Monero + Tor: ProxyMark network deanonymization (not a crypto break)
Verified (29 Jul 2026): Academic paper ProxyMark (arXiv:2607.07062, submitted 8 Jul) shows a network-layer attack on Monero nodes that use Tor hidden-service peers. Originated txs are first sent to two Tor HS “proxy” peers before clearnet Dandelion++ — an adversary who occupies those outgoing peers can capture origin txs, then watermark traffic to link onion identity to a real IP. Authors report strong lab metrics (100% onion-ID precision; 7–11 of 12 outgoing HS links occupied in tests; watermark ~91–94% recall) on live Tor + Monero mainnet/testnet. This does not break ring signatures, stealth addresses, or RingCT, and does not read tx contents. Threat model needs a heavy Sybil/Tor-entry adversary — not “Tor is useless for everyone.” Monero Research Lab agenda for Wed 29 Jul 17:00 UTC explicitly lists this paper. Lineage: WWW’24 workshop abstract; full ProxyMark arXiv is the Jul 2026 writeup.
369 take: Privacy stacks fail at seams. Monero’s crypto can hold while Tor+P2P forwarding still leaks who originated a broadcast. Pulse lesson for any “private” path (mixers, shields, Tor wallets): ask what metadata bookends remain public and who can sit on the relay choke points.