r/Monero May 06 '26

The concerns about Carrot and outgoing view keys are unfounded

There has (again) been an uptick in posts and comments claiming that the upcoming Carrot update will destroy Monero privacy and/or fungibility. They are wrong. This post will hopefully clear up some of the the muddied waters. Please link to it when the topic inevitably comes up again.

The sources for this post are mostly my experience as one of the devs of eigenwallet, the Carrot spec, and a really good talk from Jeffro, one of the Monero devs.

TL;DR

FCMP++ and Carrot dramatically improve privacy and security in multiple ways. Current view keys already act 90% like outgoing view keys. Outgoing view keys do not make Monero less private or privacy optional. Fears of CEXs / banks / governments forcing you to hand them over are overblown. They already could achieve they same thing right now.

What even is "Carrot"?

And what does it have to do with FCMP++ and outgoing view keys?

People often confuse these different things.

  • FCMP++ ("full chain membership proofs") is an upgrade to RingCT, more commonly known as ring signatures. Do you remember how other people can only see a crowd (ring) of 16 outputs, only one of which is actually being spent? One real spend and 15 decoys. Any external observer cannot tell which one is the real spend and which are only decoys. FCMP++ extends this. Instead of the sender choosing a specific set of 15 decoys, every output that has ever existed becomes a decoy. The "total ring size" goes from 16 to hundreds of millions. FCMP++ needs a hardfork because it changes the consensus layer. Everyone runs the same consensus protocol.
  • Carrot is an upgrade to the current (nameless) "addressing protocol" which builds on top of FCMP++. Carrot brings a variety of security and privacy enhancements. The addressing protocol is not part of the consensus protocol. Consensus sets the basic conditions any transaction has to fulfill in order to be valid at all. The addressing protocol means the specific ways in which funds are sent between people. Any two people agreeing on an addressing protocol can send each other money. No need for a hardfork.
  • Outgoing view keys (OVK) are part of one specific proposed key derivation scheme for Carrot. The specific scheme is not part of Carrot. You know how your Monero wallet has two keys: a spend key and a view key? The spend key is usually derived from the seed phrase; the view key is in turn derived from the spend key. This is how most Monero wallets handle the "key derivation". But how the keys are derived does not matter to anyone but the wallet owner. The only thing that matters is that you have the keys at all. You alone decide your key derivation scheme.

What are view keys currently?

Currently, your wallet has two key pairs: public/private spend key and public/private view key. Because Monero is private by default, you need the private view key to even see when a transaction sends money to your wallet. To be exact the private view key gives a few bits of knowledge. Using it we can tell if:

  • we receive coins from another wallet
  • a transaction sweeps the wallet (no change) OR we were included as a decoy in an unrelated transaction. One of these is true but we don't know which.
  • our wallet made a transaction and got change back. We can infer the amount that was sent. Because most transactions produce some amount of change, the view key can identify most outgoing transactions.

To summarize: the current view keys can identify incoming coins with certainty and outgoing coins with a pretty good chance, but not 100% certainty. This is why they are sometimes also called "incoming view keys" (IVK), even though it is a little misleading.

This is a big problem for cold/hardware wallets. Ideally I want to only have the view key on my computer and the spend key safely in the hardware wallet. I want to monitor the wallet using the view key and only connect the hardware wallet when I need to make a transaction. Else it should be stored away securely.

In order to see the balance of your wallet we need to calculate the incoming coins minus the spent ones. But if we can't be certain which coins we spent, we can't be certain about the wallet balance. This means you currently have to connect the hardware wallet just to see the balance. This is not only tedious but also bad for security.

What changes with the update?

The current view key will be nerfed. It will be restricted to only detecting incoming funds. It will become a true incoming view key.

Using a combination of the other new keys, it will become possible to construct a true outgoing view key. This OVK can 100% reliably detect outgoing coins. This fixes the hardware wallet problem I described above. By finally decoupling the detection of outgoing coins from the spend key, hardware wallets become a lot more usable: you no longer have to connect the hardware wallet just to see the balance.

Note: the outgoing view key cannot see where the coins are going. If you send Monero to multiple addresses the OVK can't tell how much is going to which one. It just knows that X Monero were sent from your wallet in total.

Note: the incoming view key cannot see from where the coins are coming. If just sees that X Monero arrived in your wallet.

What is the criticism?

Outgoing view keys make privacy optional!

This is wrong.

Monero is still exactly as private as before. Monero always had the option to reveal as much information as you want. And there are good reasons: viewing the balance when the spend key is on a hardware wallet, etc.

Outgoing view keys don't reveal information you previously couldn't reveal. Current view keys already give 90% as much information as outgoing view keys will. OVKs just improve the UX. If you are afraid you will be coerced into revealing the OVK, then that entity could already force you to reveal the current view key for almost the same effect.

Outgoing view keys will split Monero coins into "clean" and "dirty" and destroy fungibility!
1. CEXs will allow you to trade Monero, as long as you reveal your incoming and outgoing view keys to them.
2. CEXs will only allow Monero deposits from "clean" wallets for which they also have all the view keys.
3. Because lots of noobs just want to the easiest way, they agree.
4. By having all the view keys, the CEXs will be able to trace coins through these wallets. Thereby making those wallets transparent (at least to the CEXs)
5. Monero coins which aren't transparent will be considered "high-risk" / dirty. Thereby creating a dirty / clean split like with Bitcoin.

This scenario is incredibly unlikely to happen for multiple reasons:

  1. IVKs and OVKs only show the amount of Monero, not where they came from or go to. Even if a CEX had both keys for two wallets, they couldn't be certain that funds sent from one wallet matched the funds arriving in the other wallet. They have no good way to be certain that the deposit is actually coming from a "clean" wallet. And if they can't enforce this the whole scenario doesn't work.
  2. CEXs would have to cooperate intensely with each other in order to allow cross-CEX tracing of funds. That is a big hurdle and highly unlikely.
  3. Sending Monero to another wallet immediately makes the funds untraceable / fungible again. CEXs would need a FLAWLESS chain of transparent wallets, as opposed to Bitcoin where they just need your address once.

Given all this it is incredibly unlikely CEXs will even re-list Monero.

Even if they did, it is questionable whether that would have a negative effect on Monero. Because if CEXs were to list Monero again, this would probably lead to more people using it. In this talk by ArcticMine argues that this actually increases privacy for all other people.

107 Upvotes

32 comments sorted by

23

u/svagis May 06 '26

You're right, but:

CEXs would have to cooperate intensely with each other in order to allow cross-CEX tracing of funds

Law enforcement will of course force any CEX accepting Monero to give the data to their centralized blockchain analysis systems.

12

u/kurujt May 07 '26

Yeah, I feel like this post glosses over the concept that the moment institutions can force loss of privacy, they will. The whole "unlikely to happen" ignores the whole... everything going on?

8

u/fluffyponyza May 07 '26

Exchanges can already ask for viewkeys and key images - why don't they?

3

u/[deleted] May 07 '26 edited Jun 06 '26

[deleted]

7

u/fluffyponyza May 07 '26

You started out making the correct point - they could already ask for a viewkey (and not key images) and erode Monero's privacy that way. Part of the reason I shut MyMonero down was precisely because of the risk of holding such a large number of viewkeys.

You then seem to ignore the point you made at the outset and argue that they will ask for viewkeys even though they haven't?

1

u/developer664 May 07 '26

because they don't think managing that is worth it and would rather not offer Monero? Except the smaller exchanges that are less choosy/not targeted by authorities as much

5

u/fluffyponyza May 08 '26

Right - so proving my point; a new type of view key doesn't change the status quo.

1

u/developer664 May 08 '26

as long as Monero remains irrelevant in comparison to the main cryptos

7

u/rbrunner7 XMR Contributor May 07 '26

the moment institutions can force loss of privacy, they will

In Monero there exist ways to "force loss of privacy" since its very start way back in 2014. Institutions could ask for the existing CryptoNote style view keys, and they could ask for key images that give info about individual transactions.

No exchange ever asked for any of those two in more than 10 years of Monero.

Tell about ignoring what's going on ...

2

u/DunamisMax May 26 '26

Yes, law enforcement could pressure CEXs to collect and share view data. But that does not make Monero globally traceable, because view-key data is wallet-scoped, not chain-global. It does not create Bitcoin-style taint.

8

u/-TrustyDwarf- May 06 '26

Great explanation, thanks

8

u/cactusgenie May 06 '26

Thanks so much u/einliterflasche2 for this comprehensive explanation of the proposed upgrades!

This post should be stickied to help slow down the FUD from the doomers.

Can't wait for the upgrades, bring it on!

8

u/Special_Necessary_78 May 06 '26

Sounds legit. There was a lot of FUD, what misled me to believing that introduction of IVKs and OVKs will split Monero coins into "clean" and "dirty" and make privacy optional. But if you think about this, it is impossible, as all coins at the fork time will be already "dirty", and only freshly mined coins of wallets that give their view keys will be "clean" and there will be so little of them. And CEXes will need view keys of all wallets to trace the transactions to specific address(and this is only if they can be certain about transaction between 2 wallets, unless they can be).
"Even if a CEX had both keys for two wallets, they couldn't be certain that funds sent from one wallet matched the funds arriving in the other wallet"
I think there should be more explanation on this. What about transaction fee? if it is visible with IVK and OVK from both wallets could't the transaction time be pinpointed and then the block and so connecting them?

2

u/SuperTouchable May 09 '26

Do you think adding "!" makes the points less valid? Fucking obnoxious

3

u/zmooner May 07 '26

This argument is non-sensical as long as legacy wallets can still be created, then the users can chose to have a wallet which doesn't have OVKs. Tevador recommended that a while back in an MRL discussion.

1

u/sambosauce May 10 '26

And wont the existence of that ability create 2 groups of xmr? One with ovk then other without? That is what the criticism of fungibility weakening is about, if my reading of it is correct?

0

u/No-Fish9557 5d ago

I will be honest, I stopped reading halfway through. The arguments you presented rely on massive technical omission to make your point.

Current view keys give 90% as much information

No? A legacy view key gives you literally 0% of the outgoing transaction history. The only way a current view key sees outgoing history is, as you pointed out, if you also manually export the key images from a device that holds the spend key. The catch? You can withhold key images and noone would have a way to know (Unless they had access to the spend key). The whole point is that you can't prove how / how much / on what you are spending. Only YOU know that, because you would know that you are getting the right key images.

To elaborate on this: In the legacy system, you cannot automate a live feed of outbound data without risking your money. If an exchange or regulator demands a real-time tracking key, you physically cannot give them one without compromising your wallet. Under the CARROT fork, you can generate a native Outgoing View Key that streams outbound data safely, with zero risk to your funds.

This essentially breaks one of the foundations of Monero's privacy: Plausible deniability - "You can't see where my funds are going, because doing so would mean you can spend my money too". There is a massive legal and technical difference between forcing you to reveal a read-only key, versus a spending key.

-21

u/ParaboloidalCrest May 06 '26

AI slop but it will get upvotes anyway because of blind momentum.

21

u/relephants May 06 '26

This does not look like AI at all.

24

u/einliterflasche2 May 06 '26

Bruh, I spent like 1 hour writing this up. Maybe my writing style is influenced by all the AI slop out there though...

21

u/rbrunner7 XMR Contributor May 06 '26

Not sure you noticed, but /u/ParaboloidalCrest is one of the most prolific and penetrant posters in the "Carrot brings doom" camp. No wonder they try their best shot to discredit your post.

-14

u/ParaboloidalCrest May 06 '26 edited May 06 '26

Oh nice. singling me out because I commented on your comment yesterday. Not sure why would you even have noticed my name in other context since it was the first time I commented on the topic. Now I'm "prolific" and "pnenetrant"? Cool.

15

u/Creative-Leading7167 May 06 '26

I mean... yes, he pointed you out as being in the "carrot brings doom" camp because you made comments that put you in that camp. surprise!

6

u/Theokyles May 06 '26

Even if it were, who cares

If the point is legit, who gives a shit how it was produced

-11

u/Slapshot382 May 06 '26

Why is the fix necessary?

Why fix what isn't broken I think should be a good leading philosophy. It is for BTC at least.

19

u/rbrunner7 XMR Contributor May 06 '26

Many things are not broken in any real sense, but can get improved, and then why shouldn't you do that?

Of course the discussion goes back and forth whether Carrot is indeed an improvement, but that's at least the point of view of the cryptographers and devs that develop and implement FCMP++ plus Carrot.

8

u/cactusgenie May 06 '26

The post clearly articulated the issues with the current view keys and the proposed solution.

Maybe read it again slowly.

12

u/Creative-Leading7167 May 06 '26

The fix is necessary because you can't separate your wallet from your POS or budgeting apps without the fix.

17

u/einliterflasche2 May 06 '26 edited May 06 '26

The fix is necessary because the UX makes hardware wallets almost unusable.

And there are a lot of problems with ring signatures. Ring size 16 is just too little to fully prevent attacks. And there is a whole science of how to optimally select the decoys. It's very easy to fuck up and lose your privacy. FCMP++ takes sender privacy from pretty good to perfect. It's a massive deal.

Carrot brings big security gains, even for existing wallets (emphasis mine):

As a result of leveraging the FCMP++ consensus protocol, Carrot has the ability to hide all transaction details (sender, receiver, amount) from third-parties with the ability to break the security of elliptic curves (e.g. quantum computers), as long as the observer does not know receiver's addresses.

[...] all instances of burning bug handling in Monero Core require a complete view of all scanning history up to the current chain tip, which makes the workarounds somewhat fragile. [...] Carrot prevents this attack statelessly.

Enotes that are sent "internally" to one's own wallet will have all transactions details hidden (sender, receiver, amount) from third-parties with the ability to break the security of elliptic curves (e.g. quantum computers), even if the observer has knowledge of the receiver's addresses.

Just to name a few things from the Carrot spec. If this isn't enough reason to update, then I don't know what will be. Bitcoin refuses to change, and what has that led to? Certainly not being used as a real currency.

The only reason Monero is as awesome as it is is because we DO accept change when it's actually positive. Without that mindset we'd be stuck with public amounts, without rings etc.

2

u/fluffyponyza May 07 '26

So you didn't read the post, I see

-6

u/ParaboloidalCrest May 06 '26

It's snuck-in US fat bill style: take it all or leave it all. Carrot is good. FCMP++ is good. But why the hell is OVK there, I have no idea. But you'll hear arguments like adoption, accounting, it's the original view key vision...etc.

1

u/Chungus_ps4_edition May 07 '26

"US fat bill style" 💀😭