SwapSS learn

Churning Monero: what the evidence supports and what it does not

Churn advice is stated with far more certainty than any measurement behind it. Sending coins to yourself does something real, but it is narrower than the advice implies, the arithmetic people quote does not survive contact with measurement, and there are ordinary situations where an extra hop hands an observer a link it did not have.

What a churn is, and the one thing it buys

A churn is a transaction from your wallet to your own address. On the chain it is unremarkable: a new output carrying its own fresh ring. What it buys is another layer that someone tracing forward has to guess through, plus a new set of decoys around your output. What it does not touch is what your counterparty already knows. The service, merchant, or person who paid you knows the address they paid, the amount, and the minute. No number of hops edits that record.

The arithmetic everyone repeats is optimistic

The standard claim is that three churns at ring size 16 leave a one-in-16-cubed chance of linkage. That assumes every ring is sixteen equally plausible candidates. Measurement says otherwise: OSPEAD estimated the average success of the strongest statistical guess against the default decoy selection since August 2022 at 23.5 percent per ring, an effective ring size near 4.2. The two figures are not perfectly comparable, since the statistical attack keys on output age and a churned output has an unusual age profile, but the direction is not in doubt. Sixteen is a ceiling rather than the working number, and compounding a ceiling produces a comforting answer instead of a true one.

Does a churn stand out? The one serious study says less than assumed

In October 2024 Cypher Stack published the first rigorous attempt at the question, constructing a uniformly most powerful test - the strongest test of its type - for classifying which transactions on the chain are churns. The finding was that the test is unreliable in practice: at conventional thresholds it labels roughly 95 percent of ordinary transactions as churns, which makes the label close to meaningless. Rucknium reviewed it days later, calling it an important contribution to a research question that had evaded rigorous analysis for years, while noting its limited scope and that a complete picture of churning’s effectiveness will require more research. That is the honest state of the evidence: one narrow, encouraging result surrounded by open questions.

Where churning does not help at all

Four situations where hops are simply the wrong tool, because the link an observer uses is not the link hops obscure.

  • When one observer sees both ends. If the party you received from and the party you eventually pay share information, the middle is irrelevant. This is the shape of the older EAE pattern, where an adversary owning outputs on both sides of your transaction can eliminate its own from your ring.
  • When the amounts match. Churn a distinctive amount, then send almost the same amount onward, and arithmetic does the linking that rings were meant to prevent. Fees make it inexact, which is not the same as unlinkable.
  • When the hops are minutes apart. A burst of self-sends in one sitting is a timing signature, whatever the rings look like.
  • When you consolidate afterwards. Spending several churned outputs together in one transaction declares that they share an owner, and undoes the hops that produced them.

Where it actively costs you

Each hop pays a fee and locks its output for ten blocks, so a three-hop churn is roughly an hour before the funds move again - long enough that a rate-bound swap started too early can run out its window while you wait. There is also a rarer failure that the September 2025 chain reorganization demonstrated: when a transaction is dropped and rebuilt, the rebuilt version keeps the same real spend and draws new decoys, and the single output the two rings share is the real one. More transactions means more exposure to that situation, not less. Set against all of this, the largest measured lever is not user behavior at all: retuning the decoy distribution moved the modeled attack from 23.5 percent to 7.6 percent, and full-chain membership proofs remove the ring question outright.

Common questions

What the forums answer confidently, and what the research answers carefully.

  • How many churns is enough? There is no evidenced number. Anyone offering one is extrapolating from ring arithmetic that measurement does not support.
  • Should I wait between hops? Waiting weakens timing correlation and costs only patience, which makes it one of the few common recommendations with a plausible mechanism behind it. The ten-block lock already imposes about twenty minutes.
  • Does churning hide me from the service that sent the coins? No. It knows the address it paid and when it paid it.
  • Will FCMP++ make churning pointless? It removes the ring-guessing problem churning was invented to dilute. Endpoint knowledge, amounts, and timing are not ring problems and survive the upgrade.
  • Is churning detectable? The one published attempt at an optimal test found it unreliable at ordinary thresholds. That is evidence in its favor, not proof of invisibility.