xmr.club
EN 中文 ES RU
★ FRONT-PAGECOllie Swap— Anonymous Tor-only swap for BTC, BCH, DASH, LTC, XMR — no accounts, own liquidity, PGP-verified operator identity.
/mixers · 已驗證 2026-07-29

BasicSwap DEX

A-

原子互換 DEX — XMR / BTC / LTC / PIVX 等之間直接鏈上換。

維護者: BasicSwap DEX

事件時間線

  1. 2026-07-15 OrangeFren.com (verified X, @OrangeFren) reported at 2026-07-15 00:49Z that BasicSwapDEX was exploited with 0.66 BTC (~$42k) losses confirmed so far. Curator opened incident. basicswapdex.com surface still HTTP 200 at this timestamp; operator-account response not yet visible via curator probe.
  2. 2026-07-15 Operator (@BasicSwapDEX, verified) acknowledged approximately twelve hours before the +1h re-check with an Important Security Notice: 'A swap security issue has been identified and is being fixed. Until the patch is live, withdraw your offers, don't start new swaps, and if you have a swap in progress (especially stalled or near timeout), shut your node down and leave it off.' Follow-up post: 'Don't attempt manual refunds or recovery on your own, and keep your BasicSwap data and wallets intact. Patch and full instructions to follow. The fix will apply automatically when starting your node after updating.'
  3. 2026-07-15 Operator posted the v0.17.2 hardening release approximately nine hours after the acknowledgement: 'BasicSwap v0.17.2 is now out and fixes the security issue detailed in this post. Update now, then it's safe to bring your node back online and post offers again. If you had a swap in progress, update first and let it resume; don't force manual refunds.' Turnaround from OrangeFren-report to shipped fix is approximately 21 hours end-to-end. Curator read: responsible-incident-response pattern — grade movement recommendation is A → A- (mirrors Haveno post-2026-06 demotion). Reader guidance: update to v0.17.2 before restarting any node with an in-progress swap; do not force manual refunds; the patch applies the fix automatically on node restart.
  4. 2026-07-16 +24h re-check. Fresh evidence from the operator's public GitHub release train tightens the timeline meaningfully. Version cadence: v0.17.0 2026-07-09, v0.17.1 2026-07-12 (already a security-hardening release adding false-refund classification defenses + Electrum fee-inflation limits + AEAD key-format migration), v0.17.2 2026-07-14T11:36:50Z (the release that patches the exploit reported publicly by OrangeFren 13 hours later). Root cause per the v0.17.2 release notes: 'Adaptor-sig swaps: track the coin A lock refund tx to blocks_confirmed depth before publishing the lock refund spend tx. The refund spend reveals the leader's key share to the counterparty; publishing it while the refund tx is still unconfirmed could let a released follower recover that share and race both legs of the swap.' Companion hardening: the coin B lock tx must reach spendable depth before the follower broadcasts a chain B lock refund recovery spend. Curator read: the fix was already shipped ~13 hours before OrangeFren's public report on 2026-07-15 00:49Z — the operator disclosed and released in the same window, then OrangeFren picked up the public reporting later. That is meaningfully stronger incident response than 'operator responded within 12 hours of public disclosure' suggested. Loss figure ($42k / 0.66 BTC) unchanged in public sources today — no follow-up figure from OrangeFren visible via curator probe. @BasicSwapDEX X profile bio unchanged; no additional acknowledgement or post-mortem post surfaced today beyond the initial 3-tweet thread already on file. Grade held at A- per curator sign-off 2026-07-15. Reschedule +24h to keep the poll alive.
  5. 2026-07-17 +48h re-check. New release: **v0.17.3 published 2026-07-16T01:27:18Z** — a follow-up hardening release shipped ~14 hours after v0.17.2. Contents: (a) defense-in-depth on the same adaptor-sig swap surface — 'constrain which bid states accept the lock-release, coin-A-lock-signature and lock-spend P2P messages, and reject messages for revoked/inactive offers. Prevents a hostile or replayed peer message from mutating a finished/terminal bid or resurrecting it into an active swap.' This tightens which peer messages can even reach bid-state transitions, adjacent to the v0.17.2 lock-refund key-share race fix. (b) Web UI hardening on a separate attack surface: Host-header allowlist against DNS-rebinding, CSRF check on Origin/Referer as full origin, WebSocket handshake Origin validation against cross-site WebSocket hijack. Curator read: the operator is running a comprehensive audit + follow-up sweep, not treating v0.17.2 as the end of the response. That is the strongest signal I could ask for on a Grade A- listing with an open exploit incident. No new post-mortem or updated loss figure surfaced today; OrangeFren has not published a follow-up visible to curator probe. Loss figure unchanged at 0.66 BTC (~$42k). basicswapdex.com surface still up, no advisory banner on the homepage (which is fine — the response is happening on GitHub + X, not on the marketing surface). Grade held at A-. Reschedule +24h.
  6. 2026-07-18 +72h re-check. Fourth hardening release since the incident opened: **v0.17.4 published 2026-07-16T21:55:43Z** — ~20 hours after v0.17.3. Contents: (a) Particl blind swaps — verify the lock-tx-spend output pays the expected address (another adaptor-swap-adjacent invariant, tightens the same class of validation as v0.17.2 / v0.17.3). (b) Electrum hardening — confirmations Merkle-verified against block header, watch-only balances excluded from spendable balance (defense against a hostile Electrum server misreporting state to the client). (c) Reliability/config fixes — allowed_hosts single-string normalization, AMM Docker htmlhost=0.0.0.0 UI fix, active-swap loop snapshot before iterating, transient RPC-error retry on queued swap actions. (d) CI matrix expanded to run test_coins for Particl blind and Particl anon; pytest suites now fail-fast. Curator read: the release cadence (v0.17.0 → v0.17.4 over 8 days, three of them after the exploit report) is a comprehensive audit sweep, not a one-and-done hotfix. Each release tightens an adjacent validation surface (bid-state message gating in v0.17.3, expected-address invariant in v0.17.4). No post-mortem document has been published yet — root-cause is still just the v0.17.2 release-notes paragraph. Loss figure unchanged at 0.66 BTC (~$42k) per public sources today; OrangeFren has not posted a follow-up visible to curator probe. Grade held at A-. Reschedule +24h.
  7. 2026-07-19 +96h re-check. No new release since v0.17.4 (2026-07-16T21:55:43Z) — approximately 54 hours of release quiet, which is the first sustained pause since the incident opened. Read: the rapid audit-sweep cadence (v0.17.2 / v0.17.3 / v0.17.4 in 34 hours) is settling into a normal cadence. This is a good sign in its own right on a Grade A- listing with an open incident — the emergency-hardening pattern is winding down. basicswapdex.com surface still HTTP 200, no advisory banner (as expected — the response continues to happen on GitHub + X, not on the marketing page). Loss figure unchanged at 0.66 BTC (~$42k). No formal post-mortem document has been published — root-cause is still just the v0.17.2 release-notes paragraph. OrangeFren has not posted a follow-up visible to curator probe. Grade held at A-. Reschedule +24h.
  8. 2026-07-20 +120h re-check. No new release since v0.17.4 (2026-07-16T21:55:43Z) — approximately 78 hours of release quiet, extending the settle-into-normal-cadence signal from Day 5. Second consecutive check without a hardening release confirms the audit sweep has wound down into stable maintenance mode. No post-mortem document has been published — root-cause still just the v0.17.2 release-notes paragraph. Loss figure unchanged at 0.66 BTC (~$42k). OrangeFren has not posted a follow-up visible to curator probe. basicswapdex.com surface still HTTP 200 with no advisory banner (consistent with prior probes — response continues to happen on GitHub + X, not the marketing surface). Grade held at A-. Reschedule +24h.
  9. 2026-07-21 +144h re-check. **NEW: v0.17.5 published 2026-07-20T20:47:14Z** — ~96 hours after v0.17.4, ending the release quiet observed on Days 5-6. Fifth post-incident hardening release. Contents on the adaptor-sig surface: (a) ignore replayed coin-A lock-signature messages + gate the coin-A lock send; (b) re-create purged coin-B lock action after restart; (c) verify and record received lock-release esig even in error states. Networking retries socks/proxy errors as transient. Sub-fee bid fixes (off-by-one on fee verification, UI lockout during processing, prefunded-tx electrum utxo regression). Litecoin PoW scrypt fix, SMSG timeout+paging, Decred prefunded-tx + prepare/mercy tx fixes, AMM autostart under htmlhost=0.0.0.0. Daemon bumps: Bitcoin 29.4 (added alternative PGP key), Dash 23.1.7, Monero 0.18.5.1. Curator read: the release cadence never fully wound down — v0.17.5 continues the audit-sweep pattern with more adaptor-sig defense-in-depth (replay + purge + esig-record hardening) plus a broader fix pass. Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem document. OrangeFren no follow-up. Grade held at A-. Reschedule +24h.
  10. 2026-07-22 +168h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 44 hours of release quiet. Second consecutive check without a hardening release since v0.17.5 shipped. The audit-sweep cadence that spanned v0.17.2 through v0.17.5 (four post-incident releases in 6 days) has now genuinely settled. Loss figure unchanged at 0.66 BTC (~$42k) per public sources. No post-mortem document. OrangeFren has not posted a follow-up visible to curator probe. basicswapdex.com surface HTTP 200, no advisory banner (as expected — response continues on GitHub + X). Grade held at A-. Reschedule +24h.
  11. 2026-07-23 +192h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 67 hours of release quiet, third consecutive quiet-cycle probe. The post-incident audit-sweep cadence (v0.17.2 through v0.17.5 shipping in a 6-day emergency-hardening train) is durably settled into normal maintenance. Loss figure unchanged at 0.66 BTC (~$42k) per public sources. No post-mortem document published — the response continues to live in the release-notes prose for v0.17.2 (root cause) + v0.17.3 through v0.17.5 (defense-in-depth). OrangeFren has not posted a follow-up visible to curator probe. basicswapdex.com surface HTTP 200, no advisory banner (as expected). Grade held at A-. Reschedule +24h.
  12. 2026-07-24 +216h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 91 hours of release quiet, fourth consecutive quiet-cycle probe. The post-incident audit-sweep cadence remains durably settled into normal maintenance since v0.17.5. basicswapdex.com surface HTTP 200 (~40KB, no advisory banner change vs prior probes). Nitter + xcancel mirrors dark this probe — no fresh @BasicSwapDEX post-mortem or @OrangeFren follow-up capturable via curator probe today; primary GitHub signal is the release train, which remains at v0.17.5. Loss figure unchanged at 0.66 BTC (~$42k) per last-known public sources. Grade held at A-. Reschedule +24h.
  13. 2026-07-25 +240h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 116 hours of release quiet, fifth consecutive quiet-cycle probe. basicswapdex.com surface HTTP 200 / ~40 KB, no size drift or banner change from prior probes. X mirror probes remain dark this cycle (nitter + xcancel both bot-blocked from curator vantage in recent probes) — no fresh @BasicSwapDEX post-mortem or @OrangeFren follow-up capturable today; primary GitHub signal is the release train, which remains stable at v0.17.5. Loss figure unchanged at 0.66 BTC (~$42k). Grade held at A-. Reschedule +24h.
  14. 2026-07-26 +264h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 140 hours of release quiet, sixth consecutive quiet-cycle probe. basicswapdex.com surface HTTP 200 / ~40 KB, no size drift or banner change from prior probes. X mirrors dark this cycle (nitter + xcancel bot-blocked); primary GitHub signal remains stable at v0.17.5. Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem published; no OrangeFren follow-up. Note for context: the concurrent OpenMonero incident escalated D → F on 2026-07-25 on the strength of a kycnot.me advisory; that is a separate incident tracked on its own row and does not affect basicswap grading. Grade held at A-. Reschedule +24h.
  15. 2026-07-27 +288h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 164 hours of release quiet, seventh consecutive quiet-cycle probe. basicswapdex.com HTTP 200 / ~40 KB (stable, no drift). Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem, no OrangeFren follow-up. Incident has objectively settled — the 7-day stable-cadence window has now been sustained. Grade held at A-. Reschedule +24h; will surface a wind-down recommendation to the operator on the next cycle.
  16. 2026-07-28 +312h re-check. No new release since v0.17.5 (2026-07-20T20:47:14Z) — approximately 188 hours of release quiet, eighth consecutive quiet-cycle probe. basicswapdex.com HTTP 200 / ~40 KB (stable, no drift from any prior probe). Loss figure unchanged at 0.66 BTC (~$42k). No post-mortem, no OrangeFren follow-up. Incident is settled. Grade held at A-. Reschedule +24h — will surface wind-down recommendation again on next cycle.
  17. 2026-07-29 Incident closed. 14-day observation window since 2026-07-15 with responsible operator response (v0.17.2 hardening release shipped ~13h before OrangeFren's public report; four follow-up defense-in-depth releases through v0.17.5 within 6 days; 8 consecutive daily quiet cycles since). Loss figure unchanged at 0.66 BTC (~$42k); no post-mortem published but the release-notes prose across v0.17.2–v0.17.5 documents root-cause + defense-in-depth. Grade held at A- for the incident duration. Daily poll retired; future re-open triggered by event only (fresh @BasicSwapDEX activity, @OrangeFren follow-up, new hardening release, or independent loss report).

一覽

等級
A- ()
KYC 立場
匿名註冊
手續費
Swap-fee only · adaptor sigs · Particl + Tor coordinator
最後驗證
2026-07-29
營運起始
2022 · 4y
事件
⚠ 活躍自 — /incidents
A- 為什麼是 A- 級?

B-shape positive signal at A grade — solid posture and likely A, but one element of the A bar (typically operating tenure or a fresh test-trade) is not yet on file.

完整細則 + 7 步驗證流程見 /methodology.

評測

BasicSwap 是*無需信任來交換 XMR 和 BTC 的方式*——一個開源的桌面 DEX,執行真正的跨鏈原子交換,直接在對等節點之間進行,無需託管、無包裝代幣、無橋接、無可被耗盡的流動性池。

背景。 自 2022 年在 Particl 生態系統中建立,BasicSwap 是一個*跨鏈原子交換的桌面 GUI*,透過 Tor 在對等節點之間協調。其頭條能力——以及它在此處重要的原因——是使用*適配器簽章*進行原生的 *XMR↔BTC* 交換,這種密碼學技術讓雙方能夠原子地跨鏈交易,而無需任何一方持有對方的幣。這種真正非託管、無橋接的設計,是它在 /mixers 中獲得 A 級評價的原因:它是那種罕見的交換工具,其信任模型是「信任數學」,而非「信任交易所」。

你信任什麼。 除了協議之外幾乎什麼都不必信任。交換是*原子的*:適配器簽章交換鎖定資金,使得要麼交易對雙方完成,要麼雙方回收自己的幣——*沒有託管*,沒有中介在發送 BTC 時持有你的 XMR。*沒有橋接代幣*(你用真實的 XMR 交易真實的 BTC,而不是一個可能脫鉤或被 rug 的包裝 IOU),也*沒有流動性池*(因此沒有可以被駭或耗盡的池——訂單是對等節點匹配的)。整個東西是*開源的*,並且*透過 Tor* 協調,因此訂單匹配層不會暴露你的網路身分。剩餘的信任在於協議的正確性以及你的對手方尊重時間鎖——而原子性強制執行這一切。

操作規格。 一個*桌面應用程式*,你可以自行運行(它會啟動相關鏈的客戶端),透過 *Tor 進行對等節點匹配*訂單,並透過適配器簽章原子交換進行結算。*XMR↔BTC* 是旗艦交易對,其他幣種也支援。*沒有帳號、沒有 KYC*——你正在運行軟體並直接與對等節點交易。因為它是一個真正的、具有自我託管的 P2P 市場,*訂單簿較小*且比中心化交易所更薄,而一次交換涉及運行客戶端並等待兩側的鏈上確認。開源、自託管,屬於 Particl 堆疊的一部分。

哲學。 每個中心化交易所和大多數「跨鏈」橋接,重新引入了加密貨幣本應消除的確切事物:一個在交易中持有你資金的中介,和一個可以被駭、凍結或強制的蜜罐。BasicSwap 的論點是,交換 *XMR↔BTC*——最與隱私相關的交易對——應該是*無需信任且點對點的*:沒有交易所對你進行 KYC,沒有橋接需要信任,沒有池可以被耗盡,只有兩個人和一個密碼學保證。開源並透過 Tor 運行匹配系統,是唯一與該目標一致的配置。

評級理由。 在 /mixers 中獲得 A。該評級反映了真正非託管的原子交換(無託管、無包裝代幣、無池)、原生 XMR↔BTC 支援、無帳號/無 KYC 操作、開源程式碼庫,以及透過 Tor 協調的對等節點匹配。在信任模型上,它本質上是該類別中無與倫比的。注意事項——流動性、UX 和跨鏈原子交換的固有緩慢——是那種無需信任性的代價,而非設計缺陷。

適用場景。 當你想要在*比特幣和門羅幣之間移動,無需託管人或 KYC 檢查站*,並且願意運行桌面軟體並等待真正的跨鏈交換結算時,使用 BasicSwap。對於拒絕將 XMR 交給交易所或信任橋接代幣的隱私極致主義者來說,它是合適的工具——接受較薄的訂單簿作為一個無其他工具可匹配的信任模型的代價。

注意事項。 流動性是誠實的限制:一個點對點、自我託管的訂單簿比中心化交易所*更薄*,因此你可能需要等待對手方,或在較大規模時獲得較差的深度——耐心是交易的一部分。它是*你運行的桌面軟體*(啟動鏈客戶端、同步),因此有設置和資源開銷,而且跨鏈原子交換*本質上比託管的即時交換更慢*。作為一個不斷發展的開源專案,UX 比精緻的應用更粗糙,你應該驗證你正在運行的是正版客戶端。這些都不削弱 A 級評價——對於*無需信任的 XMR↔BTC*,BasicSwap 是參考工具,以明確的取捨為代價:無需信任性以便利性為成本。

手續費

Swap-fee only · adaptor sigs · Particl + Tor coordinator

連結

取自營運方頁面 — 信任時效性指示前,請從多個管道交叉驗證身份。

稽核軌跡 — 編輯主張的收據

  • UPSTREAM 正常 · HTTP 200 · 2077ms · 檢查於 20h ago
  • ONION 未列出 .onion 鏡像
  • MANUAL 最後手動驗證 2026-07-29 (<30d)

評論 — 已審核 · 規則

尚無社群評論。當第一個。

新增評論

歡迎誠實、中立的回饋。策展人審核後才會顯示。不需 JS。

必填:評論內容。誠實、具描述性的評論一天內核可。行銷文案、辱罵或攻擊會被退件。每 IP 每日上限 5 筆。