What Is Monero? Ring Signatures, Stealth Addresses and Why Exchanges Drop It
Monero explained without the hand-waving: what a ring signature actually does, why your published address never reaches the blockchain, what fungibility means in practice, and why every large exchange has been dropping it.
Most explanations of Monero start with the word "privacy" and stop there, which explains nothing. The useful version starts somewhere else: with what Bitcoin actually does, and why a lot of people were surprised by it.
Bitcoin is not anonymous, and that is the whole starting point
Every Bitcoin transaction ever made is public. Not "available to law enforcement on request" — public, permanently, to anyone with a browser. Paste an address into a block explorer and you can see every payment it has ever received, every payment it has sent, and the running balance, going back to the day it was created.
Bitcoin is pseudonymous: your name is not attached, but a persistent identifier is. And identifiers get linked to people. The moment you buy coins on an exchange that verified your passport, or send a payment to a shop that knows your delivery address, that link exists. From there, chain analysis is largely a matter of following the arrows.
If you are new to how any of this works underneath, our primer on coins, tokens and blockchains covers the ground this article assumes.
Monero was built by people who considered that a design flaw rather than a feature. Rather than adding privacy as an option, it makes every transaction private by default — there is no transparent mode to fall back to, and no way to opt out. That single decision is the source of everything else, including the delistings.
The three things it hides
A payment leaks three separate facts: who sent it, who received it, and how much. Monero conceals each with a different mechanism, and they are worth understanding separately because they solve different problems.
Ring signatures hide the sender
When you spend, your wallet does not sign alone. It pulls fifteen unrelated past outputs off the blockchain as decoys and signs on behalf of the whole group of sixteen.
The cryptography guarantees two things at once: the signature is valid, so no coins can be invented, and it is valid for the entire ring, so it proves one of the sixteen authorised the spend without recording which. The decoys are real outputs belonging to real strangers who are not involved and never find out they were used.
Stealth addresses hide the receiver
This is the part that surprises people. The address you hand out never appears on the blockchain at all.
When someone pays you, their wallet mathematically derives a brand-new one-time address from yours and sends there instead. Ten payments produce ten unrelated addresses. Nobody can look up your address to total what you have been paid, because there is nothing on the chain to look up. Your own wallet finds the payments using a private view key, which is also the thing you would hand an accountant or an auditor if you needed to prove income — privacy by default, disclosure by choice.
Confidential transactions hide the amount
The last piece encrypts the values themselves. The network can still verify that inputs equal outputs and that nobody created coins out of nothing, without any participant learning the figures. Only sender and receiver see the amount.
Fungibility: the word that explains why anyone cares
Here is the argument that privacy advocates actually make, and it is not about hiding.
Money is supposed to be interchangeable. Any ten-pound note is worth the same as any other ten-pound note, and a shop cannot refuse yours because of who held it in 2019. Bitcoin breaks that. Because the history is public, coins carry a visible past — and exchanges routinely freeze deposits whose history touches a sanctioned address or a hacked exchange, several owners back. A coin you bought legitimately can arrive "tainted" through no action of yours.
That is a real problem people hit, and we have written about why crypto exchange accounts get frozen when it happens. Monero has no history to inspect, so every unit is identical to every other unit. Whether that is a virtue or a hazard is exactly the argument, and both sides are making the same observation.
Why exchanges keep dropping it
The delistings are not a scandal, they are compliance arithmetic. OKX removed XMR pairs on 5 January 2024. Binance delisted it globally on 20 February 2024. Kraken suspended trading across the European Economic Area on 31 October 2024 and automatically converted customers' remaining balances into Bitcoin — if you left XMR sitting there, the decision was made for you.
The driver is the EU's MiCA framework and equivalent anti-money-laundering rules elsewhere, which require exchanges to trace the origin of funds. A coin engineered so that origin cannot be traced is not something a licensed venue can easily square with that obligation. Note what has not happened: owning and using Monero remains legal in the United States, the European Union, the United Kingdom and Canada. Large regulated businesses decided it was not worth the overhead. That is a commercial choice, not a ban — but the practical effect is that the familiar route disappeared.
You can still see the shape of it in our crypto exchange ranking: the venues that kept it are the ones with the least European exposure.
What it is actually used for
Honestly: both things.
It is used by people who simply do not want their salary, their savings or their donations legible to anyone who learns one address — which describes most people's relationship with their bank account, and is not a suspicious thing to want. It is also used for ransomware payments and darknet markets, for exactly the same properties. Anyone who tells you it is only one or the other is selling something.
What is worth knowing practically is that privacy is not the same as invisibility. Your Litecoin or Bitcoin side is fully transparent, so the approach to a swap is on a public ledger even when the far side is not. Exchangers have anti-money-laundering thresholds and will ask for verification above them. And a Monero balance is not immune to the ordinary risks — a lost seed phrase is just as final here as anywhere else.
Where people keep it, and how they get it
Monero does not run on Ethereum or any other chain, so most multi-coin wallets do not support it. It needs a wallet that speaks its own protocol — the official desktop client, one of the mobile wallets built for it, or a hardware device with explicit Monero firmware. Our guide to choosing a crypto wallet covers which types actually support it and what the trade-offs are, because "any wallet" is not the answer here.
Acquiring it is where the delistings bite. With the large venues out, most people now route through independent exchangers, which is why our monitor covers this pair at all — and there is more coverage than you would expect. Measured across the twenty-two crypto assets on our rate monitor, Monero sits third for exchanger coverage, ahead of coins with far larger market capitalisations. The operators went where the demand went.
Litecoin is the usual source coin because it is cheap and quick to send, and the Litecoin to Monero route has the practical detail: the rate gap between exchangers on that pair has been running near nine percent, which is worth more than any other decision you make. Going the other way, turning XMR back into a spendable balance is its own problem, covered in the Monero to Volet guide.
Bottom line
Monero is not "Bitcoin but sneaky". It is a different answer to a question Bitcoin answered in a way its own users often did not expect — that a public ledger makes money traceable and therefore not quite interchangeable. Ring signatures hide the sender, stealth addresses hide the receiver, confidential transactions hide the amount, and the result is a currency with no history to inspect.
That property is genuinely useful and genuinely inconvenient for regulated exchanges, which is why it works well and why you increasingly cannot buy it where you buy everything else. Both facts have the same cause.
