Confirm you are on the correct site before anything else. Phishing copies of mixing services exist specifically to collect deposits, and they look identical to the original. Reach the service through the address you verified yourself, and prefer the onion address when you can.

Check the deposit address character by character on the page where it is displayed, and compare it with the QR code target before you scan. Clipboard-hijacking malware silently replaces a copied address, so a visual comparison in the wallet before signing is the last practical safeguard.

Protect the session identifier. It is the only reference to your session, it is generated randomly for each new session, and anyone who obtains it learns that a session exists. Store it somewhere private rather than in a shared note, a chat message or a screenshot in a synced photo library.

Use Tor for the session itself. It prevents the connection between your network address and the session, which is exactly the metadata that on-chain mixing cannot protect. Avoid checking your deposit or payout address on a public block explorer from your normal browser.

Choose a delay and, when the option is available, several payout addresses with uneven amounts. Instant payouts of a round number are the easiest pattern to correlate. Afterwards, keep the mixed coins in a wallet of their own and never spend them together with coins tied to your identity, which would undo the separation in a single transaction.

Back to the blog