xmr.club
EN 中文 ES RU
★ FRONT-PAGECOllie Swap— Anonymous Tor-only swap for BTC, BCH, DASH, LTC, XMR — no accounts, own liquidity, PGP-verified operator identity.
/mixers · verified 2026-07-29

BasicSwap DEX

A-

Particl-led atomic-swap DEX. XMR ↔ BTC / LTC / PART / DASH cross-chain without bridges or wrapped tokens.

Maintainer: BasicSwap DEX

Incident timeline

  1. 2026-07-15 OrangeFren.com (verified X, @OrangeFren) reported at 2026-07-15 00:49Z that BasicSwapDEX was exploited with 0.66 BTC (~$42k) losses confirmed so far. Curator opened incident. basicswapdex.com surface still HTTP 200 at this timestamp; operator-account response not yet visible via curator probe.
  2. 2026-07-15 Operator (@BasicSwapDEX, verified) acknowledged approximately twelve hours before the +1h re-check with an Important Security Notice: 'A swap security issue has been identified and is being fixed. Until the patch is live, withdraw your offers, don't start new swaps, and if you have a swap in progress (especially stalled or near timeout), shut your node down and leave it off.' Follow-up post: 'Don't attempt manual refunds or recovery on your own, and keep your BasicSwap data and wallets intact. Patch and full instructions to follow. The fix will apply automatically when starting your node after updating.'
  3. 2026-07-15 Operator posted the v0.17.2 hardening release approximately nine hours after the acknowledgement: 'BasicSwap v0.17.2 is now out and fixes the security issue detailed in this post. Update now, then it's safe to bring your node back online and post offers again. If you had a swap in progress, update first and let it resume; don't force manual refunds.' Turnaround from OrangeFren-report to shipped fix is approximately 21 hours end-to-end. Curator read: responsible-incident-response pattern — grade movement recommendation is A → A- (mirrors Haveno post-2026-06 demotion). Reader guidance: update to v0.17.2 before restarting any node with an in-progress swap; do not force manual refunds; the patch applies the fix automatically on node restart.
  4. 2026-07-16 +24h re-check. Fresh evidence from the operator's public GitHub release train tightens the timeline meaningfully. Version cadence: v0.17.0 2026-07-09, v0.17.1 2026-07-12 (already a security-hardening release adding false-refund classification defenses + Electrum fee-inflation limits + AEAD key-format migration), v0.17.2 2026-07-14T11:36:50Z (the release that patches the exploit reported publicly by OrangeFren 13 hours later). Root cause per the v0.17.2 release notes: 'Adaptor-sig swaps: track the coin A lock refund tx to blocks_confirmed depth before publishing the lock refund spend tx. The refund spend reveals the leader's key share to the counterparty; publishing it while the refund tx is still unconfirmed could let a released follower recover that share and race both legs of the swap.' Companion hardening: the coin B lock tx must reach spendable depth before the follower broadcasts a chain B lock refund recovery spend. Curator read: the fix was already shipped ~13 hours before OrangeFren's public report on 2026-07-15 00:49Z — the operator disclosed and released in the same window, then OrangeFren picked up the public reporting later. That is meaningfully stronger incident response than 'operator responded within 12 hours of public disclosure' suggested. Loss figure ($42k / 0.66 BTC) unchanged in public sources today — no follow-up figure from OrangeFren visible via curator probe. @BasicSwapDEX X profile bio unchanged; no additional acknowledgement or post-mortem post surfaced today beyond the initial 3-tweet thread already on file. Grade held at A- per curator sign-off 2026-07-15. Reschedule +24h to keep the poll alive.
  5. 2026-07-17 +48h re-check. New release: **v0.17.3 published 2026-07-16T01:27:18Z** — a follow-up hardening release shipped ~14 hours after v0.17.2. Contents: (a) defense-in-depth on the same adaptor-sig swap surface — 'constrain which bid states accept the lock-release, coin-A-lock-signature and lock-spend P2P messages, and reject messages for revoked/inactive offers. Prevents a hostile or replayed peer message from mutating a finished/terminal bid or resurrecting it into an active swap.' This tightens which peer messages can even reach bid-state transitions, adjacent to the v0.17.2 lock-refund key-share race fix. (b) Web UI hardening on a separate attack surface: Host-header allowlist against DNS-rebinding, CSRF check on Origin/Referer as full origin, WebSocket handshake Origin validation against cross-site WebSocket hijack. Curator read: the operator is running a comprehensive audit + follow-up sweep, not treating v0.17.2 as the end of the response. That is the strongest signal I could ask for on a Grade A- listing with an open exploit incident. No new post-mortem or updated loss figure surfaced today; OrangeFren has not published a follow-up visible to curator probe. Loss figure unchanged at 0.66 BTC (~$42k). basicswapdex.com surface still up, no advisory banner on the homepage (which is fine — the response is happening on GitHub + X, not on the marketing surface). Grade held at A-. Reschedule +24h.
  6. 2026-07-18 +72h re-check. Fourth hardening release since the incident opened: **v0.17.4 published 2026-07-16T21:55:43Z** — ~20 hours after v0.17.3. Contents: (a) Particl blind swaps — verify the lock-tx-spend output pays the expected address (another adaptor-swap-adjacent invariant, tightens the same class of validation as v0.17.2 / v0.17.3). (b) Electrum hardening — confirmations Merkle-verified against block header, watch-only balances excluded from spendable balance (defense against a hostile Electrum server misreporting state to the client). (c) Reliability/config fixes — allowed_hosts single-string normalization, AMM Docker htmlhost=0.0.0.0 UI fix, active-swap loop snapshot before iterating, transient RPC-error retry on queued swap actions. (d) CI matrix expanded to run test_coins for Particl blind and Particl anon; pytest suites now fail-fast. Curator read: the release cadence (v0.17.0 → v0.17.4 over 8 days, three of them after the exploit report) is a comprehensive audit sweep, not a one-and-done hotfix. Each release tightens an adjacent validation surface (bid-state message gating in v0.17.3, expected-address invariant in v0.17.4). No post-mortem document has been published yet — root-cause is still just the v0.17.2 release-notes paragraph. Loss figure unchanged at 0.66 BTC (~$42k) per public sources today; OrangeFren has not posted a follow-up visible to curator probe. Grade held at A-. Reschedule +24h.
  7. 2026-07-19 +96h re-check. No new release since v0.17.4 (2026-07-16T21:55:43Z) — approximately 54 hours of release quiet, which is the first sustained pause since the incident opened. Read: the rapid audit-sweep cadence (v0.17.2 / v0.17.3 / v0.17.4 in 34 hours) is settling into a normal cadence. This is a good sign in its own right on a Grade A- listing with an open incident — the emergency-hardening pattern is winding down. basicswapdex.com surface still HTTP 200, no advisory banner (as expected — the response continues to happen on GitHub + X, not on the marketing page). Loss figure unchanged at 0.66 BTC (~$42k). No formal post-mortem document has been published — root-cause is still just the v0.17.2 release-notes paragraph. OrangeFren has not posted a follow-up visible to curator probe. Grade held at A-. Reschedule +24h.
  8. 2026-07-20 +120h re-check. No new release since v0.17.4 (2026-07-16T21:55:43Z) — approximately 78 hours of release quiet, extending the settle-into-normal-cadence signal from Day 5. Second consecutive check without a hardening release confirms the audit sweep has wound down into stable maintenance mode. No post-mortem document has been published — root-cause still just the v0.17.2 release-notes paragraph. Loss figure unchanged at 0.66 BTC (~$42k). OrangeFren has not posted a follow-up visible to curator probe. basicswapdex.com surface still HTTP 200 with no advisory banner (consistent with prior probes — response continues to happen on GitHub + X, not the marketing surface). Grade held at A-. Reschedule +24h.
  9. 2026-07-21 +144h re-check. **NEW: v0.17.5 published 2026-07-20T20:47:14Z** — ~96 hours after v0.17.4, ending the release quiet observed on Days 5-6. Fifth post-incident hardening release. Contents on the adaptor-sig surface: (a) ignore replayed coin-A lock-signature messages + gate the coin-A lock send; (b) re-create purged coin-B lock action after restart; (c) verify and record received lock-release esig even in error states. Networking retries socks/proxy errors as transient. Sub-fee bid fixes (off-by-one on fee verification, UI lockout during processing, prefunded-tx electrum utxo regression). Litecoin PoW scrypt fix, SMSG timeout+paging, Decred prefunded-tx + prepare/mercy tx fixes, AMM autostart under htmlhost=0.0.0.0. Daemon bumps: Bitcoin 29.4 (added alternative PGP key), Dash 23.1.7, Monero 0.18.5.1. Curator read: the release cadence never fully wound down — v0.17.5 continues the audit-sweep pattern with more adaptor-sig defense-in-depth (replay + purge + esig-record hardening) plus a broader fix pass. Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem document. OrangeFren no follow-up. Grade held at A-. Reschedule +24h.
  10. 2026-07-22 +168h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 44 hours of release quiet. Second consecutive check without a hardening release since v0.17.5 shipped. The audit-sweep cadence that spanned v0.17.2 through v0.17.5 (four post-incident releases in 6 days) has now genuinely settled. Loss figure unchanged at 0.66 BTC (~$42k) per public sources. No post-mortem document. OrangeFren has not posted a follow-up visible to curator probe. basicswapdex.com surface HTTP 200, no advisory banner (as expected — response continues on GitHub + X). Grade held at A-. Reschedule +24h.
  11. 2026-07-23 +192h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 67 hours of release quiet, third consecutive quiet-cycle probe. The post-incident audit-sweep cadence (v0.17.2 through v0.17.5 shipping in a 6-day emergency-hardening train) is durably settled into normal maintenance. Loss figure unchanged at 0.66 BTC (~$42k) per public sources. No post-mortem document published — the response continues to live in the release-notes prose for v0.17.2 (root cause) + v0.17.3 through v0.17.5 (defense-in-depth). OrangeFren has not posted a follow-up visible to curator probe. basicswapdex.com surface HTTP 200, no advisory banner (as expected). Grade held at A-. Reschedule +24h.
  12. 2026-07-24 +216h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 91 hours of release quiet, fourth consecutive quiet-cycle probe. The post-incident audit-sweep cadence remains durably settled into normal maintenance since v0.17.5. basicswapdex.com surface HTTP 200 (~40KB, no advisory banner change vs prior probes). Nitter + xcancel mirrors dark this probe — no fresh @BasicSwapDEX post-mortem or @OrangeFren follow-up capturable via curator probe today; primary GitHub signal is the release train, which remains at v0.17.5. Loss figure unchanged at 0.66 BTC (~$42k) per last-known public sources. Grade held at A-. Reschedule +24h.
  13. 2026-07-25 +240h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 116 hours of release quiet, fifth consecutive quiet-cycle probe. basicswapdex.com surface HTTP 200 / ~40 KB, no size drift or banner change from prior probes. X mirror probes remain dark this cycle (nitter + xcancel both bot-blocked from curator vantage in recent probes) — no fresh @BasicSwapDEX post-mortem or @OrangeFren follow-up capturable today; primary GitHub signal is the release train, which remains stable at v0.17.5. Loss figure unchanged at 0.66 BTC (~$42k). Grade held at A-. Reschedule +24h.
  14. 2026-07-26 +264h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 140 hours of release quiet, sixth consecutive quiet-cycle probe. basicswapdex.com surface HTTP 200 / ~40 KB, no size drift or banner change from prior probes. X mirrors dark this cycle (nitter + xcancel bot-blocked); primary GitHub signal remains stable at v0.17.5. Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem published; no OrangeFren follow-up. Note for context: the concurrent OpenMonero incident escalated D → F on 2026-07-25 on the strength of a kycnot.me advisory; that is a separate incident tracked on its own row and does not affect basicswap grading. Grade held at A-. Reschedule +24h.
  15. 2026-07-27 +288h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 164 hours of release quiet, seventh consecutive quiet-cycle probe. basicswapdex.com HTTP 200 / ~40 KB (stable, no drift). Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem, no OrangeFren follow-up. Incident has objectively settled — the 7-day stable-cadence window has now been sustained. Grade held at A-. Reschedule +24h; will surface a wind-down recommendation to the operator on the next cycle.
  16. 2026-07-28 +312h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 188 hours of release quiet, eighth consecutive quiet-cycle probe. basicswapdex.com HTTP 200 / ~40 KB (stable, no drift from any prior probe). Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem, no OrangeFren follow-up. Incident is settled. Grade held at A-. Reschedule +24h — will surface wind-down recommendation again on next cycle.
  17. 2026-07-29 Incident closed. 14-day observation window since 2026-07-15 with responsible operator response (v0.17.2 hardening release shipped ~13h before OrangeFren's public report; four follow-up defense-in-depth releases through v0.17.5 within 6 days; 8 consecutive daily quiet cycles since). Loss figure unchanged at 0.66 BTC (~$42k); no post-mortem published but the release-notes prose across v0.17.2–v0.17.5 documents root-cause + defense-in-depth. Grade held at A- for the incident duration. Daily poll retired; future re-open triggered by event only (fresh @BasicSwapDEX activity, @OrangeFren follow-up, new hardening release, or independent loss report).

At a glance

Grade
A- ()
KYC posture
anonymous signup
Fees
Swap-fee only · adaptor sigs · Particl + Tor coordinator
Last verified
2026-07-29
Operating since
2022 · 4y
Incident
⚠ Active since — /incidents
A- Why grade A-?

B-shape positive signal at A grade — solid posture and likely A, but one element of the A bar (typically operating tenure or a fresh test-trade) is not yet on file.

Full rubric + 7-step verification walkthrough at /methodology.

Review

⚠ INCIDENT (2026-07-15) — patch released. A swap-security exploit was reported publicly at 2026-07-15 00:49Z with ~0.66 BTC ($42k) losses confirmed so far. BasicSwap DEX acknowledged the issue within ~12 hours and shipped v0.17.2 approximately nine hours after that. Update to v0.17.2 before restarting any node. The fix applies automatically on node restart. If you have a swap in progress: update first, let the swap resume, do not force manual refunds. See the Incident block below for the full timeline.

BasicSwap is the *trustless way to swap XMR and BTC* — an open-source desktop DEX that executes genuine cross-chain atomic swaps directly between peers, with no custody, no wrapped tokens, no bridges, and no liquidity pools to drain.

Background. Built since 2022 within the Particl ecosystem, BasicSwap is a *desktop GUI for cross-chain atomic swaps* coordinated peer-to-peer over Tor. Its headline capability — and the reason it matters here — is *native XMR↔BTC* swapping using adaptor signatures, a cryptographic technique that lets two parties trade across chains atomically without either holding the other's coins. That genuinely non-custodial, bridge-free design is why it earns an A in /mixers: it's the rare swap tool whose trust model is "trust the math," not "trust the exchange."

What you trust. Almost nothing beyond the protocol. Swaps are *atomic*: adaptor-signature swaps lock funds such that either the trade completes for both sides or both reclaim their coins — there is *no custody*, no intermediary holding your XMR while it sends BTC. There are *no bridge tokens* (you trade real XMR for real BTC, not a wrapped IOU that can de-peg or rug) and *no liquidity pools* (so no pool to hack or drain — orders are matched peer-to-peer). The whole thing is *open source* and coordinated *over Tor*, so the order-matching layer doesn't expose your network identity. The residual trust is in the protocol's correctness and your counterparty honoring the timelocks — which the atomicity enforces.

Operational specs. A *desktop application* you run yourself (it spins up the relevant chain clients), matching orders *peer-to-peer over Tor* and settling via adaptor-signature atomic swaps. *XMR↔BTC* is the flagship pair, with other coins supported. There's *no account, no KYC* — you're running software and trading directly with peers. Because it's a real P2P market with self-custody, the *order book is smaller* and thinner than a centralized swap, and a swap involves running clients and waiting for on-chain confirmations on both sides. Open-source, self-hosted, part of the Particl stack.

Philosophy. Every centralized swap and most "cross-chain" bridges reintroduce the exact thing crypto was meant to remove: a custodian who holds your funds mid-trade and a honeypot that can be hacked, frozen, or coerced. BasicSwap's thesis is that swapping *XMR↔BTC* — the most privacy-relevant pair — should be *trustless and peer-to-peer*: no exchange to KYC you, no bridge to trust, no pool to drain, just two people and a cryptographic guarantee. Open-sourcing it and running matchmaking over Tor is the only configuration consistent with that goal.

Grade rationale. A in /mixers. The grade reflects genuine non-custodial atomic swaps (no custody, no wrapped tokens, no pools), native XMR↔BTC support, no-account/no-KYC operation, an open-source codebase, and Tor-coordinated peer matching. On trust model it is essentially unmatched in the category. The caveats — liquidity, UX, and the inherent slowness of cross-chain atomic swaps — are the price of that trustlessness, not flaws in the design.

Useful when. Reach for BasicSwap when you want to move between *Bitcoin and Monero without a custodian or a KYC checkpoint* and you're willing to run desktop software and wait for a real cross-chain swap to settle. It's the tool for the privacy-maximalist who refuses to hand XMR to an exchange or trust a bridge token — accept the thinner order book as the cost of a trust model nothing else matches.

Caveats. Liquidity is the honest limitation: a peer-to-peer, self-custody order book is *thinner* than a centralized swap, so you may wait for a counterparty or get worse depth on larger sizes — patience is part of the deal. It's *desktop software you run* (spinning up chain clients, syncing), so there's setup and resource overhead, and cross-chain atomic swaps are *inherently slower* than a custodial instant-swap. As an evolving open-source project the UX is rougher than a polished app, and you should verify you're running the genuine client. None of this dents the A — for *trustless XMR↔BTC*, BasicSwap is the reference tool, with the explicit trade-off that trustlessness costs convenience.

Fees

Swap-fee only · adaptor sigs · Particl + Tor coordinator

Links

Sourced from operator pages — verify identity via more than one channel before trusting time-sensitive instructions.

Audit trail — receipts for the editorial claim

  • UPSTREAM Up · HTTP 200 · 2077ms · checked 19h ago
  • ONION No .onion mirror listed
  • MANUAL Last manual verification 2026-07-29 (<30d)

Reviews — moderated · rules

No community reviews yet. Be the first below.

Add a review

Honest, brand-neutral feedback welcome. A curator approves before it appears here. No JS required.

Required: review body. Honest, descriptive reviews get approved within a day. Marketing copy, slurs, or invective get rejected. Per-day cap of 5 submissions per IP.