xmr.club
EN 中文 ES RU
★ availableBecome the front-page sponsor— 1.5 XMR/mo · 1 slot site-wide · banner on home, every category, every provider
/exchanges · verified 2026-06-24

RetoSwap

A

Decentralised XMR↔fiat P2P. Haveno fork operated independently, multi-sig escrow.

Incident timeline · resolved 2026-06-24

  1. 2026-05-20 Trade-protocol vulnerability (negative-value validation gap, shared Bisq lineage) hit the network; RetoSwap liquidity collapsed toward $0.
  2. 2026-05-28 Recovery update: RetoSwap operator back online with the patched client; network liquidity recovering.
  3. 2026-06-11 Network liquidity confirmed recovered and held (~9,500 XMR, ~2x the ~5k threshold). Incident resolved.
  4. 2026-06-17 RetoSwap exploit report received at 18:02 UTC. Team set minimum-client-version 2.0.0 via filter feature + banned attacker onion `…e6wyrtdczsrhtves2jofi2qpad.onion:9999`. Attack distinct from May: arbitrator legitimacy intact, the forced-arbitration flow itself releases XMR after 30 confs with no BTC. Damage contained to large-scale crypto offers; fiat traders unaffected. Affected traders directed to RetoSwap SimpleX group.
  5. 2026-06-24 RetoSwap announces 'back up and running' (X @RetoSwap). Network reopens on the v1.8.0-hardened client tied to Haveno v1.8.0 (released 2026-06-20), which ships arbitrator-signature verification on dispute payouts and verified-sender enforcement across trade-setup and deposit messages — the broader fix vs the May v1.5 targeted patch. Recovery coordination with affected users ongoing.
  6. 2026-06-25 Two-week liquidity recovery check (api.kyc.rip resistance.p2p_liquidity, network-wide Haveno P2P depth): network is trading again on the v1.8.0-hardened line, but depth has NOT re-cleared the ~5k-XMR health threshold. Current reading ~4.78k XMR; the trailing 14 days ranged ~4.0k–5.5k (excluding two obvious data-spike outliers), with the majority of readings below 5k and the latest dipping to ~4.79k. Severity held — depth recovery not yet confirmed; continuing the bi-weekly watch.

At a glance

Grade
A ()
KYC posture
anonymous signup
Fees
~1% taker · trade-specific spread · on-chain multisig
Last verified
2026-06-24
Operating since
2024 · 2y
Incident
✓ Resolved 2026-06-24 — /incidents
A Why grade A?

Best evidence tier. Signup tested end-to-end by xmr.club curator — deposit + withdrawal + edge cases. No-KYC posture verified at retail volume. Last_verified within 12 months.

Full rubric + 7-step verification walkthrough at /methodology.

Review

RetoSwap is an independent Haveno-based marketplace built for the use case Monverse lost when LocalMonero shut down in 2024: peer-to-peer XMR↔fiat with no central custody and no KYC. Trades settle through on-chain multisig escrow rather than an operator's hot wallet, which makes it one of the highest-privacy ways to move between Monero and fiat short of meeting someone for cash.

Background. Haveno is, in effect, Monero's answer to Bisq — a decentralized P2P exchange protocol where buyers and sellers transact directly using real-world fiat payment methods, protected by multisig escrow and security deposits. RetoSwap runs its own Haveno network (its own seed nodes and arbitrators) with a desktop client, and inherits the spirit of LocalMonero — community liquidity for fiat on/off-ramps — while explicitly dropping the central-custody model that made LocalMonero a single point of seizure. It is the privacy-first answer to "I have cash/bank fiat and I want native XMR without an exchange account."

What you trust. This is the important part, because Haveno's trust model is different from a custodial swap. Each trade is locked into a 2-of-3 multisig: buyer, seller, and an arbitrator each hold a key. Normal trades complete with just buyer and seller signing; the arbitrator only steps in on a dispute. Both sides post a security deposit that disincentivizes cheating. So you are not trusting RetoSwap with custody of your funds — you are trusting (a) the multisig cryptography, (b) the honesty and availability of the network's arbitrators, and (c) the seed-node operator's integrity. The arbitrator is the critical human trust anchor: on any Haveno network, a compromised or impersonated arbitrator is the realistic threat, not the operator absconding with a hot wallet. Follow standard discipline — never release escrow early, verify you're dealing with the legitimate arbitrator, and keep all communication and evidence inside the client.

Operational specs. Desktop client (not a website you paste an address into), on-chain multisig escrow, security deposits on both sides, fiat payment methods for the fiat leg, and no KYC. Because it's genuine P2P, liquidity and spreads are worse than centralized swaps — you trade depth for the strongest privacy posture, and you may wait for a counterparty at your size and payment method. Settlement is as fast as the two humans and the payment rail allow, not instant.

Philosophy. RetoSwap is non-custodial, permissionless fiat↔XMR by design: no account, no central pool of funds to subpoena or seize, no identity attached to a trade. It carries forward the LocalMonero community-liquidity ethos into an architecture where the operator structurally *cannot* be the single point of failure that custodial P2P platforms were. That is the whole pitch, and it's an honest one.

Grade rationale. Grade A reflects the non-custodial multisig design, the genuine no-KYC fiat on/off-ramp (a scarce and valuable capability post-LocalMonero), and an independent operator filling a real gap. It sits at A rather than higher because of the inherent P2P trade-offs — thinner liquidity, a learning curve, and a trust model that rests on arbitrator honesty rather than pure cryptography.

Useful when you need to move between fiat and native Monero without an exchange account or ID, you value seizure-resistance over speed and depth, and you're comfortable running a desktop client and following multisig discipline. It's the natural home for users who relied on LocalMonero and want the same function without the custodial risk.

Caveats. P2P means you must vet counterparties and never release escrow before you've genuinely received the fiat — the deposit and arbitrator exist precisely because some counterparties try to cheat. Haveno's safety rests on arbitrator and seed-node integrity; arbitrator-impersonation is the known class of risk on Haveno-style networks, so confirm you're interacting with the legitimate network and arbitrator before committing a trade, and re-evaluate if the operator changes its arbitrator set. Liquidity can be thin at larger sizes or uncommon payment methods. As always, verify the real client download and network details from the operator's signed/canonical sources, not third-party links.

Fees

~1% taker · trade-specific spread · on-chain multisig

Live ops data

kyc.rip hasn't routed swaps through RetoSwap yet, so we have no first-party settlement data (typical XMR settlement, slow-tail, confirmations) for it.

Operator? Request integration: @kyc_rip_bot

Integration status does not affect this provider’s grade or review.

Links

Sourced from operator pages — verify identity via more than one channel before trusting time-sensitive instructions.

Audit trail — receipts for the editorial claim

  • UPSTREAM Up · HTTP 200 · 141ms · checked 55m ago
  • ONION No .onion mirror listed
  • MANUAL Last manual verification 2026-06-24 (<7d)

Reviews — moderated · rules

No community reviews yet. Be the first below.

Add a review

Honest, brand-neutral feedback welcome. A curator approves before it appears here. No JS required.

Required: review body. Honest, descriptive reviews get approved within a day. Marketing copy, slurs, or invective get rejected. Per-day cap of 5 submissions per IP.