is Hyperliquid (HYPE)?

    Imagine an exchange whose rules run in the open, and whose history is a chain that anyone can inspect.

Coiniversity

Free crypto content for clarity, not hype.

© 2026 Coiniversity