Skip to content
CryptoDecentral

Note

An Anonymity Set Is Not a Ring Size

An anonymity set is the group of candidates an observer cannot tell apart, not the count of candidates a transaction names.

2026-10-07 · privacy, monero, zcash, ring-signatures, fcmp, ironwood, orchard, halo2, nullifiers, anonymity-sets, ospead, civil-liberties, protocol-literacy

Dark CryptoDecentral hex mesh: on the left a small bronze ring of sixteen hexagonal nodes, one faintly brighter; on the right a vast teal field of points like a pool; a faint arc between them; no text.

On 5 October 2026, Sooraj (@iAnonymous3000) posted a long explanation of why his Tools directory lists Zcash and not Monero. His scope was narrow: hiding which earlier coin a transaction spends, Monero as it runs today versus a fully shielded transfer inside Zcash's newest pool, Ironwood. He said FCMP++ deserves a fresh look once deployed, and asked both sides for corrections.

We use the post as a prompt, not an authority, and do not grade his choice. It is useful because it names what most coin arguments skip: the number on the box is not the number that protects you.

Thesis, stated once: an anonymity set is the group of candidates an observer cannot tell apart, not the count of candidates a transaction names. A ring of 16 whose members are statistically distinguishable protects less than 16. A pool proof with no visible candidate list can still leak through fees, timing, amounts at pool boundaries, and a thin crowd. Compare designs by three questions: what does it prove, what does it still expose, and what can you check yourself? Educational only.

Monero today: a ring of 16 and a model of time

What it proves. Since the August 2022 network upgrade (v0.18, block 2,688,888), every Monero input carries a ring of exactly 16: the real output plus 15 decoys drawn from the chain. The ring signature proves that one of the 16 is being spent by its owner, and a key image stops that output from being spent twice, without revealing which member it was. Fixed size stops anyone fingerprinting themselves with an unusual number.

What it leaks. Decoys only work if they look like real spends, and the strongest signal is age. The standard wallet draws decoys from an age distribution fitted to data from Monero's early years. Rucknium, a Monero Research Lab researcher, built OSPEAD, funded through the community's CCS, to estimate real-spend ages directly from on-chain ring data. Its preliminary estimate: against rings built with the default decoy selection since the August 2022 fork, an adversary who always bets on the most likely ring member (the "MAP decoder" attack) is right about 23.5% of the time on average, versus 6.25% for a random pick. That is an "effective ring size" of about 4.2 (OSPEAD-docs, ch. 13).

Read the number precisely: it is the average hit rate of a best guess, not a tracing tool. The guess is still wrong about three times in four, and the observer usually cannot tell which guesses landed. The getmonero.org write-up notes the research is not yet formally peer-reviewed and frames the risk mainly for extreme threat models, especially when combined with other heuristics. OSPEAD also proposes a better-fitted decoy distribution (estimated 7.6%), safest to deploy only at a hard fork; the fork now planned is FCMP++, which removes on-chain rings instead.

Beside the decoy problem, input counts, output counts and fees are public, and wallets that select decoys differently are themselves distinguishable.

Zcash shielded: one pool, a nullifier, a proof

What it proves. In a fully shielded transfer, each spend proves in zero knowledge that the note exists in the pool's note-commitment tree as of an earlier anchor, that the spender holds its key, and that values balance. It publishes a nullifier, a tag derived from the note and the owner's key, so the same note cannot be spent twice, while outsiders cannot link the nullifier back to the note. No candidate list appears on chain for anyone to rank.

The proof system is Halo 2. ZIP 224, which introduced Orchard, gives the reason: Sprout and Sapling used Groth16, which needs a trusted setup ceremony, while Orchard moved to a system that requires none.

Ironwood is real, and new. It is the shielded pool created by the NU6.3 upgrade, activated on mainnet at block 3,428,143 on 28 July 2026 (ZIP 258). According to the Ironwood Book, it reuses the Orchard protocol (action shape, keys, Halo 2 circuit) but keeps its own note-commitment tree, nullifier set and value balance. It followed a soundness flaw in Orchard that was disclosed and patched earlier in 2026. Orchard is now sealed: value can leave but not enter, and exits pass a turnstile so supply can be checked at the boundary.

What it leaks. "The whole pool" is a moving target, and Ironwood's started empty on 28 July. ZIP 224 says this plainly for Orchard: each new pool is a separate anonymity set that starts empty. Value crossing a pool boundary (transparent to shielded, Orchard to Ironwood) reveals its amount on chain. That is why ZIP 318 spends pages on migration hygiene: canonical denominations, randomised scheduling, shared anchors, Tor or Nym prompts. Fees, timing and action counts stay visible. Most ZEC also sits outside shielded pools. The third-party tracker ZecStats, summing consensus value-pool balances, put about 29% of issued ZEC in shielded pools and about 70% transparent on 6 October 2026, and warns that a balance is not a user count.

FCMP++: the whole chain, not yet

What it proves (on paper). FCMP++ replaces rings with a proof that the spent output is one of the outputs in a curve-tree accumulator over the chain, with separate spend authorisation and linkability so double spends stay impossible. The current beta release describes this as proving ownership of one of "150 million+" outputs rather than one of 16. Different protocol, different membership set. Our explainer covers the cryptography: From Rings of 16 to the Whole Chain.

Status as of 6 October 2026. It is not on mainnet. Beta stressnet v3.0, published 25 September, was scheduled to fork from testnet on 5 October at block 3,102,800. Hardware wallets, multisig and transaction proofs are listed as not yet working. At the 16 September Monero Research Lab meeting, developers said the bottleneck was finishing and merging code, while a second independent circuit audit was being commissioned. None of the primary sources we checked announce a mainnet date.

What it won't fix. Fees, timing, input and output counts, and network metadata remain. OSPEAD's README notes decoys may survive in one corner: shielding a wallet from a spying remote node. And a stressnet is not a privacy tool; its release notes warn the node anonymity set is "in the dozens at best."

The leaks no membership proof touches

What the three designs share outlasts how they differ:

  • Fees: amounts and fee policy can fingerprint wallets.
  • Timing: when coins arrive, wait, and move.
  • Shape: input and output counts in Monero; action counts in Zcash.
  • Boundaries: crossings between transparent and shielded, or between pools, reveal amounts.
  • Crowd size: a perfect proof over a quiet set still protects few people.
  • Infrastructure: IP addresses, remote nodes, light-wallet servers.
  • Behaviour: consolidating coins, round numbers, predictable schedules.
DesignWhat a spend provesMain residual leakStatus (6 Oct 2026)
Monero ringsone of 16 named outputsdecoy-age model (OSPEAD preliminary: 23.5% best guess)live since Aug 2022
Zcash Ironwooda note somewhere in this poolpool crossings, young set, fees and timinglive since 28 Jul 2026
FCMP++one of the chain's outputs (150M+, per developers)fees, timing, counts, networkbeta stressnet

For journalists, organisers, and ordinary people under ambient financial surveillance, these residuals often matter more than the headline cryptography. A proof can do exactly what its spec says while habits undo it.

What you can verify yourself

  • Read OSPEAD's results, code and caveats, not just the quoted number.
  • Read ZIPs 224, 258 and 318 and the Ironwood Book; confirm the activation height on a node you run.
  • Check FCMP++ status on the seraphis-migration release page and MRL logs. Don't take dates from a timeline post, this one included.
  • Read pool balances from consensus value-pool data (ZIP 209), and note which pools a tracker counts.
  • Know who runs your node, whether your wallet uses Tor, and when a send crosses a boundary.

What this is not

This note is not a ranking, a "best privacy coin" verdict, or a reason to buy, sell or hold anything. It quotes no prices or market data. It is not a wallet, exchange or custody guide. It does not claim Monero is traceable or Zcash untraceable. It does not treat a preliminary statistical estimate as deanonymisation, and it does not promise FCMP++ on any date. No evasion guidance.

Educational takeaway: ask what a design proves, what it still exposes, and who else is in the crowd. Ring size counts names. A pool proof removes the list but inherits the pool's age and boundaries. FCMP++ aims at the whole chain and isn't here yet. Re-compare when it is.

Related on CryptoDecentral

Further reading (primary)

All notes