Monero Atomic Swaps: Trading Without Exchanges

Explore how Monero atomic swaps utilize adaptor signatures and DLEQ proofs to enable trustless, non-custodial XMR-BTC trading without centralized exchanges

On this page

Centralized cryptocurrency exchanges represent the antithesis of privacy-preserving systems. By aggregating sensitive identity data through mandatory Know Your Customer (KYC) regulations and recording custodial interactions, these intermediaries create attractive targets for data breaches, state surveillance, and chain analysis profiling. For users of privacy-focused assets like Monero (XMR), centralized ramps present a critical failure point: the moment an individual interacts with a compliant exchange, the boundary between transparent financial tracking and privacy-preserving zero-knowledge transactions is compromised. Monero atomic swaps eliminate this counterparty risk entirely by enabling cross-chain, trustless exchanges directly between individuals using mathematical guarantees rather than escrow intermediaries.

The Asymmetry Dilemma: Scriptless Privacy vs. Scripting Capabilities

In classical cross-chain atomic swaps (such as between Bitcoin and Litecoin), transactions rely heavily on Hash Time-Locked Contracts (HTLCs). An HTLC enforces conditions on-chain using smart contracting primitives: funds are locked until the recipient reveals a cryptographic preimage s such that H(s) = h, or until a designated block height passes, triggering a refund.

Monero's core architecture, designed for maximum financial fungibility and privacy via Ring Signatures, Stealth Addresses, and Ring Confidential Transactions (RingCT), intentionally lacks an expressive scripting language. The Monero virtual machine does not support arbitrary conditional operations, hash locks, or native contract execution on-chain. Constructing an atomic swap between Monero and Bitcoin thus presents a fundamental cryptographic asymmetry:

  • Bitcoin: Supports expressive scripting (OP_SHA256, OP_EQUALVERIFY, OP_CHECKLOCKTIMEVERIFY, OP_CHECKSIG).
  • Monero: Operates strictly on Edwards-curve digital signature algorithms (Ed25519) within its transaction validation rules, without on-chain conditional hash evaluation.

Because Monero cannot verify a hash preimage on-chain within an HTLC, developers had to bypass traditional HTLC mechanisms entirely. The solution relies on advanced off-chain cryptography: cross-group discrete logarithm equality (DLEQ) proofs and adaptor signatures.

The Cryptographic Foundation: Adaptor Signatures and DLEQ Proofs

The modern Monero-Bitcoin atomic swap protocol—originally formalized by Joël Gugger (h4sh3d) and implemented by teams like COMIT and the Farcaster Project—utilizes Scriptless Scripts. This approach pushes the conditional logic of the swap off-chain into the cryptographic signature generation process itself.

Cross-Group Discrete Logarithm Equivalence (DLEQ)

Bitcoin operates natively over the secp256k1 elliptic curve, while Monero relies on Curve25519/Ed25519. To link actions between the two completely distinct networks without a bridge, the swap protocol must verify that a secret scalar s used to conceal a key on Bitcoin is mathematically identical to the secret scalar s used on Monero, without revealing s prematurely.

Let $G_{btc}$ be the base point on secp256k1 and $G_{xmr}$ be the base point on Ed25519. The protocol relies on a zero-knowledge proof showing:

P_{btc} = s * G_{btc}
P_{xmr} = s * G_{xmr}

This DLEQ proof proves that the discrete logarithm of $P_{btc}$ with respect to $G_{btc}$ is equal to the discrete logarithm of $P_{xmr}$ with respect to $G_{xmr}$, without exposing the scalar $s$. This proof guarantees atomicity: if one party learns the secret scalar necessary to claim funds on one chain, the other party simultaneously gains the exact cryptographic material needed to unlock the funds on the second chain.

Adaptor Signatures

An adaptor signature acts as an encrypted or "half" signature. Given an elliptic curve public key (statement) $Y = y * G$, an adaptor signature can be combined with the secret $y$ (witness) to yield a valid digital signature. Conversely, seeing both the completed valid signature and the adaptor signature allows an observer to extract the secret scalar $y$. This mechanism effectively binds the publication of a transaction on the Bitcoin blockchain to the automatic decryption of Monero spending keys.

Anatomy of an XMR-BTC Atomic Swap

To understand the mechanics, consider a swap where Alice holds Monero (XMR) and wishes to trade with Bob, who holds Bitcoin (BTC). The protocol proceeds across distinct phases, guaranteeing that neither party can steal funds, regardless of network dropouts or adversarial behavior.

  1. Key Exchange and Setup: Alice and Bob generate ephemeral key pairs on both the secp256k1 and Ed25519 curves. Bob creates an adaptor signature that commits to spending a Bitcoin output, conditional upon Alice revealing a private scalar. Alice and Bob mutually construct a 2-of-2 shared Monero address, splitting both the view key and the spend key such that:
    Spend_Key_Total = (Spend_Alice + Spend_Bob) mod l
  2. Locking Monero: Alice broadcasts a transaction on the Monero blockchain, depositing the agreed-upon XMR into the distributed 2-of-2 multisignature address. Because Alice controls only her half of the private spend key (Spend_Alice) and Bob controls only his (Spend_Bob), neither party can move the XMR unilaterally.
  3. Locking Bitcoin: Bob observes the Monero transaction confirm on-chain. Bob then publishes a Bitcoin transaction locking his BTC into an output with two possible spending paths:
    • Path A (Success): Requires a valid signature from Alice and Bob, which Alice can only generate by finalizing Bob's adaptor signature.
    • Path B (Refund): A relative timelock (using OP_CHECKSEQUENCEVERIFY) that returns the BTC to Bob if Alice fails to execute the swap within a defined block window ($T_1$).
  4. Execution and Claim: Alice claims the BTC by spending from Path A. In constructing and broadcasting the valid Bitcoin transaction signature, Alice mathematically reveals the scalar secret $s$.
  5. Monero Settlement: Bob monitors the Bitcoin mempool and blockchain. As soon as Alice's Bitcoin claim transaction is published, Bob extracts the scalar $s$. Bob combines $s$ with his own partial key Spend_Bob, reconstructing Alice's Monero spending share. Bob now possesses the complete private key for the 2-of-2 Monero address and transfers the XMR to a private address under his sole control.
Critical Safety Guarantee: If Alice disappears before locking the Bitcoin, Bob never locks his funds, and Alice uses a predefined refund mechanism. If Bob disappears after Alice locks her Monero, Alice waits for Bob's Bitcoin timelock to expire without executing, triggering a protocol sequence that refunds her Monero using collaborative emergency keys.

Threat Modeling and Operational Security Risks

While the cryptographic guarantees of Monero atomic swaps prevent outright theft under standard execution, several operational and network-level vectors require careful threat modeling.

Timelock Griefing and Asymmetric Stalling

A malicious counterparty can initiate a swap with no intention of completing it, effectively locking the honest participant's capital until the expiration of the timelocks ($T_1$ or $T_2$). Because Monero transactions require mining confirmations before the Bitcoin transaction can be safely published, a staller can force an honest user to wait hours or days for capital return. Implementations mitigate this via client reputation systems, deposit bonds, or randomized order execution, but the underlying risk remains intrinsic to timelocked protocols.

Mempool Congestion and Fee Spikes

The safety of an atomic swap is tightly coupled to the predictable confirmation of transactions before timelocks expire. If the Bitcoin network experiences extreme mempool congestion, Alice's claim transaction might fail to confirm before Bob's refund timelock ($T_1$) activates. If Bob's refund path becomes valid while Alice's claim transaction is still pending unconfirmed, Bob could theoretically confirm his refund, regaining his BTC while still harvesting Alice's secret $s$ to sweep the Monero.

Defensive design requires generous timelock buffers (often 24 to 72 hours), the integration of Replace-By-Fee (RBF, BIP 125), and child-pays-for-parent (CPFP) capabilities within swap software to ensure transactions can be dynamically accelerated under adverse fee environments.

Metadata Leakage and On-Chain Heuristics

While the Monero side of the swap benefits from native stealth addresses and RingCT, the Bitcoin side exposes transaction graphs. The Bitcoin lock script exhibits specific characteristics (P2WSH or Taproot script trees) that chain analysis heuristics can flag as non-standard contracts or atomic swap outputs. Furthermore, static trading volumes (e.g., swapping precisely 0.50000000 BTC for its precise fiat equivalent in XMR) allow surveillance algorithms to correlate transactions across time, linking a transparent Bitcoin identity to the exact moment an off-ramp into Monero occurred.

Implementations: From Theory to Production

The practical execution of Monero atomic swaps has advanced from academic whitepapers to functional implementations deployed across desktop and headless environments:

  • COMIT Network / UnstoppableSwap: An operational protocol and open-source graphical user interface for automated, permissionless XMR-BTC swaps. It uses an automated market maker (maker-taker) architecture where liquidity providers host daemons that publish exchange rates over Tor hidden services.
  • Farcaster Project: A dedicated community initiative developing a robust, modular XMR-BTC atomic swap client written in Rust, focused heavily on minimizing on-chain footprints, protocol resilience, and cross-platform terminal operation.
  • Basic Swap DEX: Developed by Particl, integrating atomic swap capabilities across multiple non-scriptable and scriptable privacy assets using specialized adaptor signature frameworks and secure off-chain order messaging.

The Paradigm Shift for Sovereign Privacy

Monero atomic swaps represent a significant development in self-sovereign financial privacy. By transforming cross-chain interoperability from a custodial vulnerability into a trustless cryptographic proof, atomic swaps neutralize the choke points historically exploited by state surveillance and centralized platforms. When combined with anonymizing routing networks like Tor and I2P, atomic swaps allow researchers, journalists, and privacy-conscious users to move unencumbered between different digital asset ecosystems without yielding custody, identity, or metadata.

Keywords
Monero atomic swapsXMR BTC swapadaptor signaturesDLEQ proofstrustless exchangeMonero privacydecentralized exchangeScriptless Scripts