xmr.club
EN 中文 ES RU
★ FRONT-PAGECOllie Swap— Anonymous Tor-only swap for BTC, BCH, DASH, LTC, XMR — no accounts, own liquidity, PGP-verified operator identity.
/mixers · verificado 2026-07-29

BasicSwap DEX

A-

DEX de atomic swaps — intercambio directo on-chain entre XMR / BTC / LTC / PIVX.

Mantenedor: BasicSwap DEX

Cronología del incidente

  1. 2026-07-15 OrangeFren.com (verified X, @OrangeFren) reported at 2026-07-15 00:49Z that BasicSwapDEX was exploited with 0.66 BTC (~$42k) losses confirmed so far. Curator opened incident. basicswapdex.com surface still HTTP 200 at this timestamp; operator-account response not yet visible via curator probe.
  2. 2026-07-15 Operator (@BasicSwapDEX, verified) acknowledged approximately twelve hours before the +1h re-check with an Important Security Notice: 'A swap security issue has been identified and is being fixed. Until the patch is live, withdraw your offers, don't start new swaps, and if you have a swap in progress (especially stalled or near timeout), shut your node down and leave it off.' Follow-up post: 'Don't attempt manual refunds or recovery on your own, and keep your BasicSwap data and wallets intact. Patch and full instructions to follow. The fix will apply automatically when starting your node after updating.'
  3. 2026-07-15 Operator posted the v0.17.2 hardening release approximately nine hours after the acknowledgement: 'BasicSwap v0.17.2 is now out and fixes the security issue detailed in this post. Update now, then it's safe to bring your node back online and post offers again. If you had a swap in progress, update first and let it resume; don't force manual refunds.' Turnaround from OrangeFren-report to shipped fix is approximately 21 hours end-to-end. Curator read: responsible-incident-response pattern — grade movement recommendation is A → A- (mirrors Haveno post-2026-06 demotion). Reader guidance: update to v0.17.2 before restarting any node with an in-progress swap; do not force manual refunds; the patch applies the fix automatically on node restart.
  4. 2026-07-16 +24h re-check. Fresh evidence from the operator's public GitHub release train tightens the timeline meaningfully. Version cadence: v0.17.0 2026-07-09, v0.17.1 2026-07-12 (already a security-hardening release adding false-refund classification defenses + Electrum fee-inflation limits + AEAD key-format migration), v0.17.2 2026-07-14T11:36:50Z (the release that patches the exploit reported publicly by OrangeFren 13 hours later). Root cause per the v0.17.2 release notes: 'Adaptor-sig swaps: track the coin A lock refund tx to blocks_confirmed depth before publishing the lock refund spend tx. The refund spend reveals the leader's key share to the counterparty; publishing it while the refund tx is still unconfirmed could let a released follower recover that share and race both legs of the swap.' Companion hardening: the coin B lock tx must reach spendable depth before the follower broadcasts a chain B lock refund recovery spend. Curator read: the fix was already shipped ~13 hours before OrangeFren's public report on 2026-07-15 00:49Z — the operator disclosed and released in the same window, then OrangeFren picked up the public reporting later. That is meaningfully stronger incident response than 'operator responded within 12 hours of public disclosure' suggested. Loss figure ($42k / 0.66 BTC) unchanged in public sources today — no follow-up figure from OrangeFren visible via curator probe. @BasicSwapDEX X profile bio unchanged; no additional acknowledgement or post-mortem post surfaced today beyond the initial 3-tweet thread already on file. Grade held at A- per curator sign-off 2026-07-15. Reschedule +24h to keep the poll alive.
  5. 2026-07-17 +48h re-check. New release: **v0.17.3 published 2026-07-16T01:27:18Z** — a follow-up hardening release shipped ~14 hours after v0.17.2. Contents: (a) defense-in-depth on the same adaptor-sig swap surface — 'constrain which bid states accept the lock-release, coin-A-lock-signature and lock-spend P2P messages, and reject messages for revoked/inactive offers. Prevents a hostile or replayed peer message from mutating a finished/terminal bid or resurrecting it into an active swap.' This tightens which peer messages can even reach bid-state transitions, adjacent to the v0.17.2 lock-refund key-share race fix. (b) Web UI hardening on a separate attack surface: Host-header allowlist against DNS-rebinding, CSRF check on Origin/Referer as full origin, WebSocket handshake Origin validation against cross-site WebSocket hijack. Curator read: the operator is running a comprehensive audit + follow-up sweep, not treating v0.17.2 as the end of the response. That is the strongest signal I could ask for on a Grade A- listing with an open exploit incident. No new post-mortem or updated loss figure surfaced today; OrangeFren has not published a follow-up visible to curator probe. Loss figure unchanged at 0.66 BTC (~$42k). basicswapdex.com surface still up, no advisory banner on the homepage (which is fine — the response is happening on GitHub + X, not on the marketing surface). Grade held at A-. Reschedule +24h.
  6. 2026-07-18 +72h re-check. Fourth hardening release since the incident opened: **v0.17.4 published 2026-07-16T21:55:43Z** — ~20 hours after v0.17.3. Contents: (a) Particl blind swaps — verify the lock-tx-spend output pays the expected address (another adaptor-swap-adjacent invariant, tightens the same class of validation as v0.17.2 / v0.17.3). (b) Electrum hardening — confirmations Merkle-verified against block header, watch-only balances excluded from spendable balance (defense against a hostile Electrum server misreporting state to the client). (c) Reliability/config fixes — allowed_hosts single-string normalization, AMM Docker htmlhost=0.0.0.0 UI fix, active-swap loop snapshot before iterating, transient RPC-error retry on queued swap actions. (d) CI matrix expanded to run test_coins for Particl blind and Particl anon; pytest suites now fail-fast. Curator read: the release cadence (v0.17.0 → v0.17.4 over 8 days, three of them after the exploit report) is a comprehensive audit sweep, not a one-and-done hotfix. Each release tightens an adjacent validation surface (bid-state message gating in v0.17.3, expected-address invariant in v0.17.4). No post-mortem document has been published yet — root-cause is still just the v0.17.2 release-notes paragraph. Loss figure unchanged at 0.66 BTC (~$42k) per public sources today; OrangeFren has not posted a follow-up visible to curator probe. Grade held at A-. Reschedule +24h.
  7. 2026-07-19 +96h re-check. No new release since v0.17.4 (2026-07-16T21:55:43Z) — approximately 54 hours of release quiet, which is the first sustained pause since the incident opened. Read: the rapid audit-sweep cadence (v0.17.2 / v0.17.3 / v0.17.4 in 34 hours) is settling into a normal cadence. This is a good sign in its own right on a Grade A- listing with an open incident — the emergency-hardening pattern is winding down. basicswapdex.com surface still HTTP 200, no advisory banner (as expected — the response continues to happen on GitHub + X, not on the marketing page). Loss figure unchanged at 0.66 BTC (~$42k). No formal post-mortem document has been published — root-cause is still just the v0.17.2 release-notes paragraph. OrangeFren has not posted a follow-up visible to curator probe. Grade held at A-. Reschedule +24h.
  8. 2026-07-20 +120h re-check. No new release since v0.17.4 (2026-07-16T21:55:43Z) — approximately 78 hours of release quiet, extending the settle-into-normal-cadence signal from Day 5. Second consecutive check without a hardening release confirms the audit sweep has wound down into stable maintenance mode. No post-mortem document has been published — root-cause still just the v0.17.2 release-notes paragraph. Loss figure unchanged at 0.66 BTC (~$42k). OrangeFren has not posted a follow-up visible to curator probe. basicswapdex.com surface still HTTP 200 with no advisory banner (consistent with prior probes — response continues to happen on GitHub + X, not the marketing surface). Grade held at A-. Reschedule +24h.
  9. 2026-07-21 +144h re-check. **NEW: v0.17.5 published 2026-07-20T20:47:14Z** — ~96 hours after v0.17.4, ending the release quiet observed on Days 5-6. Fifth post-incident hardening release. Contents on the adaptor-sig surface: (a) ignore replayed coin-A lock-signature messages + gate the coin-A lock send; (b) re-create purged coin-B lock action after restart; (c) verify and record received lock-release esig even in error states. Networking retries socks/proxy errors as transient. Sub-fee bid fixes (off-by-one on fee verification, UI lockout during processing, prefunded-tx electrum utxo regression). Litecoin PoW scrypt fix, SMSG timeout+paging, Decred prefunded-tx + prepare/mercy tx fixes, AMM autostart under htmlhost=0.0.0.0. Daemon bumps: Bitcoin 29.4 (added alternative PGP key), Dash 23.1.7, Monero 0.18.5.1. Curator read: the release cadence never fully wound down — v0.17.5 continues the audit-sweep pattern with more adaptor-sig defense-in-depth (replay + purge + esig-record hardening) plus a broader fix pass. Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem document. OrangeFren no follow-up. Grade held at A-. Reschedule +24h.
  10. 2026-07-22 +168h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 44 hours of release quiet. Second consecutive check without a hardening release since v0.17.5 shipped. The audit-sweep cadence that spanned v0.17.2 through v0.17.5 (four post-incident releases in 6 days) has now genuinely settled. Loss figure unchanged at 0.66 BTC (~$42k) per public sources. No post-mortem document. OrangeFren has not posted a follow-up visible to curator probe. basicswapdex.com surface HTTP 200, no advisory banner (as expected — response continues on GitHub + X). Grade held at A-. Reschedule +24h.
  11. 2026-07-23 +192h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 67 hours of release quiet, third consecutive quiet-cycle probe. The post-incident audit-sweep cadence (v0.17.2 through v0.17.5 shipping in a 6-day emergency-hardening train) is durably settled into normal maintenance. Loss figure unchanged at 0.66 BTC (~$42k) per public sources. No post-mortem document published — the response continues to live in the release-notes prose for v0.17.2 (root cause) + v0.17.3 through v0.17.5 (defense-in-depth). OrangeFren has not posted a follow-up visible to curator probe. basicswapdex.com surface HTTP 200, no advisory banner (as expected). Grade held at A-. Reschedule +24h.
  12. 2026-07-24 +216h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 91 hours of release quiet, fourth consecutive quiet-cycle probe. The post-incident audit-sweep cadence remains durably settled into normal maintenance since v0.17.5. basicswapdex.com surface HTTP 200 (~40KB, no advisory banner change vs prior probes). Nitter + xcancel mirrors dark this probe — no fresh @BasicSwapDEX post-mortem or @OrangeFren follow-up capturable via curator probe today; primary GitHub signal is the release train, which remains at v0.17.5. Loss figure unchanged at 0.66 BTC (~$42k) per last-known public sources. Grade held at A-. Reschedule +24h.
  13. 2026-07-25 +240h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 116 hours of release quiet, fifth consecutive quiet-cycle probe. basicswapdex.com surface HTTP 200 / ~40 KB, no size drift or banner change from prior probes. X mirror probes remain dark this cycle (nitter + xcancel both bot-blocked from curator vantage in recent probes) — no fresh @BasicSwapDEX post-mortem or @OrangeFren follow-up capturable today; primary GitHub signal is the release train, which remains stable at v0.17.5. Loss figure unchanged at 0.66 BTC (~$42k). Grade held at A-. Reschedule +24h.
  14. 2026-07-26 +264h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 140 hours of release quiet, sixth consecutive quiet-cycle probe. basicswapdex.com surface HTTP 200 / ~40 KB, no size drift or banner change from prior probes. X mirrors dark this cycle (nitter + xcancel bot-blocked); primary GitHub signal remains stable at v0.17.5. Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem published; no OrangeFren follow-up. Note for context: the concurrent OpenMonero incident escalated D → F on 2026-07-25 on the strength of a kycnot.me advisory; that is a separate incident tracked on its own row and does not affect basicswap grading. Grade held at A-. Reschedule +24h.
  15. 2026-07-27 +288h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 164 hours of release quiet, seventh consecutive quiet-cycle probe. basicswapdex.com HTTP 200 / ~40 KB (stable, no drift). Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem, no OrangeFren follow-up. Incident has objectively settled — the 7-day stable-cadence window has now been sustained. Grade held at A-. Reschedule +24h; will surface a wind-down recommendation to the operator on the next cycle.
  16. 2026-07-28 +312h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 188 hours of release quiet, eighth consecutive quiet-cycle probe. basicswapdex.com HTTP 200 / ~40 KB (stable, no drift from any prior probe). Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem, no OrangeFren follow-up. Incident is settled. Grade held at A-. Reschedule +24h — will surface wind-down recommendation again on next cycle.
  17. 2026-07-29 Incident closed. 14-day observation window since 2026-07-15 with responsible operator response (v0.17.2 hardening release shipped ~13h before OrangeFren's public report; four follow-up defense-in-depth releases through v0.17.5 within 6 days; 8 consecutive daily quiet cycles since). Loss figure unchanged at 0.66 BTC (~$42k); no post-mortem published but the release-notes prose across v0.17.2–v0.17.5 documents root-cause + defense-in-depth. Grade held at A- for the incident duration. Daily poll retired; future re-open triggered by event only (fresh @BasicSwapDEX activity, @OrangeFren follow-up, new hardening release, or independent loss report).

Visión general

Grado
A- ()
Postura KYC
registro anónimo
Tarifas
Swap-fee only · adaptor sigs · Particl + Tor coordinator
Última verificación
2026-07-29
Operando desde
2022 · 4y
Incidente
⚠ Activo desde — /incidents
A- ¿Por qué grado A-?

B-shape positive signal at A grade — solid posture and likely A, but one element of the A bar (typically operating tenure or a fresh test-trade) is not yet on file.

Rubric completo + recorrido de verificación de 7 pasos en /methodology.

Reseña

BasicSwap es la *forma sin confianza de intercambiar XMR y BTC* — un DEX de escritorio de código abierto que ejecuta genuinos intercambios atómicos entre cadenas directamente entre pares, sin custodia, sin tokens envueltos, sin puentes y sin pools de liquidez que drenar.

Antecedentes. Construido desde 2022 dentro del ecosistema Particl, BasicSwap es una *interfaz gráfica de escritorio para intercambios atómicos entre cadenas* coordinada entre pares sobre Tor. Su capacidad principal — y la razón por la que importa aquí — es el intercambio nativo *XMR↔BTC* utilizando firmas adaptadoras, una técnica criptográfica que permite a dos partes comerciar a través de cadenas atómicamente sin que ninguna tenga las monedas de la otra. Ese diseño genuinamente no custodial y sin puentes es por lo que obtiene una A en /mixers: es la rara herramienta de intercambio cuyo modelo de confianza es "confía en las matemáticas", no "confía en el exchange".

En qué confías. Casi nada más allá del protocolo. Los intercambios son *atómicos*: los intercambios con firmas adaptadoras bloquean los fondos de tal manera que o bien el comercio se completa para ambas partes o ambas recuperan sus monedas — *no hay custodia*, ningún intermediario que sostenga tu XMR mientras envía BTC. *No hay tokens puente* (intercambias XMR real por BTC real, no un pagaré envuelto que puede desvincularse o ser estafado) y *no hay pools de liquidez* (así que no hay pool que hackear o drenar — las órdenes se emparejan entre pares). Todo es *código abierto* y se coordina *sobre Tor*, por lo que la capa de emparejamiento de órdenes no expone tu identidad de red. La confianza residual está en la corrección del protocolo y en que tu contraparte respete los bloqueos temporales — lo cual la atomicidad impone.

Especificaciones operativas. Una *aplicación de escritorio* que ejecutas tú mismo (levanta los clientes de cadena relevantes), emparejando órdenes *entre pares sobre Tor* y liquidando mediante intercambios atómicos con firmas adaptadoras. *XMR↔BTC* es el par insignia, con otras monedas soportadas. *No hay cuenta, no hay KYC* — estás ejecutando software e intercambiando directamente con pares. Como es un mercado P2P real con autocustodia, el *libro de órdenes es más pequeño* y más delgado que un intercambio centralizado, y un intercambio implica ejecutar clientes y esperar confirmaciones en cadena en ambos lados. Código abierto, autoalojado, parte del stack de Particl.

Filosofía. Cada intercambio centralizado y la mayoría de los puentes "entre cadenas" reintroducen exactamente lo que las criptomonedas debían eliminar: un custodio que retiene tus fondos durante el comercio y un tarro de miel que puede ser hackeado, congelado o coaccionado. La tesis de BasicSwap es que intercambiar *XMR↔BTC* — el par más relevante para la privacidad — debe ser *sin confianza y entre pares*: ningún exchange que te haga KYC, ningún puente en quien confiar, ningún pool que drenar, solo dos personas y una garantía criptográfica. Liberarlo como código abierto y ejecutar el emparejamiento sobre Tor es la única configuración consistente con ese objetivo.

Justificación de la calificación. A en /mixers. La calificación refleja genuinos intercambios atómicos no custodiales (sin custodia, sin tokens envueltos, sin pools), soporte nativo XMR↔BTC, operación sin cuenta/sin KYC, una base de código abierta y emparejamiento entre pares coordinado por Tor. En modelo de confianza está esencialmente sin igual en la categoría. Las advertencias — liquidez, UX y la lentitud inherente de los intercambios atómicos entre cadenas — son el precio de esa ausencia de necesidad de confianza, no defectos en el diseño.

Útil cuando. Recurre a BasicSwap cuando quieras moverte entre *Bitcoin y Monero sin un custodio ni un punto de control KYC* y estés dispuesto a ejecutar software de escritorio y esperar a que se liquide un intercambio real entre cadenas. Es la herramienta para el maximalista de privacidad que se niega a entregar XMR a un exchange o confiar en un token puente — acepta el libro de órdenes más delgado como el costo de un modelo de confianza que nada más iguala.

Advertencias. La liquidez es la limitación honesta: un libro de órdenes entre pares con autocustodia es *más delgado* que un intercambio centralizado, por lo que puedes esperar por una contraparte u obtener peor profundidad en tamaños mayores — la paciencia es parte del trato. Es *software de escritorio que ejecutas* (levantando clientes de cadena, sincronizando), por lo que hay sobrecarga de configuración y recursos, y los intercambios atómicos entre cadenas son *inherentemente más lentos* que un intercambio instantáneo custodial. Como proyecto de código abierto en evolución, la UX es más tosca que una aplicación pulida, y debes verificar que estás ejecutando el cliente genuino. Nada de esto mella la A — para *XMR↔BTC sin confianza*, BasicSwap es la herramienta de referencia, con la compensación explícita de que la ausencia de necesidad de confianza cuesta conveniencia.

Tarifas

Swap-fee only · adaptor sigs · Particl + Tor coordinator

Enlaces

Tomado de las páginas del operador — verifique por más de un canal antes de confiar en instrucciones urgentes.

Rastro de auditoría — recibos del reclamo editorial

  • UPSTREAM Activo · HTTP 200 · 2077ms · comprobado 22h ago
  • ONION Sin .onion espejo
  • MANUAL Última verificación manual 2026-07-29 (<30d)

Reseñas — moderado · reglas

Aún no hay reseñas. Sé el primero.

Añadir reseña

Feedback honesto y neutral bienvenido. El curador aprueba antes de mostrarse. Sin JS.

Requerido: cuerpo de reseña. Reseñas honestas y descriptivas se aprueban en un día. Copy de marketing, insultos y diatribas se rechazan. Tope diario de 5 envíos por IP.