Paranoid crypto tips and random opsec thoughts

bright said:

A suggestion for anyone who wants a clean email address: Protonmail ... though you have to reach it through a VPN. For the one-time verification -> code anonibox works right now. Never use your real email adress! Protonmail only counts as next level opsec when you use it that way. They remain fully bound to suisse law and they also happily log everything.

Right now I am looking into options for a phone number. This is a new field for me though. Any recommendations
Gotchu



og-home.png




Anonymous eSIM for Travel | No Account or Email Required - PikaSim



PikaSim (Pika eSIM) - Anonymous eSIM for 190+ countries. No account needed. No KYC required. Your eSIM details appear instantly after payment. Private, fast, and secure.

favicon.ico



pikasim.com

jpru2001 said:

Other than the possibility of a Coinbase account getting closed, purchasing peps isn't against the law at this point... so as long as it remains legal, if I:

purchase USDC through coinbase, just enough for one order

move it to my own exodus wallet

send it along to the vendor

what actual danger does that pose? It's not illegal, and there's no balance sitting in the coinbase account that I could stand to lose. What I'm doing doesn't even compare to the US resellers who are picking up cases upon cases of kits for thousands of dollars and flipping them at a 10x markup. Most of those folks aren't even making a real effort to market strictly as RUO, they do stuff like bundle with BAC, etc., which genuinely steps over the legal line. At this point nobody seems to even bother with those guys either... unless they're dodging taxes through venmo payments/etc, then they'll probably start to care.
Fair point, though you did wander into a schizo thread, soo

Whether the apathy ever lifts, or when, is anybody's guess — and once it does, plenty of eyes could turn this way. Everything you do right now gets retained by your exchange for good and stamped permanently into the blockchain, and there's no telling where things go from here. Can you really be certain the person you're buying from isn't running things for a cartel, or for North Korea? Down the line somebody might take an interest in you, pull a few threads together using a handful of clicks and a dozen gallons of water at a data center, and just like that you're a terrorist financier.

Hiding something isn't the same as protecting it, and anybody in IT knows that.
 

Attachments

  • 6f88e189581d065b696aa73b77eb7caeddc8e1cf9bbaed767ba161f5906081da.png
    6f88e189581d065b696aa73b77eb7caeddc8e1cf9bbaed767ba161f5906081da.png
    762.8 KB · Views: 5
  • a4bc8db04e5bd782fb27327af62f67f1214219a016252ad805cea292935f4bf4.png
    a4bc8db04e5bd782fb27327af62f67f1214219a016252ad805cea292935f4bf4.png
    158.9 KB · Views: 5
bright said:

A suggestion for anyone who wants a clean email address: Protonmail ... though you have to reach it through a VPN. For the one-time verification -> code anonibox works right now. Never use your real email adress! Protonmail only counts as next level opsec when you use it that way. They remain fully bound to suisse law and they also happily log everything.

Right now I am looking into options for a phone number. This is a new field for me though. Any recommendations




Silent Link





android-icon-192x192.png



silent.link



og-image.png




Private eSIMs, pay with Bitcoin or Monero | simsup



Grab an eSIM that needs no KYC and settle it in Bitcoin or Monero. There is no signup and no identity check. Data eSIMs and anonymous numbers arrive as a QR code in a matter of minutes.

favicon.svg



simsup.com

That said, GSM networks are extremely insecure and offer almost no privacy, and there is basically no way to fix that. The only thing this improves is vendor misbehaviour, because no matter which SIM you hold, you still attach to the same tower, and the handsets carry their own identifiers that are simple to follow. Keep your GSM usage to a minimum.
 

Attachments

  • 50f83ea46f4718c41a2eaf228f86bad4cdca0943675a56044b274ed57f9f8fe2.png
    50f83ea46f4718c41a2eaf228f86bad4cdca0943675a56044b274ed57f9f8fe2.png
    27.1 KB · Views: 5
  • 6412a7fb50553b522b370985b5b9ed93bb454e11f70ec203b8b17fe1ad5dc866.png
    6412a7fb50553b522b370985b5b9ed93bb454e11f70ec203b8b17fe1ad5dc866.png
    29.9 KB · Views: 5
First time moving XMR into bitcoin through Cake Wallet... How long does it usually take to finish, and roughly what does it cost? Also, if I'm working with something like 300usd, how much extra cushion should I add so price swings don't leave me short?

One more thing: when you send the exact amount, is the transaction cost deducted from your side? Or is it already factored into the prices?
 
kugelblitz said:

bright said:

A suggestion for anyone who wants a clean email address: Protonmail ... though you have to reach it through a VPN. For the one-time verification -> code anonibox works right now. Never use your real email adress! Protonmail only counts as next level opsec when you use it that way. They remain fully bound to suisse law and they also happily log everything.

Right now I am looking into options for a phone number. This is a new field for me though. Any recommendations




Silent Link





android-icon-192x192.png



silent.link



og-image.png




Private eSIMs, pay with Bitcoin or Monero | simsup



Grab an eSIM that needs no KYC and settle it in Bitcoin or Monero. There is no signup and no identity check. Data eSIMs and anonymous numbers arrive as a QR code in a matter of minutes.

favicon.svg



simsup.com

That said, GSM networks are extremely insecure and offer almost no privacy, and there is basically no way to fix that. The only thing this improves is vendor misbehaviour, because no matter which SIM you hold, you still attach to the same tower, and the handsets carry their own identifiers that are simple to follow. Keep your GSM usage to a minimum.

In the era of AI, believing a burner phone is truly anonymous only works in a terrible film. The moment you relocate, the device goes with you, and connecting the two has repeatedly been shown to be trivially easy.
 

Attachments

  • 50f83ea46f4718c41a2eaf228f86bad4cdca0943675a56044b274ed57f9f8fe2.png
    50f83ea46f4718c41a2eaf228f86bad4cdca0943675a56044b274ed57f9f8fe2.png
    27.1 KB · Views: 5
  • 6412a7fb50553b522b370985b5b9ed93bb454e11f70ec203b8b17fe1ad5dc866.png
    6412a7fb50553b522b370985b5b9ed93bb454e11f70ec203b8b17fe1ad5dc866.png
    29.9 KB · Views: 5
sonic_boom said:

First time moving XMR into bitcoin through Cake Wallet... How long does it usually take to finish, and roughly what does it cost? Also, if I'm working with something like 300usd, how much extra cushion should I add so price swings don't leave me short?

One more thing: when you send the exact amount, is the transaction cost deducted from your side? Or is it already factored into the prices?
Doing the swap right inside Cake Wallet isn't something I'd recommend — when a wallet handles the exchange for you, there's typically a fee baked in. Instead, head here, choose one of the aggregators that don't require KYC, and check which swappers are quoting the most favorable rate.

The swapper quotes you an expected amount, which lets you size your send to what you actually need. Even so, I still overshoot by about 1 to 2 USD to absorb rate swings.

As far as I know, there's no method for landing on the exact figure you need, right down to the cent.
 
mybodyisasewer said:

It's become painfully obvious to me that a huge number of newcomers here are in way over their heads and have zero grasp of opsec. That's why I'm putting together this schizo post.

I was present during the SR1.0 RC days (read my username literally), so the mere fact that I'm walking free ought to demonstrate that I understand what I'm doing.

Way too many people I see are buying bitcoin on a clearnet KYC exchange like Coinbase and then firing it directly at the vendor. That is pure insanity. The blockchain is public, your BTC address is not private, and the moment the vendor's address gets identified, you are tied to them permanently and forever.

A huge number of people have had their crypto accounts shut down for sending funds to gambling sites, peptide sites, foreign governments, donating to the wrong cause, and anything else the powers that be disapprove of. Would you write a check to your drug dealer? Don't do this.

Open a Kraken account, purchase XMR, and send that to a non-custodial wallet such as Cake Wallet. Cake lets you swap the XMR into BTC. Whose BTC are you receiving? Doesn't matter, you're paying a sketchy foreign agent, it's for the best. Decentralized exchanges are the best tool available for destroying the forensic trail between you and the vendor.

If using Kraken as an onramp gives you trouble, use any exchage of your choice to get crypto and transfer it to Kraken to get the XMR. Kraken is the only exchange I know of that supports this currency, as there is a lot of pressure to delist XMR because of what I'm about to explain.

XMR has not been cracked. Despite the FUD, the US government's bounty on XMR was never claimed. This breaks the traceable chain from your custodial clearnet funds to BTC that has never touched anything with your name on it.

Obviously, vendors should be taking XMR directly, but they haven't quite caught up to the DNMs, which typically REQUIRE payment in XMR. So we're just using it to create a forensic gap between you and the funds that reach the vendor. And if you think XMR is for criminals, fine, but I've seen a $20 treasury note do things you wouldn't believe, so let's try to have consistent standards.

If you are worried about the security of running your own wallet with a seed phrase and everything, do not keep any more money in there than you need for a single purchase.

However, it is beneficial to get your crypto off the exchnage as fast as possible. This gives you plausible deniability if they ever come at you for capital gains. You can say you sold immediately at the buy price, leaving them to prove how long you held the asset. If you do this right, they won't. Also we want to keep our taxes as simple as possible. Bringing your 1099-B to H&R Block so they can work out your pittance of capital gains tax is just rude and pointless. They will hate you for this and it will cost you extra for the return prep.

Use a VPN for everything. Obviously the exchange has KYC on you, but don't give them anything more than that. Broadcasting a transaction from your personal IP address is an unnecessary risk. You want your IP associated with as little as possible. Proton VPN and PIA are solid choices if you wanted a lead on that. They don't log, and their data has yet to be seen in any unsealed warrants.

Also, rememeber the basics. Use a password for your phone, not a pin, not biometric. Do not tell people you have crypto, they will immediately and correctly assume you are a criminal. Never unlock your phone for law enforcement. Cellebrite and Graykey do not work as well as advertised. I have been in a position to see a large enough sample size and that's all I'm saying.

Ideally, you wouldn't even use a phone for this, but a laptop running a linux live distro like TAILS. This depends on your risk tolerance and threat models.

Read off the addresses when you send. Just the first and last characters. A popular cyber attack is to compromise the clipboard and have you paste the attacker's receiving address when you send.

To recap:

Kraken XMR -> Cake wallet -> swap to BTC

Use a VPN.

Write down your seed somewhere, or don't, it's just a temporary parking spot for your next purchase, right?

Stop screwing around with solana and usdt and paypal and all that noise. It is horrifying to see people buying this stuff using an American KYC service. This is how you get blacklisted from paypal. Stripe, Square, Venmo, Cashapp and all these other services are NOT YOUR FRIEND and they will snitch you out and close your account at the first sign of anything illegitimate. These financial institutions are so heavily regulated that they are essentially organs of the very state that is oppressing us. Stop trusting them!

Always assume your that exchange, bank, postman, and dentist are conspiring to build a case on you. Give them nothing to work with, get your coins off the exchange and swap them that same day. Say nothing to anyone. And if you are ever cornered for any reason, remember the magic words: I want a lawyer.

You never know when permissible actions today will come back at you in the future, ex post facto is not the shield you might think it is. If you want more info, look up the DNM bible. I'll certainly answer questions here or defend my position if someone else has a different doctrine.

Security doesn't have to be onerous or difficult, but there's a lot to learn if you're going to do it right.

this is great advice. At the very least, move it to your own wallet first, before it goes to the vendor.
 
mybodyisasewer said:

It's become painfully obvious to me that a huge number of newcomers here are in way over their heads and have zero grasp of opsec. That's why I'm putting together this schizo post.

I was present during the SR1.0 RC days (read my username literally), so the mere fact that I'm walking free ought to demonstrate that I understand what I'm doing.

Way too many people I see are buying bitcoin on a clearnet KYC exchange like Coinbase and then firing it directly at the vendor. That is pure insanity. The blockchain is public, your BTC address is not private, and the moment the vendor's address gets identified, you are tied to them permanently and forever.

A huge number of people have had their crypto accounts shut down for sending funds to gambling sites, peptide sites, foreign governments, donating to the wrong cause, and anything else the powers that be disapprove of. Would you write a check to your drug dealer? Don't do this.

Open a Kraken account, purchase XMR, and send that to a non-custodial wallet such as Cake Wallet. Cake lets you swap the XMR into BTC. Whose BTC are you receiving? Doesn't matter, you're paying a sketchy foreign agent, it's for the best. Decentralized exchanges are the best tool available for destroying the forensic trail between you and the vendor.

If using Kraken as an onramp gives you trouble, use any exchage of your choice to get crypto and transfer it to Kraken to get the XMR. Kraken is the only exchange I know of that supports this currency, as there is a lot of pressure to delist XMR because of what I'm about to explain.

XMR has not been cracked. Despite the FUD, the US government's bounty on XMR was never claimed. This breaks the traceable chain from your custodial clearnet funds to BTC that has never touched anything with your name on it.

Obviously, vendors should be taking XMR directly, but they haven't quite caught up to the DNMs, which typically REQUIRE payment in XMR. So we're just using it to create a forensic gap between you and the funds that reach the vendor. And if you think XMR is for criminals, fine, but I've seen a $20 treasury note do things you wouldn't believe, so let's try to have consistent standards.

If you are worried about the security of running your own wallet with a seed phrase and everything, do not keep any more money in there than you need for a single purchase.

However, it is beneficial to get your crypto off the exchnage as fast as possible. This gives you plausible deniability if they ever come at you for capital gains. You can say you sold immediately at the buy price, leaving them to prove how long you held the asset. If you do this right, they won't. Also we want to keep our taxes as simple as possible. Bringing your 1099-B to H&R Block so they can work out your pittance of capital gains tax is just rude and pointless. They will hate you for this and it will cost you extra for the return prep.

Use a VPN for everything. Obviously the exchange has KYC on you, but don't give them anything more than that. Broadcasting a transaction from your personal IP address is an unnecessary risk. You want your IP associated with as little as possible. Proton VPN and PIA are solid choices if you wanted a lead on that. They don't log, and their data has yet to be seen in any unsealed warrants.

Also, rememeber the basics. Use a password for your phone, not a pin, not biometric. Do not tell people you have crypto, they will immediately and correctly assume you are a criminal. Never unlock your phone for law enforcement. Cellebrite and Graykey do not work as well as advertised. I have been in a position to see a large enough sample size and that's all I'm saying.

Ideally, you wouldn't even use a phone for this, but a laptop running a linux live distro like TAILS. This depends on your risk tolerance and threat models.

Read off the addresses when you send. Just the first and last characters. A popular cyber attack is to compromise the clipboard and have you paste the attacker's receiving address when you send.

To recap:

Kraken XMR -> Cake wallet -> swap to BTC

Use a VPN.

Write down your seed somewhere, or don't, it's just a temporary parking spot for your next purchase, right?

Stop screwing around with solana and usdt and paypal and all that noise. It is horrifying to see people buying this stuff using an American KYC service. This is how you get blacklisted from paypal. Stripe, Square, Venmo, Cashapp and all these other services are NOT YOUR FRIEND and they will snitch you out and close your account at the first sign of anything illegitimate. These financial institutions are so heavily regulated that they are essentially organs of the very state that is oppressing us. Stop trusting them!

Always assume your that exchange, bank, postman, and dentist are conspiring to build a case on you. Give them nothing to work with, get your coins off the exchange and swap them that same day. Say nothing to anyone. And if you are ever cornered for any reason, remember the magic words: I want a lawyer.

You never know when permissible actions today will come back at you in the future, ex post facto is not the shield you might think it is. If you want more info, look up the DNM bible. I'll certainly answer questions here or defend my position if someone else has a different doctrine.

Security doesn't have to be onerous or difficult, but there's a lot to learn if you're going to do it right.

Kraken has de-listed XMR since this thread was started.

Can I reasonably assume ZEC would work as a viable substitute for XMR?
 
kugelblitz said:

sonic_boom said:

First time moving XMR into bitcoin through Cake Wallet... How long does it usually take to finish, and roughly what does it cost? Also, if I'm working with something like 300usd, how much extra cushion should I add so price swings don't leave me short?

One more thing: when you send the exact amount, is the transaction cost deducted from your side? Or is it already factored into the prices?
Doing the swap right inside Cake Wallet isn't something I'd recommend — when a wallet handles the exchange for you, there's typically a fee baked in. Instead, head here, choose one of the aggregators that don't require KYC, and check which swappers are quoting the most favorable rate.

The swapper quotes you an expected amount, which lets you size your send to what you actually need. Even so, I still overshoot by about 1 to 2 USD to absorb rate swings.

As far as I know, there's no method for landing on the exact figure you need, right down to the cent.
appreciate it, I skipped straight to SOL inside Cake wallet, the fees were pretty low and moving Sol appears to run about a penny.
 
mybodyisasewer said:

It's become painfully obvious to me that a huge number of newcomers here are in way over their heads and have zero grasp of opsec. That's why I'm putting together this schizo post.

I was present during the SR1.0 RC days (read my username literally), so the mere fact that I'm walking free ought to demonstrate that I understand what I'm doing.

Way too many people I see are buying bitcoin on a clearnet KYC exchange like Coinbase and then firing it directly at the vendor. That is pure insanity. The blockchain is public, your BTC address is not private, and the moment the vendor's address gets identified, you are tied to them permanently and forever.

A huge number of people have had their crypto accounts shut down for sending funds to gambling sites, peptide sites, foreign governments, donating to the wrong cause, and anything else the powers that be disapprove of. Would you write a check to your drug dealer? Don't do this.

Open a Kraken account, purchase XMR, and send that to a non-custodial wallet such as Cake Wallet. Cake lets you swap the XMR into BTC. Whose BTC are you receiving? Doesn't matter, you're paying a sketchy foreign agent, it's for the best. Decentralized exchanges are the best tool available for destroying the forensic trail between you and the vendor.

If using Kraken as an onramp gives you trouble, use any exchage of your choice to get crypto and transfer it to Kraken to get the XMR. Kraken is the only exchange I know of that supports this currency, as there is a lot of pressure to delist XMR because of what I'm about to explain.

XMR has not been cracked. Despite the FUD, the US government's bounty on XMR was never claimed. This breaks the traceable chain from your custodial clearnet funds to BTC that has never touched anything with your name on it.

Obviously, vendors should be taking XMR directly, but they haven't quite caught up to the DNMs, which typically REQUIRE payment in XMR. So we're just using it to create a forensic gap between you and the funds that reach the vendor. And if you think XMR is for criminals, fine, but I've seen a $20 treasury note do things you wouldn't believe, so let's try to have consistent standards.

If you are worried about the security of running your own wallet with a seed phrase and everything, do not keep any more money in there than you need for a single purchase.

However, it is beneficial to get your crypto off the exchnage as fast as possible. This gives you plausible deniability if they ever come at you for capital gains. You can say you sold immediately at the buy price, leaving them to prove how long you held the asset. If you do this right, they won't. Also we want to keep our taxes as simple as possible. Bringing your 1099-B to H&R Block so they can work out your pittance of capital gains tax is just rude and pointless. They will hate you for this and it will cost you extra for the return prep.

Use a VPN for everything. Obviously the exchange has KYC on you, but don't give them anything more than that. Broadcasting a transaction from your personal IP address is an unnecessary risk. You want your IP associated with as little as possible. Proton VPN and PIA are solid choices if you wanted a lead on that. They don't log, and their data has yet to be seen in any unsealed warrants.

Also, rememeber the basics. Use a password for your phone, not a pin, not biometric. Do not tell people you have crypto, they will immediately and correctly assume you are a criminal. Never unlock your phone for law enforcement. Cellebrite and Graykey do not work as well as advertised. I have been in a position to see a large enough sample size and that's all I'm saying.

Ideally, you wouldn't even use a phone for this, but a laptop running a linux live distro like TAILS. This depends on your risk tolerance and threat models.

Read off the addresses when you send. Just the first and last characters. A popular cyber attack is to compromise the clipboard and have you paste the attacker's receiving address when you send.

To recap:

Kraken XMR -> Cake wallet -> swap to BTC

Use a VPN.

Write down your seed somewhere, or don't, it's just a temporary parking spot for your next purchase, right?

Stop screwing around with solana and usdt and paypal and all that noise. It is horrifying to see people buying this stuff using an American KYC service. This is how you get blacklisted from paypal. Stripe, Square, Venmo, Cashapp and all these other services are NOT YOUR FRIEND and they will snitch you out and close your account at the first sign of anything illegitimate. These financial institutions are so heavily regulated that they are essentially organs of the very state that is oppressing us. Stop trusting them!

Always assume your that exchange, bank, postman, and dentist are conspiring to build a case on you. Give them nothing to work with, get your coins off the exchange and swap them that same day. Say nothing to anyone. And if you are ever cornered for any reason, remember the magic words: I want a lawyer.

You never know when permissible actions today will come back at you in the future, ex post facto is not the shield you might think it is. If you want more info, look up the DNM bible. I'll certainly answer questions here or defend my position if someone else has a different doctrine.

Security doesn't have to be onerous or difficult, but there's a lot to learn if you're going to do it right.
I appreciate this, it's great. I've been avoiding crypto for precisely this reason — I couldn't understand how it wouldn't actually be MORE incriminating than other p 2 p transaction types.
 
boytres said:

mybodyisasewer said:

It's become painfully obvious to me that a huge number of newcomers here are in way over their heads and have zero grasp of opsec. That's why I'm putting together this schizo post.

I was present during the SR1.0 RC days (read my username literally), so the mere fact that I'm walking free ought to demonstrate that I understand what I'm doing.

Way too many people I see are buying bitcoin on a clearnet KYC exchange like Coinbase and then firing it directly at the vendor. That is pure insanity. The blockchain is public, your BTC address is not private, and the moment the vendor's address gets identified, you are tied to them permanently and forever.

A huge number of people have had their crypto accounts shut down for sending funds to gambling sites, peptide sites, foreign governments, donating to the wrong cause, and anything else the powers that be disapprove of. Would you write a check to your drug dealer? Don't do this.

Open a Kraken account, purchase XMR, and send that to a non-custodial wallet such as Cake Wallet. Cake lets you swap the XMR into BTC. Whose BTC are you receiving? Doesn't matter, you're paying a sketchy foreign agent, it's for the best. Decentralized exchanges are the best tool available for destroying the forensic trail between you and the vendor.

If using Kraken as an onramp gives you trouble, use any exchage of your choice to get crypto and transfer it to Kraken to get the XMR. Kraken is the only exchange I know of that supports this currency, as there is a lot of pressure to delist XMR because of what I'm about to explain.

XMR has not been cracked. Despite the FUD, the US government's bounty on XMR was never claimed. This breaks the traceable chain from your custodial clearnet funds to BTC that has never touched anything with your name on it.

Obviously, vendors should be taking XMR directly, but they haven't quite caught up to the DNMs, which typically REQUIRE payment in XMR. So we're just using it to create a forensic gap between you and the funds that reach the vendor. And if you think XMR is for criminals, fine, but I've seen a $20 treasury note do things you wouldn't believe, so let's try to have consistent standards.

If you are worried about the security of running your own wallet with a seed phrase and everything, do not keep any more money in there than you need for a single purchase.

However, it is beneficial to get your crypto off the exchnage as fast as possible. This gives you plausible deniability if they ever come at you for capital gains. You can say you sold immediately at the buy price, leaving them to prove how long you held the asset. If you do this right, they won't. Also we want to keep our taxes as simple as possible. Bringing your 1099-B to H&R Block so they can work out your pittance of capital gains tax is just rude and pointless. They will hate you for this and it will cost you extra for the return prep.

Use a VPN for everything. Obviously the exchange has KYC on you, but don't give them anything more than that. Broadcasting a transaction from your personal IP address is an unnecessary risk. You want your IP associated with as little as possible. Proton VPN and PIA are solid choices if you wanted a lead on that. They don't log, and their data has yet to be seen in any unsealed warrants.

Also, rememeber the basics. Use a password for your phone, not a pin, not biometric. Do not tell people you have crypto, they will immediately and correctly assume you are a criminal. Never unlock your phone for law enforcement. Cellebrite and Graykey do not work as well as advertised. I have been in a position to see a large enough sample size and that's all I'm saying.

Ideally, you wouldn't even use a phone for this, but a laptop running a linux live distro like TAILS. This depends on your risk tolerance and threat models.

Read off the addresses when you send. Just the first and last characters. A popular cyber attack is to compromise the clipboard and have you paste the attacker's receiving address when you send.

To recap:

Kraken XMR -> Cake wallet -> swap to BTC

Use a VPN.

Write down your seed somewhere, or don't, it's just a temporary parking spot for your next purchase, right?

Stop screwing around with solana and usdt and paypal and all that noise. It is horrifying to see people buying this stuff using an American KYC service. This is how you get blacklisted from paypal. Stripe, Square, Venmo, Cashapp and all these other services are NOT YOUR FRIEND and they will snitch you out and close your account at the first sign of anything illegitimate. These financial institutions are so heavily regulated that they are essentially organs of the very state that is oppressing us. Stop trusting them!

Always assume your that exchange, bank, postman, and dentist are conspiring to build a case on you. Give them nothing to work with, get your coins off the exchange and swap them that same day. Say nothing to anyone. And if you are ever cornered for any reason, remember the magic words: I want a lawyer.

You never know when permissible actions today will come back at you in the future, ex post facto is not the shield you might think it is. If you want more info, look up the DNM bible. I'll certainly answer questions here or defend my position if someone else has a different doctrine.

Security doesn't have to be onerous or difficult, but there's a lot to learn if you're going to do it right.

Kraken has de-listed XMR since this thread was started.

Can I reasonably assume ZEC would work as a viable substitute for XMR?
I've never come across it before. That said, if the reason XMR got delisted is that it's a privacy coin, then ZEC is likely less private, given that it's still listed.
 
sonic_boom said:

boytres said:

mybodyisasewer said:

It's become painfully obvious to me that a huge number of newcomers here are in way over their heads and have zero grasp of opsec. That's why I'm putting together this schizo post.

I was present during the SR1.0 RC days (read my username literally), so the mere fact that I'm walking free ought to demonstrate that I understand what I'm doing.

Way too many people I see are buying bitcoin on a clearnet KYC exchange like Coinbase and then firing it directly at the vendor. That is pure insanity. The blockchain is public, your BTC address is not private, and the moment the vendor's address gets identified, you are tied to them permanently and forever.

A huge number of people have had their crypto accounts shut down for sending funds to gambling sites, peptide sites, foreign governments, donating to the wrong cause, and anything else the powers that be disapprove of. Would you write a check to your drug dealer? Don't do this.

Open a Kraken account, purchase XMR, and send that to a non-custodial wallet such as Cake Wallet. Cake lets you swap the XMR into BTC. Whose BTC are you receiving? Doesn't matter, you're paying a sketchy foreign agent, it's for the best. Decentralized exchanges are the best tool available for destroying the forensic trail between you and the vendor.

If using Kraken as an onramp gives you trouble, use any exchage of your choice to get crypto and transfer it to Kraken to get the XMR. Kraken is the only exchange I know of that supports this currency, as there is a lot of pressure to delist XMR because of what I'm about to explain.

XMR has not been cracked. Despite the FUD, the US government's bounty on XMR was never claimed. This breaks the traceable chain from your custodial clearnet funds to BTC that has never touched anything with your name on it.

Obviously, vendors should be taking XMR directly, but they haven't quite caught up to the DNMs, which typically REQUIRE payment in XMR. So we're just using it to create a forensic gap between you and the funds that reach the vendor. And if you think XMR is for criminals, fine, but I've seen a $20 treasury note do things you wouldn't believe, so let's try to have consistent standards.

If you are worried about the security of running your own wallet with a seed phrase and everything, do not keep any more money in there than you need for a single purchase.

However, it is beneficial to get your crypto off the exchnage as fast as possible. This gives you plausible deniability if they ever come at you for capital gains. You can say you sold immediately at the buy price, leaving them to prove how long you held the asset. If you do this right, they won't. Also we want to keep our taxes as simple as possible. Bringing your 1099-B to H&R Block so they can work out your pittance of capital gains tax is just rude and pointless. They will hate you for this and it will cost you extra for the return prep.

Use a VPN for everything. Obviously the exchange has KYC on you, but don't give them anything more than that. Broadcasting a transaction from your personal IP address is an unnecessary risk. You want your IP associated with as little as possible. Proton VPN and PIA are solid choices if you wanted a lead on that. They don't log, and their data has yet to be seen in any unsealed warrants.

Also, rememeber the basics. Use a password for your phone, not a pin, not biometric. Do not tell people you have crypto, they will immediately and correctly assume you are a criminal. Never unlock your phone for law enforcement. Cellebrite and Graykey do not work as well as advertised. I have been in a position to see a large enough sample size and that's all I'm saying.

Ideally, you wouldn't even use a phone for this, but a laptop running a linux live distro like TAILS. This depends on your risk tolerance and threat models.

Read off the addresses when you send. Just the first and last characters. A popular cyber attack is to compromise the clipboard and have you paste the attacker's receiving address when you send.

To recap:

Kraken XMR -> Cake wallet -> swap to BTC

Use a VPN.

Write down your seed somewhere, or don't, it's just a temporary parking spot for your next purchase, right?

Stop screwing around with solana and usdt and paypal and all that noise. It is horrifying to see people buying this stuff using an American KYC service. This is how you get blacklisted from paypal. Stripe, Square, Venmo, Cashapp and all these other services are NOT YOUR FRIEND and they will snitch you out and close your account at the first sign of anything illegitimate. These financial institutions are so heavily regulated that they are essentially organs of the very state that is oppressing us. Stop trusting them!

Always assume your that exchange, bank, postman, and dentist are conspiring to build a case on you. Give them nothing to work with, get your coins off the exchange and swap them that same day. Say nothing to anyone. And if you are ever cornered for any reason, remember the magic words: I want a lawyer.

You never know when permissible actions today will come back at you in the future, ex post facto is not the shield you might think it is. If you want more info, look up the DNM bible. I'll certainly answer questions here or defend my position if someone else has a different doctrine.

Security doesn't have to be onerous or difficult, but there's a lot to learn if you're going to do it right.

Kraken has de-listed XMR since this thread was started.

Can I reasonably assume ZEC would work as a viable substitute for XMR?
I've never come across it before. That said, if the reason XMR got delisted is that it's a privacy coin, then ZEC is likely less private, given that it's still listed.
According to Google AI, "Zcash (ZEC) is the closest major alternative to Monero (XMR) regarding privacy and security, as it utilizes advanced zero-knowledge cryptography (zk-SNARKs) to completely hide transaction senders, receivers, and amounts.

While Monero(XMR) enforces mandatory privacy for every transaction, Zcash(ZEC) offers flexible privacy. Zcash(ZEC) allows users to choose between transparent addresses (similar to Bitcoin) and "shielded" addresses (which offer untraceable security identical to XMR)."

That's the reason I switched to ZEC after Kraken delisted XMR, and it's also why I asked.
 
Fabulous_Jackal said:

Fine, suppose we accept that your crypto transfer really is 'untraceable' — you're on burner numbers for telegram, WhatsApp and and discord. A dedicated laptop running a Linux OS, used only on public WiFi through the Tor browser, and so on. The moment you put in an order, though, there has to be a physical address where that product gets received. Nobody is dropping it from a drone, and no shadowy courier is leaving it at some secret spot. It shows up at your door, or at the door of somebody tied to you. There's no real way around that. Even if you're paying for a P.O. Box so you can limit your KYC exposure to the vendor, the transactions to minimise the possibility of you losing money/wallets to confiscation or TOS violations etc. But not sure how you get around that final step in the end. On top of that, every one of these steps piles on cost, complexity and a whole lot of time. Where's the line where the whole thing turns so onerous that simply handing 'the man' his pound of flesh and buying 'legitimate' peptides ends up easier and comes out to the same price? - Don't get me wrong I'm all about this and want to learn as much as I can to be smart about protecting myself. But if my financial cost of buying grey, then 3rd party testing - not to mention the extensive time delay waiting on CofA's to validate the product, filtering and reconstitution supplies etc etc. eventually it's just not worth the hassle…
Simple. Brushing is a thing. Random packages showing up that nobody ordered are way more common than you'd expect. Should it ever come to that, you just play dumb until they detain you, and once you're detained, you say nothing to anyone but a lawyer.

Given that our data gets sold on the darkweb constantly, and your phone number and email don't line up, any lawyer with two working braincells can get the case thrown out (that is, if you didn't screw yourself over in some other way).
 
boytres said:

mybodyisasewer said:

It's become painfully obvious to me that a huge number of newcomers here are in way over their heads and have zero grasp of opsec. That's why I'm putting together this schizo post.

I was present during the SR1.0 RC days (read my username literally), so the mere fact that I'm walking free ought to demonstrate that I understand what I'm doing.

Way too many people I see are buying bitcoin on a clearnet KYC exchange like Coinbase and then firing it directly at the vendor. That is pure insanity. The blockchain is public, your BTC address is not private, and the moment the vendor's address gets identified, you are tied to them permanently and forever.

A huge number of people have had their crypto accounts shut down for sending funds to gambling sites, peptide sites, foreign governments, donating to the wrong cause, and anything else the powers that be disapprove of. Would you write a check to your drug dealer? Don't do this.

Open a Kraken account, purchase XMR, and send that to a non-custodial wallet such as Cake Wallet. Cake lets you swap the XMR into BTC. Whose BTC are you receiving? Doesn't matter, you're paying a sketchy foreign agent, it's for the best. Decentralized exchanges are the best tool available for destroying the forensic trail between you and the vendor.

If using Kraken as an onramp gives you trouble, use any exchage of your choice to get crypto and transfer it to Kraken to get the XMR. Kraken is the only exchange I know of that supports this currency, as there is a lot of pressure to delist XMR because of what I'm about to explain.

XMR has not been cracked. Despite the FUD, the US government's bounty on XMR was never claimed. This breaks the traceable chain from your custodial clearnet funds to BTC that has never touched anything with your name on it.

Obviously, vendors should be taking XMR directly, but they haven't quite caught up to the DNMs, which typically REQUIRE payment in XMR. So we're just using it to create a forensic gap between you and the funds that reach the vendor. And if you think XMR is for criminals, fine, but I've seen a $20 treasury note do things you wouldn't believe, so let's try to have consistent standards.

If you are worried about the security of running your own wallet with a seed phrase and everything, do not keep any more money in there than you need for a single purchase.

However, it is beneficial to get your crypto off the exchnage as fast as possible. This gives you plausible deniability if they ever come at you for capital gains. You can say you sold immediately at the buy price, leaving them to prove how long you held the asset. If you do this right, they won't. Also we want to keep our taxes as simple as possible. Bringing your 1099-B to H&R Block so they can work out your pittance of capital gains tax is just rude and pointless. They will hate you for this and it will cost you extra for the return prep.

Use a VPN for everything. Obviously the exchange has KYC on you, but don't give them anything more than that. Broadcasting a transaction from your personal IP address is an unnecessary risk. You want your IP associated with as little as possible. Proton VPN and PIA are solid choices if you wanted a lead on that. They don't log, and their data has yet to be seen in any unsealed warrants.

Also, rememeber the basics. Use a password for your phone, not a pin, not biometric. Do not tell people you have crypto, they will immediately and correctly assume you are a criminal. Never unlock your phone for law enforcement. Cellebrite and Graykey do not work as well as advertised. I have been in a position to see a large enough sample size and that's all I'm saying.

Ideally, you wouldn't even use a phone for this, but a laptop running a linux live distro like TAILS. This depends on your risk tolerance and threat models.

Read off the addresses when you send. Just the first and last characters. A popular cyber attack is to compromise the clipboard and have you paste the attacker's receiving address when you send.

To recap:

Kraken XMR -> Cake wallet -> swap to BTC

Use a VPN.

Write down your seed somewhere, or don't, it's just a temporary parking spot for your next purchase, right?

Stop screwing around with solana and usdt and paypal and all that noise. It is horrifying to see people buying this stuff using an American KYC service. This is how you get blacklisted from paypal. Stripe, Square, Venmo, Cashapp and all these other services are NOT YOUR FRIEND and they will snitch you out and close your account at the first sign of anything illegitimate. These financial institutions are so heavily regulated that they are essentially organs of the very state that is oppressing us. Stop trusting them!

Always assume your that exchange, bank, postman, and dentist are conspiring to build a case on you. Give them nothing to work with, get your coins off the exchange and swap them that same day. Say nothing to anyone. And if you are ever cornered for any reason, remember the magic words: I want a lawyer.

You never know when permissible actions today will come back at you in the future, ex post facto is not the shield you might think it is. If you want more info, look up the DNM bible. I'll certainly answer questions here or defend my position if someone else has a different doctrine.

Security doesn't have to be onerous or difficult, but there's a lot to learn if you're going to do it right.

Kraken has de-listed XMR since this thread was started.

Can I reasonably assume ZEC would work as a viable substitute for XMR?
sadly, in certain European countries that's the case — Ireland being one I'm aware of.

still, monero remains purchasable across most of the globe

what really grates is that vendors won't take monero; my hope is that eventually a privacy-focused ERC-20 coin shows up, letting us move USDT through it just as easily but with privacy
 
boytres said:

sonic_boom said:

boytres said:

mybodyisasewer said:

It's become painfully obvious to me that a huge number of newcomers here are in way over their heads and have zero grasp of opsec. That's why I'm putting together this schizo post.

I was present during the SR1.0 RC days (read my username literally), so the mere fact that I'm walking free ought to demonstrate that I understand what I'm doing.

Way too many people I see are buying bitcoin on a clearnet KYC exchange like Coinbase and then firing it directly at the vendor. That is pure insanity. The blockchain is public, your BTC address is not private, and the moment the vendor's address gets identified, you are tied to them permanently and forever.

A huge number of people have had their crypto accounts shut down for sending funds to gambling sites, peptide sites, foreign governments, donating to the wrong cause, and anything else the powers that be disapprove of. Would you write a check to your drug dealer? Don't do this.

Open a Kraken account, purchase XMR, and send that to a non-custodial wallet such as Cake Wallet. Cake lets you swap the XMR into BTC. Whose BTC are you receiving? Doesn't matter, you're paying a sketchy foreign agent, it's for the best. Decentralized exchanges are the best tool available for destroying the forensic trail between you and the vendor.

If using Kraken as an onramp gives you trouble, use any exchage of your choice to get crypto and transfer it to Kraken to get the XMR. Kraken is the only exchange I know of that supports this currency, as there is a lot of pressure to delist XMR because of what I'm about to explain.

XMR has not been cracked. Despite the FUD, the US government's bounty on XMR was never claimed. This breaks the traceable chain from your custodial clearnet funds to BTC that has never touched anything with your name on it.

Obviously, vendors should be taking XMR directly, but they haven't quite caught up to the DNMs, which typically REQUIRE payment in XMR. So we're just using it to create a forensic gap between you and the funds that reach the vendor. And if you think XMR is for criminals, fine, but I've seen a $20 treasury note do things you wouldn't believe, so let's try to have consistent standards.

If you are worried about the security of running your own wallet with a seed phrase and everything, do not keep any more money in there than you need for a single purchase.

However, it is beneficial to get your crypto off the exchnage as fast as possible. This gives you plausible deniability if they ever come at you for capital gains. You can say you sold immediately at the buy price, leaving them to prove how long you held the asset. If you do this right, they won't. Also we want to keep our taxes as simple as possible. Bringing your 1099-B to H&R Block so they can work out your pittance of capital gains tax is just rude and pointless. They will hate you for this and it will cost you extra for the return prep.

Use a VPN for everything. Obviously the exchange has KYC on you, but don't give them anything more than that. Broadcasting a transaction from your personal IP address is an unnecessary risk. You want your IP associated with as little as possible. Proton VPN and PIA are solid choices if you wanted a lead on that. They don't log, and their data has yet to be seen in any unsealed warrants.

Also, rememeber the basics. Use a password for your phone, not a pin, not biometric. Do not tell people you have crypto, they will immediately and correctly assume you are a criminal. Never unlock your phone for law enforcement. Cellebrite and Graykey do not work as well as advertised. I have been in a position to see a large enough sample size and that's all I'm saying.

Ideally, you wouldn't even use a phone for this, but a laptop running a linux live distro like TAILS. This depends on your risk tolerance and threat models.

Read off the addresses when you send. Just the first and last characters. A popular cyber attack is to compromise the clipboard and have you paste the attacker's receiving address when you send.

To recap:

Kraken XMR -> Cake wallet -> swap to BTC

Use a VPN.

Write down your seed somewhere, or don't, it's just a temporary parking spot for your next purchase, right?

Stop screwing around with solana and usdt and paypal and all that noise. It is horrifying to see people buying this stuff using an American KYC service. This is how you get blacklisted from paypal. Stripe, Square, Venmo, Cashapp and all these other services are NOT YOUR FRIEND and they will snitch you out and close your account at the first sign of anything illegitimate. These financial institutions are so heavily regulated that they are essentially organs of the very state that is oppressing us. Stop trusting them!

Always assume your that exchange, bank, postman, and dentist are conspiring to build a case on you. Give them nothing to work with, get your coins off the exchange and swap them that same day. Say nothing to anyone. And if you are ever cornered for any reason, remember the magic words: I want a lawyer.

You never know when permissible actions today will come back at you in the future, ex post facto is not the shield you might think it is. If you want more info, look up the DNM bible. I'll certainly answer questions here or defend my position if someone else has a different doctrine.

Security doesn't have to be onerous or difficult, but there's a lot to learn if you're going to do it right.

Kraken has de-listed XMR since this thread was started.

Can I reasonably assume ZEC would work as a viable substitute for XMR?
I've never come across it before. That said, if the reason XMR got delisted is that it's a privacy coin, then ZEC is likely less private, given that it's still listed.
According to Google AI, "Zcash (ZEC) is the closest major alternative to Monero (XMR) regarding privacy and security, as it utilizes advanced zero-knowledge cryptography (zk-SNARKs) to completely hide transaction senders, receivers, and amounts.

While Monero(XMR) enforces mandatory privacy for every transaction, Zcash(ZEC) offers flexible privacy. Zcash(ZEC) allows users to choose between transparent addresses (similar to Bitcoin) and "shielded" addresses (which offer untraceable security identical to XMR)."

That's the reason I switched to ZEC after Kraken delisted XMR, and it's also why I asked.
you put faith in a marketing blurb, even though a basic non-AI search reveals they just dropped 38% because of a bug? I'm not saying it isn't private, it's just that it's less likely to be private than monero, otherwise it would be forced to be delisted.
 
sonic_boom said:

boytres said:

sonic_boom said:

boytres said:

mybodyisasewer said:

It's become painfully obvious to me that a huge number of newcomers here are in way over their heads and have zero grasp of opsec. That's why I'm putting together this schizo post.

I was present during the SR1.0 RC days (read my username literally), so the mere fact that I'm walking free ought to demonstrate that I understand what I'm doing.

Way too many people I see are buying bitcoin on a clearnet KYC exchange like Coinbase and then firing it directly at the vendor. That is pure insanity. The blockchain is public, your BTC address is not private, and the moment the vendor's address gets identified, you are tied to them permanently and forever.

A huge number of people have had their crypto accounts shut down for sending funds to gambling sites, peptide sites, foreign governments, donating to the wrong cause, and anything else the powers that be disapprove of. Would you write a check to your drug dealer? Don't do this.

Open a Kraken account, purchase XMR, and send that to a non-custodial wallet such as Cake Wallet. Cake lets you swap the XMR into BTC. Whose BTC are you receiving? Doesn't matter, you're paying a sketchy foreign agent, it's for the best. Decentralized exchanges are the best tool available for destroying the forensic trail between you and the vendor.

If using Kraken as an onramp gives you trouble, use any exchage of your choice to get crypto and transfer it to Kraken to get the XMR. Kraken is the only exchange I know of that supports this currency, as there is a lot of pressure to delist XMR because of what I'm about to explain.

XMR has not been cracked. Despite the FUD, the US government's bounty on XMR was never claimed. This breaks the traceable chain from your custodial clearnet funds to BTC that has never touched anything with your name on it.

Obviously, vendors should be taking XMR directly, but they haven't quite caught up to the DNMs, which typically REQUIRE payment in XMR. So we're just using it to create a forensic gap between you and the funds that reach the vendor. And if you think XMR is for criminals, fine, but I've seen a $20 treasury note do things you wouldn't believe, so let's try to have consistent standards.

If you are worried about the security of running your own wallet with a seed phrase and everything, do not keep any more money in there than you need for a single purchase.

However, it is beneficial to get your crypto off the exchnage as fast as possible. This gives you plausible deniability if they ever come at you for capital gains. You can say you sold immediately at the buy price, leaving them to prove how long you held the asset. If you do this right, they won't. Also we want to keep our taxes as simple as possible. Bringing your 1099-B to H&R Block so they can work out your pittance of capital gains tax is just rude and pointless. They will hate you for this and it will cost you extra for the return prep.

Use a VPN for everything. Obviously the exchange has KYC on you, but don't give them anything more than that. Broadcasting a transaction from your personal IP address is an unnecessary risk. You want your IP associated with as little as possible. Proton VPN and PIA are solid choices if you wanted a lead on that. They don't log, and their data has yet to be seen in any unsealed warrants.

Also, rememeber the basics. Use a password for your phone, not a pin, not biometric. Do not tell people you have crypto, they will immediately and correctly assume you are a criminal. Never unlock your phone for law enforcement. Cellebrite and Graykey do not work as well as advertised. I have been in a position to see a large enough sample size and that's all I'm saying.

Ideally, you wouldn't even use a phone for this, but a laptop running a linux live distro like TAILS. This depends on your risk tolerance and threat models.

Read off the addresses when you send. Just the first and last characters. A popular cyber attack is to compromise the clipboard and have you paste the attacker's receiving address when you send.

To recap:

Kraken XMR -> Cake wallet -> swap to BTC

Use a VPN.

Write down your seed somewhere, or don't, it's just a temporary parking spot for your next purchase, right?

Stop screwing around with solana and usdt and paypal and all that noise. It is horrifying to see people buying this stuff using an American KYC service. This is how you get blacklisted from paypal. Stripe, Square, Venmo, Cashapp and all these other services are NOT YOUR FRIEND and they will snitch you out and close your account at the first sign of anything illegitimate. These financial institutions are so heavily regulated that they are essentially organs of the very state that is oppressing us. Stop trusting them!

Always assume your that exchange, bank, postman, and dentist are conspiring to build a case on you. Give them nothing to work with, get your coins off the exchange and swap them that same day. Say nothing to anyone. And if you are ever cornered for any reason, remember the magic words: I want a lawyer.

You never know when permissible actions today will come back at you in the future, ex post facto is not the shield you might think it is. If you want more info, look up the DNM bible. I'll certainly answer questions here or defend my position if someone else has a different doctrine.

Security doesn't have to be onerous or difficult, but there's a lot to learn if you're going to do it right.

Kraken has de-listed XMR since this thread was started.

Can I reasonably assume ZEC would work as a viable substitute for XMR?
I've never come across it before. That said, if the reason XMR got delisted is that it's a privacy coin, then ZEC is likely less private, given that it's still listed.
According to Google AI, "Zcash (ZEC) is the closest major alternative to Monero (XMR) regarding privacy and security, as it utilizes advanced zero-knowledge cryptography (zk-SNARKs) to completely hide transaction senders, receivers, and amounts.

While Monero(XMR) enforces mandatory privacy for every transaction, Zcash(ZEC) offers flexible privacy. Zcash(ZEC) allows users to choose between transparent addresses (similar to Bitcoin) and "shielded" addresses (which offer untraceable security identical to XMR)."

That's the reason I switched to ZEC after Kraken delisted XMR, and it's also why I asked.
you put faith in a marketing blurb, even though a basic non-AI search reveals they just dropped 38% because of a bug? I'm not saying it isn't private, it's just that it's less likely to be private than monero, otherwise it would be forced to be delisted.
A marketing blurb isn't something I put my faith in. The question below is actually what I asked at the start, in an attempt to work out whether ZEC could serve as a workable substitute for XMR. (Since whether it can or can't is something I genuinely don't know.)

boytres said:

mybodyisasewer said:

It's become painfully obvious to me that a huge number of newcomers here are in way over their heads and have zero grasp of opsec. That's why I'm putting together this schizo post.

I was present during the SR1.0 RC days (read my username literally), so the mere fact that I'm walking free ought to demonstrate that I understand what I'm doing.

Way too many people I see are buying bitcoin on a clearnet KYC exchange like Coinbase and then firing it directly at the vendor. That is pure insanity. The blockchain is public, your BTC address is not private, and the moment the vendor's address gets identified, you are tied to them permanently and forever.

A huge number of people have had their crypto accounts shut down for sending funds to gambling sites, peptide sites, foreign governments, donating to the wrong cause, and anything else the powers that be disapprove of. Would you write a check to your drug dealer? Don't do this.

Open a Kraken account, purchase XMR, and send that to a non-custodial wallet such as Cake Wallet. Cake lets you swap the XMR into BTC. Whose BTC are you receiving? Doesn't matter, you're paying a sketchy foreign agent, it's for the best. Decentralized exchanges are the best tool available for destroying the forensic trail between you and the vendor.

If using Kraken as an onramp gives you trouble, use any exchage of your choice to get crypto and transfer it to Kraken to get the XMR. Kraken is the only exchange I know of that supports this currency, as there is a lot of pressure to delist XMR because of what I'm about to explain.

XMR has not been cracked. Despite the FUD, the US government's bounty on XMR was never claimed. This breaks the traceable chain from your custodial clearnet funds to BTC that has never touched anything with your name on it.

Obviously, vendors should be taking XMR directly, but they haven't quite caught up to the DNMs, which typically REQUIRE payment in XMR. So we're just using it to create a forensic gap between you and the funds that reach the vendor. And if you think XMR is for criminals, fine, but I've seen a $20 treasury note do things you wouldn't believe, so let's try to have consistent standards.

If you are worried about the security of running your own wallet with a seed phrase and everything, do not keep any more money in there than you need for a single purchase.

However, it is beneficial to get your crypto off the exchnage as fast as possible. This gives you plausible deniability if they ever come at you for capital gains. You can say you sold immediately at the buy price, leaving them to prove how long you held the asset. If you do this right, they won't. Also we want to keep our taxes as simple as possible. Bringing your 1099-B to H&R Block so they can work out your pittance of capital gains tax is just rude and pointless. They will hate you for this and it will cost you extra for the return prep.

Use a VPN for everything. Obviously the exchange has KYC on you, but don't give them anything more than that. Broadcasting a transaction from your personal IP address is an unnecessary risk. You want your IP associated with as little as possible. Proton VPN and PIA are solid choices if you wanted a lead on that. They don't log, and their data has yet to be seen in any unsealed warrants.

Also, rememeber the basics. Use a password for your phone, not a pin, not biometric. Do not tell people you have crypto, they will immediately and correctly assume you are a criminal. Never unlock your phone for law enforcement. Cellebrite and Graykey do not work as well as advertised. I have been in a position to see a large enough sample size and that's all I'm saying.

Ideally, you wouldn't even use a phone for this, but a laptop running a linux live distro like TAILS. This depends on your risk tolerance and threat models.

Read off the addresses when you send. Just the first and last characters. A popular cyber attack is to compromise the clipboard and have you paste the attacker's receiving address when you send.

To recap:

Kraken XMR -> Cake wallet -> swap to BTC

Use a VPN.

Write down your seed somewhere, or don't, it's just a temporary parking spot for your next purchase, right?

Stop screwing around with solana and usdt and paypal and all that noise. It is horrifying to see people buying this stuff using an American KYC service. This is how you get blacklisted from paypal. Stripe, Square, Venmo, Cashapp and all these other services are NOT YOUR FRIEND and they will snitch you out and close your account at the first sign of anything illegitimate. These financial institutions are so heavily regulated that they are essentially organs of the very state that is oppressing us. Stop trusting them!

Always assume your that exchange, bank, postman, and dentist are conspiring to build a case on you. Give them nothing to work with, get your coins off the exchange and swap them that same day. Say nothing to anyone. And if you are ever cornered for any reason, remember the magic words: I want a lawyer.

You never know when permissible actions today will come back at you in the future, ex post facto is not the shield you might think it is. If you want more info, look up the DNM bible. I'll certainly answer questions here or defend my position if someone else has a different doctrine.

Security doesn't have to be onerous or difficult, but there's a lot to learn if you're going to do it right.

Kraken has de-listed XMR since this thread was started.

Can I reasonably assume ZEC would work as a viable substitute for XMR?
My use of ZEC started because buying XMR wasn't possible for me. Honestly, my crypto knowledge isn't deep enough for me to be sure it's private, safe, or a stand-in for XMR. It's just the route I've been taking as a temporary fix.

After my earlier posts, I've been digging for more information on a way to get untraceable coin, and here's what I've arrived at. Whether it's completely private I can't say, but with the crypto knowledge I have, this is the best conclusion I can reach...

Get LTC or SOL.

Send it over to Cake wallet.

Swap it for XMR.

Transfer it into a second wallet inside Cake wallet.

Convert that XMR into BTC - with a new seed inside Cake wallet.

If any of this is off, tell me. For my grey transactions, I'd like a fullproof way to obtain untraceable coin.
 
Alright, I'm extremely new here. Because of that, I can't even bring up buying anything at this point. Is all of this meant to keep our money safe, or is it about keeping us out of trouble for picking things up for our own personal testing? I realize it's a grey area, but the more I read, the less at ease I feel. In theory, I'd just prefer to use a CC and not have to think about it…
 
BigGuyInTN said:

Alright, I'm extremely new here. Because of that, I can't even bring up buying anything at this point. Is all of this meant to keep our money safe, or is it about keeping us out of trouble for picking things up for our own personal testing? I realize it's a grey area, but the more I read, the less at ease I feel. In theory, I'd just prefer to use a CC and not have to think about it…
Vendors will not take CC, so paying that way is not an option.

A few will take Alipay, and back in the day I came across a Vendor who accepted paypal, but Crypto remains the norm.

Go through the first post carefully; it lays out the logic very plainly, namely that this is about shielding you, your assets and your privacy.

If you want, the simple route is to buy some Crypto and send it straight to the Vendor, done.

But doing that carries the risk that your Crypto account gets flagged at some point as linked to a Vendor, after which the account is banned.

To obscure their identity and protect their accounts, people attempt various ways of rinsing their coin. For my part, I want traceability kept as low as possible.

I'm personally not bothered that people are aware I use peptides, however I dont want my Crypto wallets being compromised in any way. And I dont know what else the Vendor is embroiled in, I certainly don't want tied to any other possible criminality.
 
BigGuyInTN said:

Alright, I'm extremely new here. Because of that, I can't even bring up buying anything at this point. Is all of this meant to keep our money safe, or is it about keeping us out of trouble for picking things up for our own personal testing? I realize it's a grey area, but the more I read, the less at ease I feel. In theory, I'd just prefer to use a CC and not have to think about it…

boytres said:

BigGuyInTN said:

Alright, I'm extremely new here. Because of that, I can't even bring up buying anything at this point. Is all of this meant to keep our money safe, or is it about keeping us out of trouble for picking things up for our own personal testing? I realize it's a grey area, but the more I read, the less at ease I feel. In theory, I'd just prefer to use a CC and not have to think about it…
Vendors will not take CC, so paying that way is not an option.

A few will take Alipay, and back in the day I came across a Vendor who accepted paypal, but Crypto remains the norm.

Go through the first post carefully; it lays out the logic very plainly, namely that this is about shielding you, your assets and your privacy.

If you want, the simple route is to buy some Crypto and send it straight to the Vendor, done.

But doing that carries the risk that your Crypto account gets flagged at some point as linked to a Vendor, after which the account is banned.

To obscure their identity and protect their accounts, people attempt various ways of rinsing their coin. For my part, I want traceability kept as low as possible.

I'm personally not bothered that people are aware I use peptides, however I dont want my Crypto wallets being compromised in any way. And I dont know what else the Vendor is embroiled in, I certainly don't want tied to any other possible criminality.
Yeah, everything said above lines up with how I see it. If this ends up being a path I go down, it sounds like there's a lot I still need to work out, since privacy does matter to me.
 
So the core problem you're facing isn't whether you can dodge KYC (Know your Customer) when buying crypto entirely. Picture this: you've got yourself a 'securely anonymous' wallet, and you've gone through the hassle of locating some random person willing to send crypto straight to your wallet in return for cash or another form of collateral. Even then, your address or delivery location remains your biggest vulnerability, and it always WILL be. Getting a package reliably without revealing something about yourself is basically impossible - a p.o box still carries the KYC problem, and any kind of postal 'service' that forwards deliveries runs into the same wall (plus every one of those layers adds complexity and drives up the cost). Sure, if you run a business with a business address that has plenty of employees, you could have the package sent there, and it turns into a genuine headache for anyone trying to prove it was meant for you. But again, if the products carry a name nobody recognizes, whoever handles the deliveries will either send it back to the sender or it eventually becomes a problem anyway, because packages keep arriving without your name on them, which by itself looks suspicious. If you're having things sent to your own address, even under a different name, it won't take the vendor OR anyone else who gets hold of that information long to work out who you actually are, provided they're willing to put in a bit of effort. So even with wallet mixing and crypto obfuscation, your $$$ is mostly protected, but your identity really isn't, nor is the whole "Let's narrow it down to x number of people"
 
Fabulous_Jackal said:

So the core problem you're facing isn't whether you can dodge KYC (Know your Customer) when buying crypto entirely. Picture this: you've got yourself a 'securely anonymous' wallet, and you've gone through the hassle of locating some random person willing to send crypto straight to your wallet in return for cash or another form of collateral. Even then, your address or delivery location remains your biggest vulnerability, and it always WILL be. Getting a package reliably without revealing something about yourself is basically impossible - a p.o box still carries the KYC problem, and any kind of postal 'service' that forwards deliveries runs into the same wall (plus every one of those layers adds complexity and drives up the cost). Sure, if you run a business with a business address that has plenty of employees, you could have the package sent there, and it turns into a genuine headache for anyone trying to prove it was meant for you. But again, if the products carry a name nobody recognizes, whoever handles the deliveries will either send it back to the sender or it eventually becomes a problem anyway, because packages keep arriving without your name on them, which by itself looks suspicious. If you're having things sent to your own address, even under a different name, it won't take the vendor OR anyone else who gets hold of that information long to work out who you actually are, provided they're willing to put in a bit of effort. So even with wallet mixing and crypto obfuscation, your $$$ is mostly protected, but your identity really isn't, nor is the whole "Let's narrow it down to x number of people"
I'm with you — when it comes to this particular angle, there isn't much you can realistically do to fully conceal who you are.

As far as I'm concerned, I don't get too worked up about people finding out that I do my own peptide "research". Buying and keeping peptides is still completely legal, for research purposes only, naturally.

The thing that actually concerns me, and what I'm attempting to keep hidden, is my personal financial accounts and the possibility of those accounts being digitally tied to a vendor. This has caused problems, and continues to cause them, for plenty of users — accounts getting frozen, banned and shut down. Anyone foolish enough to leave their investments sitting in the same wallet they use to pay vendors is taking an enormous risk with those finances. If there were any steps I could take to lower that risk, I'd rather take them.

Once more, this comes down to personal preference. I'm no crypto expert either — I'm just here trying to pick up whatever I can so I can stay safe where it's possible.
 
Back
Top