Monero: The Crypto That Forgets
This time: Monero, the most hunted coin alive.

Reach into your pocket and pull out a banknote. Any note. Look at it for a second.
It doesn’t know your name. It doesn’t remember the last hand it was in, or what they bought, or whether they were a saint or a crook. It carries no history and it asks no permission. You can hand it to anyone alive and no one, anywhere, gets a record. We’ve had money like this for thousands of years, and we barely notice how quietly radical it is.
Now here’s the thing almost nobody has clocked. The money were building to replace that note has a perfect memory. And there’s exactly one coin that looked at that and said, no. Money should forget. Its called Monero, ticker XMR, and it is the most hunted, most misunderstood, and quietly most principled project in all of crypto.

This is issue three of The Teardown, where we take one coin at a time and open it up like the back of a watch, to understand the machine, not the price. A couple of issues ago we cracked open Zcash, the coin that lets you switch privacy on. Today’s coin is the answer to Zcash’s biggest weakness, and it gets there by doing the one thing Zcash never dared: taking the switch away.
Ill go slow, like always. Not investment advice, and honestly this might be the hardest coin in the whole series to even buy, and the one most likely to earn you a funny look. I just went down the rabbit hole of how it works and why it exists, and it left me thinking harder about what money even is than anything else in crypto. Let me show you.
What a banknote quietly does
Stay with that note in your hand, because its hiding the whole point.
A banknote works precisely because it has amnesia. It doesn’t remember where its been, which means every note is equal to every other note of the same value. A ten from a church collection spends exactly like a ten from a card table. Nobody inspects its past. Nobody can refuse it because of where it slept last night.
Economists have a clumsy word for that equality: fungibility. It just means one unit is perfectly interchangeable with any other. Boring word, enormous idea. Its the thing that quietly lets money be money at all.
The money we are building never forgets
Now look at what we are building to replace cash. On a normal blockchain like Bitcoin, every coin carries its entire life story, permanently, in public. Every payment it was ever part of is written on a shared wall that anyone on Earth can read, forever. (If thats new to you, how blockchain actually works lays the floor for all of this.)

That sounds harmless, even virtuous. Transparency. Honesty. But follow it one step. If every coin remembers everywhere its been, then coins stop being equal. A coin that once passed through a hack, or a sanctioned wallet, or a gambling site, picks up a reputation. Exchanges flag it. Services refuse it. It can be frozen, or quietly treated as worth less than a clean coin of the very same value.

Sit with how strange that is. Two identical coins, the same number stamped on each, and one is worth less, or gets you investigated, purely because of a stranger who held it three owners ago. That is money losing the one magic property cash always had. It is money that can be punished for its past. And once money can be judged, it can be steered.
Enter the coin that forgets
Monero, born in 2014, exists to rebuild the amnesia of cash for the internet. Its goal, stated plainly, is to be digital money that is private, and therefore equal, by default. Not private if you flip a setting. Private always, for everyone, no exceptions.
And that single design choice, mandatory privacy, is the key to the whole coin. Its also where it breaks hard from Zcash.

Remember Zcash’s honest weakness. Privacy there was optional, a shielded mode you chose to turn on, and because most people never bothered, the crowd you hid inside was thin, which made the hiding weaker. Monero looked at that exact problem, years earlier, and made the opposite, radical call. It removed the off switch entirely. On Monero there is no transparent option. Everyone is private, whether they care or not.
You cant be anonymous alone
Here’s why that matters far more than it first sounds, and its genuinely beautiful.
Privacy, it turns out, is not something you can really have by yourself. Picture a public square where every face is bare, and you alone put on a mask. You havent hidden. Youve done the opposite. Youve made yourself the single thing everyone notices. A crowd with one masked person in it hides nobody.
But if everyone in the square is masked, suddenly no single person can be picked out, and your mask is now protecting the stranger beside you as much as it protects you. Privacy becomes a herd. A thing you can only truly have together.

That is Monero’s whole philosophy in one picture. By pulling everyone into the crowd, it keeps the crowd permanently full, and everyone’s privacy holds up everyone else’s. You cant be anonymous alone. So on Monero, no one is asked to be.
One honest word before we go under the hood
Quick pause, friend to friend. What’s coming next is the actual machinery, three clever pieces of cryptography, and its the good stuff. If a part needs a second read, that’s not you failing, that’s you learning something most people who own this coin have never bothered to understand. Ill build it slowly. I’m not here to keep you nodding along at the same lines everyone repeats. I want you to walk away actually knowing this. Onward.
How it hides three things at once
To make a payment truly private, you have to hide three separate facts, and Monero uses a different tool for each. This is the part I love, because none of the three is redundant. Each one plugs a hole the other two leave open.
Fact one, who sent it. Monero hides the sender with something called a ring signature. When you spend your coins, your real coin is mixed into a lineup with a batch of decoys, other real coins pulled from the blockchain’s own history. The signature that authorises the payment proves that one coin in the lineup is genuinely yours and is being spent honestly, yet it gives away no clue which one. An observer sees, say, sixteen possible senders, and cannot tell the real one from the decoys.

Fact two, who received it. Monero hides the receiver with a stealth address. Even if you hand out a single public address, every payment sent to you is quietly redirected to a brand-new, one-time address that only you can detect and unlock. So your real address never appears on the chain, and no two payments to you can ever be linked together. A fresh disposable mailbox for every single payment, and only you hold the keys.

Fact three, how much. Monero hides the amount with a piece called RingCT. The number is sealed inside cryptographic commitments, so no observer can read it, and yet the network can still do the one check that matters, confirming that the money going in equals the money coming out, so nothing is ever conjured from nothing.

Put those three together, sender hidden, receiver hidden, amount hidden, then add a fourth layer that scrambles which computer first announced the payment so your internet address doesn’t betray you, and you get a transaction that leaks almost nothing. Four locks, each shutting a different kind of spy out.

There is a lovely detail I have to mention, because we met it last time. A hidden-coin system has the same puzzle Zcash had. If nobody can see which coin you’re spending, how does the network stop you spending it twice? Monero solves it almost identically. Each coin, when spent, produces a unique unforgeable marker, a key image, that reveals nothing about the coin but comes out identical if you ever try to spend that coin again. Spend twice, the same marker appears, and the network rejects it. Same elegant trick, different coin.
The upgrade that turns sixteen into everyone
Now, that lineup of decoys has a limit. For years the ring held only about sixteen possible senders. Better than nothing, but a determined analyst with enough data could sometimes make educated guesses about which was the real one.
So Monero is rolling out the biggest cryptographic upgrade in its history, with a name only a mathematician could love, full-chain membership proofs. In plain terms, instead of hiding your coin among sixteen decoys, it hides it among every coin that has ever existed on the entire blockchain. Tens of millions of them. The whole haystack.

The community calls it going from a padlock to a vault door, and its powered by the same family of proof-magic we saw inside Zcash. When it fully lands, guessing which coin was really spent goes from merely hard to effectively hopeless.
The most honest money in the room
Theres one more thing about Monero almost nobody talks about, and it genuinely moved me.
There was no pre-mine, where founders quietly keep a fat slice for themselves before anyone else can join. No ICO, no big sale to insiders. No company sitting on a treasury of coins. No venture investors with tokens waiting to unlock and land on your head. Every single Monero in existence was mined, coin by coin, in the open, by people running the software. What you see is the entire supply, with nothing hidden behind it. In a space absolutely riddled with insider allocations and quiet enrichment, that is stunningly rare.

It even mines in a deliberately egalitarian way, using an algorithm tuned so that ordinary computer processors stay competitive, to keep mining in the hands of many small players instead of a few industrial giants.
There is one genuine catch here, and I wont skip it. Unlike Bitcoin’s famous hard cap of twenty-one million coins, Monero never stops issuing entirely. A small, fixed reward keeps being minted forever, a gentle trickle of new coins, mild inflation that fades over time but never fully dies. To the hard-money crowd, that’s close to heresy. Monero’s builders made the choice on purpose, arguing that a network has to keep paying its miners to stay secure, and that relying on transaction fees alone one day, as Bitcoin plans to, is a dangerous bet. You can disagree with the choice. But its a considered, honest one, not an accident.
The most hunted coin alive
Now the hard part, and it is very hard.
Actually delivering money that forgets has made Monero the most aggressively hunted asset in all of crypto. Because the same amnesia that protects an ordinary person also protects a criminal, Monero is the coin governments least want to exist.
The result has been a slow siege. Through 2024 and 2025, dozens upon dozens of exchanges, including some of the biggest names, removed Monero, many of them under pressure from new rules in Europe and outright bans in countries like Japan and South Korea. Europe is preparing rules that would push privacy coins off regulated platforms almost entirely by 2027. Years ago, a tax authority literally posted a bounty, real money, for anyone who could reliably crack Monero’s privacy. By and large, that bounty went unclaimed.

And heres the twist that tells you something deep. It didnt die. Kicked off the big exchanges, Monero’s community simply built its own doors, peer-to-peer marketplaces and atomic swaps that let people trade directly, wallet to wallet, with no company in the middle to lean on or shut down. Push hard on genuinely decentralized money and, maddeningly for regulators, it tends to just route around the pressure and come out more resilient. Being un-listable turned out to be a strange kind of strength.
The honest scratches
You deserve the whole picture, so, plainly, the rest of the downsides.
The reputation is real. Monero genuinely is a preferred coin for a lot of illicit activity, precisely because it works, and that stigma is not going away. Unlike Zcash, it offers no easy built-in way to selectively reveal your history to, say, an auditor or a tax office. Its closer to all-or-nothing, which makes it genuinely harder to square with regulation, though you can, if you choose, hand someone a key to view specific payments. Its privacy is strong but not magic. Researchers have probed weaknesses over the years, and the network has had scares, including moments where a single mining group grew uncomfortably large. And being delisted almost everywhere is not only a badge of honour, its a real practical problem, because thin liquidity and hard access genuinely hurt ordinary holders.
None of that makes Monero a scam. And none of it makes it a sure thing. It makes it exactly what it is, the most serious attempt anyone has made to rebuild cash for the internet, carrying both the freedom and the danger that cash has always carried.
The one idea to keep
Forget the words ring signature and stealth address by next week if you like. Keep this instead, because it will quietly change how you look at every kind of money for the rest of your life.
Ask of any money, does it remember?

Three questions. Can two units of it be told apart by where they’ve been? Can one unit be frozen, taxed differently, or refused because of its past, while an identical unit is fine? And does spending it leave a permanent record that could one day be used against you? The more yeses, the more that money can be sorted, judged, and controlled. Cash forgets, and that forgetting is a freedom we never even had to think about. Monero is the attempt to keep that freedom alive as money turns digital. Once you start seeing money this way, you cant unsee it.
Where this comes home
So, three issues into cracking these things open, a map is forming, and its worth pinning to the wall.

Bitcoin fought to be money that cant be censored. Zcash fought to be money that cant be watched. Stellar chose to be money that can be frozen and cleared, so that institutions would actually use it. And Monero fights to be money that cant be told apart, money with no memory, where every coin is equal. Four coins, four completely different answers to a question almost nobody stops to ask: what should money be?
And that lands us right back on the thread this whole newsletter keeps pulling. Ive argued for a long time that the world is drifting, slowly and unstoppably, toward shared digital money-rails, which we walked through in what settlement layer really means and the convergence. That future is coming. But if all of it runs on money that remembers everything, we will have built something genuinely new under the sun. Money as a permanent, searchable record of every human life, readable by whoever holds power, and usable to reward, punish, freeze, and steer. As tax systems already scan transparent chains in milliseconds, that world is not a fantasy. Its a roadmap.

Monero is the stubborn argument that the coming on-chain world needs at least one money that forgets. Not so criminals can hide, that is the cost of the thing, not its purpose, but so that money cannot quietly become a leash. Because almost everyone, if they’re honest, has something in their spending they’d simply rather the whole world not see. Not because its a crime. Because its theirs.
Whether XMR the coin thrives or gets regulated into a corner, I don’t know, and I’m not here to tell you. But the question it is fighting over, whether money in the digital age gets to forget, may be one of the most important questions of the century. And now, at least, you can see that the question is even being asked.
Money that remembers can be controlled. Money that forgets stays free. Monero picked a side. Now you know why.