xmr.club
EN 中文 ES RU
← back home
accountability ledger · facts only · source-linked

Shamelist

A facts-only watchlist of listed providers with documented concerns. Every entry is backed by a source URL, a curator-set chip, or a logged policy-change diff. No interpretive editorial — only signals you can verify yourself. A provider being here is a caution flag, not a verdict; read the receipt and decide.

Recent downgrade 12

Curator lowered this provider's grade after a documented incident or posture change. The source is the receipt.

F XMR Escrow /tools 2026-08-05

evidence C → F — Active exit-scam by verified xmrescrow.app operator. Victim reported $6,000 BTC loss (3 on-chain txids verified on mempool.space). Operator identity confirmed as @xmrescrow on X via documented DM history with xmr.club (screenshots on file, operator engaged with our C-rating listing + ran "official updates" against our critiques + discussed roadmap). Operator identifier "TT" independently corroborated by GitHub org display name (xmrescro reads "tt"). Coincident operator-flight signals: X account deleted, GitHub "Contact: XMPP only; drop ref" whitewash commit, /about page reactively added "no social media" disclaimer contradicting the DM history. Site still taking new escrows at time of demotion — active harm surface. Evidence preserved to Internet Archive 2026-08-05. source →

C FixedFloat /exchanges 2026-08-04

evidence B- → C — Operator quietly moved legal entity from FFX Group Ltd (Marshall Islands) to FFGX Group LLC (Kutaisi, Georgia) — ToS updated 2026-08-02, no announcement on site/blog/X. Same precedent as BitcoinVN 2026-07-30 shell-shift downgrade. source →

C StealthEX /exchanges 2026-07-30

evidence A → C — First-party verified shotgun-KYC event 2026-07-30: on a swap >$10k the operator sent the user a KYC-verification link mid-flow, contradicting the previously-marketed "Anonymous" posture. Operator explanation the trigger was "LE-flagged funds" — structurally unverifiable, and the trigger logic is not published, so the user experience is operationally identical to threshold-triggered shotgun-KYC (no way to predict pre-deposit whether a swap will land in the KYC pipeline). Grade A per methodology requires the marketed posture to hold up end-to-end; the >$10k trigger + undisclosed detection logic breaks that. Not F/D because sub-threshold swaps do work and the operator explanation is plausible (chain-analysis flagging is a real category), just unverifiable. C reflects: acceptable for <$10k swaps with the caveat clearly named; not acceptable for larger amounts if anonymity is the requirement. source →

C ETZ-Swap /exchanges 2026-07-29

evidence A → C — Three signals stacked without any first-party counter-evidence: (a) OrangeFren.com public tweet 2026-07-28 attributing an operator-cluster affiliation grouping etz-swap with BitXchange / Explace / MIXED / NeverKYC / OctoSwap / PegasusSwap; (b) operator silence — three renewal outreach messages (10, 14, 16 July) all delivered, none answered, while operator remained actively online on TG (last-seen minutes-old); (c) kyc.rip integration partnership request (14 July) also unanswered, so no clean-operation first-party evidence will materialize. None of these alone would demote; together they remove the trust weight that supported an A grade. C reflects "acceptable with the above reservations named." Not F — no independent scam evidence for etz-swap itself; the cluster attribution is suggestive, not conclusive. Source: https://twitter.com/OrangeFren source →

F OctoSwap /exchanges 2026-07-29

evidence D → F — Escalation trigger noted at the 2026-07-26 +7d re-check ("OF publishing hash evidence or public cluster attribution") is now met. OrangeFren.com published a tweet on 2026-07-28 formally attributing OctoSwap to an operator-cluster (BitXchange / ETZ-Swap / Explace / MIXED / NeverKYC / PegasusSwap) — a stronger public statement than the earlier delist + network-analysis note. Combined with the pre-existing signals — Trvoid Bitcointalk $30k loss report (2026-07-18), OrangeFren delist and operator-denial-on-record (2026-07-19), kycnot.me AI-summary warning about processing delays and unresponsive support — this crosses from "acceptable with reservations" (D) to "do not deposit" (F). No user-side tx-hash surfaced from the victim; no on-chain drain evidence at hide-cash-tier detail — F is warranted on the aggregated peer-directory attribution weight, not on independent on-chain forensics. Source: https://twitter.com/OrangeFren source →

F OpenMonero /exchanges 2026-07-25

evidence D → F — Escalation from D on the strength of the 2026-07-24 kycnot.me advisory: a Monero Matrix Channel user disclosed a login-API endpoint vulnerability that allowed sequential account takeover via a single GET request (oldest → newest), with claims that admins chose to remain silent and are actively ignoring a similar unpatched vulnerability. Reported consequences: drained accounts, leaked trading histories, exfiltrated shipping addresses and private chat logs. Operator X account (@OpenMonero) has posted nothing since 2026-06-08 ("OpenMonero is Back!" — a claim our own timeline already documents as only partially true). Combined pattern — repeat compromise (May & June 2026) + new API-driven mass-compromise class + persistent operator silence during a known active-exploit window — is the trust break behind F. Do not deposit; withdraw anything still accessible. source →

A- Wagyu /exchanges 2026-07-07

evidence B- → D — 18-day operator X silence since 2026-06-19 while remaining publicly active on Hyperliquid memecoin side; third-party swap-widget outage report on 2026-07-07 ("Failed to fetch"). Product is operationally unreliable AND operator unreachable via public channels — the exchange thesis (custodial risk bounded by attentive operator) does not hold in this state. No fund-loss evidence; the D reflects unreliability + unreachability, not fraud. source →

A- Haveno /exchanges 2026-06-17

evidence A → A- — Two distinct trade-protocol exploits within 30 days against the Haveno surface. May 2026: arbitrator-substitution / fake-arbitrator-ACK on the arbitrator-selection step. June 2026: forced-arbitration-flow abuse — XMR releases after 30 confirmations even when BTC was never sent and the arbitrator is honest. Operators (RetoSwap and others) responded correctly — banned attackers, halted trading, broadcast PSAs — but user-facing risk is structural until a hardened trade-protocol ships. Revisit if the next ~60 days are incident-free after a structural fix.

A- Njalla Domains /email 2026-06-14

evidence A → A- — Trust posture softened after the silent Q4 2024 jurisdictional move from Nevis to Costa Rica — no customer announcement, weaker offshore offsets, take-it-or-leave-it response from support, founder profiles dormant in the same window. Mirrors the 1984.is precedent: opacity is treated as a permanent grade input even when no malicious behaviour is documented.

A- Njalla VPS /hosting 2026-06-14

evidence A → A- — Trust posture softened after the silent Q4 2024 jurisdictional move from Nevis to Costa Rica — no customer announcement, weaker offshore offsets, take-it-or-leave-it response from support, founder profiles dormant in the same window. Mirrors the 1984.is precedent: opacity is treated as a permanent grade input even when no malicious behaviour is documented.

B- Njalla VPN /vpns 2026-06-14

evidence B → B- — Trust posture softened after the silent Q4 2024 jurisdictional move from Nevis to Costa Rica — no customer announcement, weaker offshore offsets, take-it-or-leave-it response from support, founder profiles dormant in the same window. Mirrors the 1984.is precedent: opacity is treated as a permanent grade input even when no malicious behaviour is documented.

A- 1984.is /hosting RESOLVED 2026-06-07

evidence A → A- — Pattern of no-notice service suspensions. 1984.is shut down Hack Liberty — a 4+ year customer with a clearly visible abuse-reporting mechanism and explicit anti-abuse ToS — without warning or a chance to respond (Mar 31, 2026), then auto-suspended a legal Monero marketplace (XmrBazaar) on weaponized DMCA complaints (Jun 2026). XmrBazaar was restored after public pushback, but two no-notice takedowns of legal privacy projects is a permanent record. source →

Credibility chip 3

Curator set a credibility flag after specific documented evidence. The chip is the receipt.

C FixedFloat /exchanges 2026-08-04

evidence KYC forced on AML dispute

A- Wagyu /exchanges 2026-07-22

evidence Hype-aligned operator

A- Exolix /exchanges 2026-05-31

evidence Partner-API data leak (2026)

What's on this listinclusion rules

Not on this list editorial opinions, single user complaints, predictions, or smear claims. We add only what we can defend with a link or a chip backed by curator-logged evidence.