How to read this list
Each habit is rated on two things: how much it protects (what leak it closes) and what it costs you in effort. Start at the top; the first four close most of the exposure most people have, and none of them cost money.
1. Never reuse an address โ protection: very high, cost: none
Address reuse is the single largest source of de-anonymisation on transparent chains. Every payment to the same address is trivially linked; one identified payment identifies all of them. Modern wallets generate a new address per receipt automatically โ let them. For Monero, use a new subaddress per counterparty. For a swap, give a fresh receiving address every time.
2. Keep an exchange's withdrawal and your private activity apart โ protection: very high, cost: one extra transaction
A KYC exchange knows the address it withdrew to. If that address then pays a swap deposit, a merchant or a mixer, the exchange โ and anyone who obtains its data โ knows too. Withdraw to your own wallet, then act from your wallet. Withdraw โ wallet โ swap, never withdraw โ swap.
3. Convert to a privacy coin when the received side must be private โ protection: very high for what it covers, cost: a swap
Transparent coins cannot be made private after the fact; a privacy coin can be the destination instead. BTC โ XMR makes everything after the swap invisible to chain analysis; USDT (TRC-20) โ XMR does the same from a stablecoin. The transparent side of the swap remains public โ that is what habits 1 and 2 are for.
4. Do not link amounts and timing โ protection: high, cost: patience
A withdrawal of 0.0473 BTC followed eleven minutes later by a swap deposit of 0.0473 BTC is a link, even across a privacy break. Use round amounts, split, or wait. The same applies to the receiving side: an XMR โ BTC payout that lands on an exchange in the exact amount you sent is a link too.
5. Use Tor or a VPN for wallet and exchange traffic โ protection: medium-high, cost: low
Your IP is visible to every website and to the nodes your wallet broadcasts through. Tor Browser for websites; Tor or a reputable VPN for the wallet's node connection. Monero wallets can route over Tor natively; Bitcoin wallets vary. This closes the network-level link between your location and your transactions.
6. Prefer your own node โ protection: medium-high for a specific threat, cost: hardware and time
A light wallet asks a server about your addresses; the server learns them. A remote Monero node learns which outputs you scan. Running your own node removes that party entirely. It matters most for Monero (where the remote node is the main leak) and for Bitcoin light clients; it is the most effort on this list.
7. Keep the swap's status link, nothing else โ protection: medium, cost: none
An account-free swap gives you a status page identified by its link. It is your record of the transaction; it is not stored against your name anywhere. Save it somewhere private (a password manager note). Do not email it to yourself from a work account.
8. Separate wallets by purpose โ protection: medium, cost: some discipline
One wallet for exchange interactions, one for private holdings, one for spending. Coins should flow between them only through a privacy break (a Monero swap) or not at all. Mixing purposes in one wallet re-links everything you separated.
9. Check what your stablecoin can do to you โ protection: medium for a specific threat, cost: reading
USDT and USDC issuers can freeze addresses on request. That is not a privacy leak, but it is a control lever, and it operates on the address. If freeze risk is part of your model, hold balances in a native coin rather than a stablecoin, and use stablecoins as a transit, not a store. The USDT network guide covers the differences between rails.
10. Assume every third party keeps records โ protection: mindset, cost: none
Exchanges, block explorers you paste addresses into, portfolio trackers you give your xpub to, merchants, and DNS resolvers all see something. Each one is a potential leak, breach or subpoena target. Give each the minimum, and prefer services that structurally cannot record who you are โ which is the point of an account-free exchange.
What is not on the list
- Mixers and tumblers for Bitcoin. Legally contested in several jurisdictions, frequently scams, and inferior to a privacy coin for the same purpose.
- "Privacy" browser extensions and paid anonymisers. Mostly no effect on chain-level privacy.
- Fresh exchange accounts. A new KYC account is a new copy of your ID, not privacy.
A minimal routine, if you only do one thing per step
- Withdraw from any exchange to your own wallet.
- Swap to Monero from that wallet โ BTC โ XMR or USDT (TRC-20) โ XMR โ receiving to a fresh subaddress.
- Hold, spend or swap back later to a fresh address โ XMR โ BTC.
Three steps, no accounts, and the received side is private by construction.
Frequently asked questions
Is Bitcoin private if I follow all of this? No โ Bitcoin is public. The habits limit who can link the public data to you. Only a privacy coin hides the data itself.
Do I need Tor and a VPN? One or the other for most people. Tor for websites and Monero wallet traffic is the stronger option; a VPN is the convenient one.
Does a hardware wallet improve privacy? It improves key security, not privacy. Its companion app is often a light client that reveals your addresses to a server โ habit 6 applies.
What about Lightning? Lightning payments are more private than on-chain Bitcoin in some respects (no global ledger of payments), but channel opens and closes are on-chain, and routing nodes see part of the path. It is not a substitute for a privacy coin.
Where do these habits matter most? At the boundary between an identified account and your own wallet. Everything on this list is about keeping that boundary clean.
BTC โ XMR
XMR โ BTC
USDT (TRC-20) โ XMR