The First Post-Quantum Private Money

MoneroUSD (USDm) is true digital cash — a dollar-pegged stablecoin on the world's first private, zero-knowledge block-DAG. Every payment is untraceable and quantum-proof, and settles in under two seconds. It's also the foundation of a complete post-quantum DeFi ecosystem: swap, message, pay, build, and explore — all with zero metadata revealed.

$ 1 USDm = 1 USD — protocol-enforced · post-quantum · zero metadata

$1.00
Protocol Peg
~500ms
Block Time
<2s
Absolute Finality
~45 KB
Whole-Chain WHIR Proof
32
DAG Width — Absorbs Tor Latency
150%+
Min Reserve Ratio

A List of Firsts

Not an iteration of anything — a genuinely new kind of money. Watch each breakthrough actually work.

01

The First Private zk-DAG

Every other private coin runs a single-file chain. MoneroUSD is a GHOSTDAG block-DAG — blocks confirm in parallel lanes and link to many parents, so the ledger is fast and leaderless. Each block seals itself with its own zero-knowledge proof and carries the identical constant-256 cover, so the graph you're watching reveals nothing about who paid whom.

GHOSTDAG width 32 by defaultper-block WHIR proofconstant-256 cover
02

Post-Quantum at Every Layer

ML-KEM-768 encryption, ML-DSA-65 signatures, Poseidon2 hashing, WHIR proofs — and not a single elliptic curve anywhere. A quantum computer can't unwind today's transactions tomorrow: harvest-now-decrypt-later simply bounces off. The first money built to outlive the quantum era.

ML-KEM-768ML-DSA-65Poseidon2WHIR
03

True Digital Cash

Every block records exactly 256 notes and 256 spend tags — real payments hidden among byte-indistinguishable cover, shuffled to random positions. Scan the chain as any node, indexer, or global adversary: count, volume, timing, amounts, identities — all invisible. One note is one dollar bill.

zero metadataconstant shape every blockindistinguishable cover
04

PQ FCMP++ Membership

MoneroUSD's own post-quantum Full-Chain Membership Proofs. A spend proves it references a real, unspent note somewhere in the entire chain — millions of candidates — without ever pointing at one. No decoy rings, no heuristics to attack: the proof closes and not a single note lights up.

anonymity set: the whole chainno decoy selectionquantum-safe ZK
05

O(1) at Any Height

The chain grows forever; the node doesn't grow at all. State, RAM, and proof size stay constant at any height — notes are stored nowhere and regenerated on demand. A phone verifies the whole chain from a single WHIR proof of about 45 kilobytes — the megabyte-scale STARK it replaces is retired — whether the chain is a day or a decade old.

~45 KB whole-chain WHIR proofinstant syncphone-class RAM
06

Absolute Finality, Under 2s

Blocks land about every 500 milliseconds, and a post-quantum finality certificate makes settlement absolute in under two seconds — card-swipe fast with cash finality. No probabilistic waiting, no rollback window, no "wait for six confirmations."

~500 ms blocksPQ finality certificateno rollback
07

The First 100% Tor-Native Chain

Every node speaks only over Tor v3 onion services — there is no clearnet path in the protocol at all — and constant-rate cover cells make even packet timing meaningless. The DAG's default width of 32 absorbs onion latency completely: blocks confirm in parallel while packets take the scenic route, so total network privacy costs zero speed.

onion-only transportconstant-rate cover cellswidth 32 absorbs Tor latency
Trustless by construction — no trusted party for soundness or liveness
Useful-work mining — the mining hardware is the proving hardware
Checking the chain's live confidential-solvency attestation…

One Ecosystem, Fully Private

Everything you can do with money — reimagined post-quantum, node-first, and metadata-free. Your node is the hub; every app orbits it.

💳

USDm Wallet

The first post-quantum private desktop & mobile wallet. Sub-second sends, a live mirror of your own node, and a built-in browser that opens every ecosystem app.

🔄

Ion Swap

A fully private DeFi exchange — swaps, liquidity pools, one-click token launches, DCA, yield, and NFTs — running entirely on your node, with no order-flow or balances leaked.

✉️

Letter

Private messaging that works like sending a sealed letter: ML-KEM-768 handshake, ML-DSA-65 authentication, onion transport, and a metadata-blind relay. Nobody can see who wrote to whom.

💼

USDm Pay

A private, self-custodial bank in your pocket — pay by @username, tap-to-pay at the register, and a spend-bounded card key. The privacy of cash with the convenience of a card.

🔮

Explorer

A novel private block explorer: real proving power and TPS, with a constant 256 transactions shown for every block — because a true-cash chain must never reveal how many payments really happened.

💻

MonerousD IDE & DSOL

Write and deploy smart contracts on DSOL — a post-quantum contract VM — straight from an in-browser IDE. Programmable money that keeps every layer quantum-safe and private.

🖥️

Run a Node

The chain is the backend, so anyone can host it. One click runs a full post-quantum node — O(1) state, instant sync, onion transport — that produces, verifies, and serves the whole ecosystem.

🌐

Sovereign Hosting

Every app here is served by the chain itself — the node is the backend. No cloud, no VPS, no single point to censor or take down. The network hosts the network.

How It Works

Three steps to private, stable money.

01

Create Your Wallet

Generate a recovery seed. That's your only credential — no accounts, no email, no identity verification. Your seed alone restores your full balance and spendability from the chain, at any height, forever.

02

Fund with Crypto

Swap BTC or XMR for USDm at live market rates, backed at 150% — deposit $150 of crypto to receive 100 USDm. Every USDm is overcollateralized from the moment it exists, so the reserve can only grow.

03

Spend Privately

Send USDm to anyone in under two seconds. PQ FCMP++ membership proofs plus constant cover traffic make every payment untraceable — your balance, your history, your identity, and even how often you pay stay private.

one payment, end to end every stage post-quantum + zero-metadata

Download

Native desktop wallet for every platform.

macOS

v1.2.98 — Apple Silicon & Intel
Coming Soon — Mac (Apple Silicon) Coming Soon — Mac (Intel)
💻

Windows

v1.2.86 — 64-bit
Coming Soon — Windows
🐧

Linux

v1.2.86 — AppImage
Coming Soon — Linux

macOS Users: Allow App to Run

MoneroUSD is not signed with an Apple Developer certificate, so macOS will show "damaged and can't be opened." To fix this, open Terminal and run:

sudo xattr -rd com.apple.quarantine "/Applications/Monero USD Wallet.app" && sudo codesign --force --deep --sign - "/Applications/Monero USD Wallet.app"

This removes the quarantine flag and ad-hoc signs the app locally. You will be prompted for your Mac password. If it still doesn't open, go to System Settings → Privacy & Security and click "Open Anyway" next to the MoneroUSD message.

PQ FCMP++ — Privacy That Survives Quantum

MoneroUSD's own post-quantum Full-Chain Membership Proofs — the strongest transaction privacy ever shipped, and the only kind a quantum computer can't unwind.

The anonymity set is the whole chain

PQ FCMP++ (post-quantum Full-Chain Membership Proofs) replaces decoy selection entirely. A spend proves — with Poseidon2 commitments and a WHIR zero-knowledge proof, no elliptic curves anywhere — that it references a real, unspent note somewhere in the entire chain. Millions of candidates, zero information leaked. Double-spends are blocked by an O(1) nullifier accumulator while the spent note stays unlinkable, and the proof is a constant few tens of kilobytes that verifies in milliseconds on a phone — at any chain height, against any quantum adversary, forever.

no rings, no heuristicsKB-scale constant proofquantum-safe forever

Ring Signatures (Legacy)

  • 11–16 decoy outputs per input
  • Statistical analysis can narrow candidates
  • Classical curves — breakable by a quantum computer
  • Privacy degrades over time with chain analysis

PQ FCMP++ (MoneroUSD)

  • Every note on-chain is a candidate — millions
  • Zero-knowledge proof — no information leakage
  • Post-quantum — safe against quantum adversaries
  • Privacy is cryptographic, not statistical

FAQ

Common questions about MoneroUSD.

USDm is true digital cash — a stablecoin pegged 1:1 to the US dollar on the first-ever post-quantum private zero-knowledge block-DAG. It gives you the privacy of physical cash (zero value, identity, or metadata revealed) with the stability of a dollar. There's no centralized issuer — the peg is enforced at the protocol level through consensus rules, and every cryptographic layer is quantum-safe.
Every USDm is backed by at least $1.50 of BTC or XMR held in the protocol's reserve wallets. Swaps mint at a 1.5:1 ratio (deposit $150 → receive 100 USDm), so the reserve grows with every entry. Auto-mining is gated by reserve health and halts if the ratio would drop below 150%. Staking yield is funded only by loan interest — reserves are never drawn down to pay yields.
Ring signatures hide your transaction among 11–16 decoys, but statistical analysis can narrow the candidates over time. PQ FCMP++ references every note on the entire chain, using a post-quantum zero-knowledge proof to verify without revealing which note is yours — so the anonymity set goes from ~16 to millions, and it can't be unwound by a quantum computer.
Yes. MoneroUSD uses a novel post-quantum Proof-of-Useful-Work built on the Poseidon2 hash — the same hardware that mines also produces the chain's zero-knowledge proofs, so mining energy does double duty. It runs efficiently on consumer CPUs; start with one click from the wallet, no external software needed.
No. Your 25-word seed phrase is generated locally on your device and never transmitted to any server. It is the sole key to your wallet — if you lose it, your funds cannot be recovered. Write it down on paper and store it securely.
macOS applies a quarantine flag to apps downloaded from the internet that aren't signed with an Apple Developer certificate. MoneroUSD is open-source and not signed by Apple. To run the app, open Terminal and run: sudo xattr -rd com.apple.quarantine "/Applications/Monero USD Wallet.app" && sudo codesign --force --deep --sign - "/Applications/Monero USD Wallet.app" — this removes the quarantine flag and ad-hoc signs the app locally. If it still won't open, go to System Settings → Privacy & Security and click "Open Anyway."
Open the wallet (browser or desktop), go to the Swap tab, select BTC or XMR, enter the amount, and confirm. The protocol mints at a 1.5:1 ratio — for every $1.50 of crypto you deposit, you receive 1 USDm. This overcollateralizes every mint from creation. Your rate is locked at the moment of swap creation using median oracle pricing.
Yes. The desktop wallet includes a "Create Node" button that can build and run a local MoneroUSD node directly on your machine. Running your own node gives you full sovereignty — you verify transactions yourself without trusting any third-party server.

Download the Wallet

Download the native desktop wallet for macOS, Windows, and Linux. Your keys never leave your device.

Download Now