Skip to content

Ermine — case study

Ermine

Ermine — a claim I measured, and then had to narrow

A Monero wallet built so that using it leaves as little trace as possible: it talks only to your own node, gives each account its own route through Tor, and keeps everything in a file that does not reveal how much is in it. It is not finished, and the interesting part is a sentence I had to take off its website.

See the project site
The Ermine site, with a permanent banner across the top saying the wallet is in early development and there is nothing to download yet

The claim

If a wallet holds several accounts and they all reach the network down the same path, the machine on the other end can see that they arrive together, and two identities you were keeping apart are one identity. So each account gets its own circuit through Tor. Nothing in the published Rust Monero stack does this, so the transport is written here: one isolation token per account, held in a map because the Tor library's token is an opaque counter with no way to derive one from an account number.

Writing that is easy. Knowing it works is not, and the website was already making the claim.

Measuring it properly meant going a layer down

To see whether two accounts really got different circuits, it is not enough to observe that the traffic worked. The measurement reaches below the ordinary Tor client interface to read each connection's actual circuit identity and relay path from inside the library.

It also needed a control that is easy to skip. Without one, the observation "different accounts got different circuits" is equally consistent with the library simply handing every new stream a fresh circuit — which would say nothing at all about whether the isolation tokens work. So the same account is measured twice as well, and has to come back on the same circuit for the result to mean anything.

The earlier draft was wrong, and wrong in the sentence most likely to be quoted.

What the measurement actually supported

  1. 1

    The circuits do differ

    Separate accounts get separate circuits, and the same account reuses its own. The mechanism works as designed.

  2. 2

    But two circuits can still leave by the same door

    Independent circuits can independently choose the same exit relay, and the choice is re-rolled every time a circuit rotates, so over a long block scan the chance of a collision grows rather than staying fixed.

  3. 3

    And they share a guard, which is correct and still worth saying

    All the accounts entered through the same guard relay. That is how Tor is supposed to work and changing it would be worse — but it means one relay sees one client, which is not the same as seeing nothing.

  4. 4

    Network isolation does nothing about timing

    Accounts scanning the same blocks at the same time are correlated by when they act, and no amount of separate circuits touches that.

So the sentence on the site changed. "Your accounts can never be linked by the network" became "each account gets its own Tor circuit, so the node cannot tie your identities together by connection" — narrower, and true. The findings document also records what the evidence is not: one observation per pair of accounts, taken from inside the wallet's own process, with no view from an adversary's side.

The rest of the build

A file that does not count itself

The wallet container holds thirty-two key slots behind a fixed-size header, and every byte past that header is indistinguishable from random — so the file does not reveal how many wallets are inside it. Changing a passphrase rewrites one small slot rather than re-encrypting everything.

Your node, not someone else's

The wallet speaks the daemon's own binary protocol, including a hand-written codec for it, rather than depending on a public remote node that would see every address it asks about.

A dependency graph that enforces the design

The encrypted store depends on no other part of the wallet, and the transport knows only URLs and bytes. Choosing Tor is a constructor argument, so the code that understands consensus can never reach the code that opens a connection.

Where it actually is

In progress, and honestly so. The workspace builds and four hundred and thirty-nine tests pass, with the ones needing a live Tor network or a multi-minute chain scan gated and labelled with why. There is no graphical wallet and no command-line wallet: the only program that exists is the acceptance harness. Nothing is packaged, there is nothing to download, and the project's own site says so in a banner across the top of every page rather than in the small print.

In development

Watch it rather than install it

There is nothing to run yet. The site explains what it will do, marks what is built against what is planned, and has a list for launch.

erminewallet.org