For everyone who keeps asking why I am adding @Zcash but not @monero to my Tools directory - here is my response.
For h | Hanami
For everyone who keeps asking why I am adding @Zcash but not @monero to my Tools directory - here is my response.
For hiding which earlier coins a transaction spends, I prefer Ironwood's design to Monero's current ring signatures. I am comparing Monero as it runs today with a fully shielded transfer that stays inside Zcash's Ironwood pool.
Monero hides each input among 16 ring members: the real output being spent and 15 other outputs used as decoys. The ages of those decoys need to resemble actual spending patterns. OSPEAD research (funded by the Monero community) found a mismatch between the two distributions.
Its preliminary estimate is that an adversary's best guess is right about 23.5% of the time on average, roughly 1 in 4.2, rather than the 6.25% of random guessing. The observer usually cannot confirm which guesses were right, and the best guess is still wrong most of the time. But the estimated hit rate is nearly 4 times random guessing.
Ironwood works differently. A spend proves the coin exists somewhere in the Ironwood pool, that the spender holds its key, and that the amounts add up, all without revealing which coin it was. The proof uses Halo 2, which needs no trusted setup. Each spend also publishes a nullifier, a unique tag that stops double spending without pointing back to the coin.
That leaves no list of candidates for decoy age analysis to rank. Some things are still visible, including fees, timing, and technical details like action counts, so wallet behavior and network privacy still matter. And proving a coin is somewhere in the pool does not make every coin in the pool an equally likely match.
Monero is developing FCMP++ to replace its rings of 16 with membership proofs covering eligible outputs across the chain, described by its developers as more than 150 million outputs. Zcash's shielded pools already prove membership across the whole pool, although FCMP++ is a different protocol with a different membership set. FCMP++ remains in beta stressnet (not active on Monero mainnet yet).
My recommendation specifically concerns fully shielded transfers that stay within one pool. For hiding which coins are spent under those conditions, Ironwood is the design I prefer today. FCMP++ will warrant a fresh comparison when it is deployed.
Corrections welcome from both sides.(Historical earnings: For 2026Q1 (period ended 2026-03-31), Coinbase reported basic and diluted EPS of -1.49, net income of USD -0.394 billion, and revenue of USD 1.413 billion. In the prior-year 2025Q1 (period ended 2025-03-31), basic EPS was 0.26, diluted EPS was 0.24, net income was USD 65.608 million, and revenue was USD 2.034 billion. For 2025FY (period ended 2025-12-31), basic EPS was 4.85, diluted EPS was 4.45, net income was USD 1.260 billion, and revenue was USD 7.181 billion.
Consensus expectations: For 2026Q3, consensus EPS estimate is -0.1106 and revenue estimate is USD 1.211 billion. For 2026Q4, consensus EPS estimate is 0.1407 and revenue estimate is USD 1.398 billion.)