A fork of monero-project/monero that adds native support for ANyONe Protocol
.anyonehidden services, allowing monerod to route P2P traffic and accept inbound connections through the ANyONe onion-routing network.
ANyONe Protocol is a decentralized onion-routing network. Like Tor, it routes traffic through a layered-encryption network and exposes a standard SOCKS5 proxy. Hidden services use .anyone addresses, built on the same ED25519 cryptography as Tor v3 .onion addresses with a different TLD. ANyONe operates 7300+ relays including ~4,400 exit nodes, so it can carry both hidden-service traffic and clearnet exit traffic.
This fork introduces zone::anon as a first-class anonymity network alongside Tor and I2P, and teaches the wallet to recognize .anyone as a privacy-preserving network.
| File | Change |
|---|---|
src/net/anon_address.h |
New — net::anon_address class, mirrors tor_address |
src/net/anon_address.cpp |
New — parsing, validation, SOCKS5 connect, serialization |
contrib/epee/include/net/enums.h |
Added address_type::anon = 5 and zone::anon = 4 |
contrib/epee/include/net/net_utils_base.h |
Added anon_address forward declaration and serialization dispatch |
contrib/epee/src/net_utils_base.cpp |
Added zone_to_string / zone_from_string handling for anon |
src/net/CMakeLists.txt |
Added anon_address.cpp to the net library |
src/net/parse.cpp |
Added .anyone suffix detection in address parsing |
src/p2p/net_node.cpp |
Added anon zone parsing, inbound/outbound handling, SOCKS5 dispatch |
src/p2p/net_node.inl |
Updated send_txs loop guards and static asserts for zone::anon |
src/p2p/p2p_protocol_defs.h |
Added #include "net/anon_address.h" |
The official wallet only recognizes .onion and .i2p as self-authenticating, end-to-end-encrypted domains. Connecting to a .anyone daemon over --proxy would otherwise fail with an SSL-certificate error. These three changes make .anyone behave like .onion/.i2p:
| File | Change |
|---|---|
contrib/epee/src/net_ssl.cpp |
has_strong_verification() now returns true for .anyone hosts (they are already E2E encrypted, so no SSL cert is required) |
src/common/util.cpp |
is_privacy_preserving_network() now returns true for .anyone, so the wallet routes it as an anonymity network |
src/wallet/wallet2.cpp |
Updated the proxy/SSL error message to read .onion/.i2p/.anyone |
Monero does not synchronize the blockchain over .anyone hidden services — anonymity zones only carry handshakes, peer timed syncs, and transaction broadcasts (see the upstream ANONYMITY_NETWORKS.md). This fork inherits that design. The privacy-preserving setup therefore uses two complementary mechanisms:
proxy=— routes clearnet IPv4 blockchain sync through ANyONe exit nodes.tx-proxy=anon+anonymous-inbound=— broadcasts your transactions and connects to.anyonepeers over ANyONe hidden services.
Download and install the anon daemon from anyone-protocol/ator-protocol/releases.
Create your anonrc file by running :
sudo tee /etc/anon/anonrc > /dev/null << 'EOF'
#Anon client-only
ORPort 0
DirPort 0
SocksPort 127.0.0.1:9050
SocksPolicy accept 127.0.0.1
SocksPolicy reject *
# Log
Log notice file /var/log/anon/notices.log
DataDirectory /var/lib/anon
# Hidden service for monerod P2P
HiddenServiceDir /var/lib/anon/monerod/
HiddenServicePort 18084 127.0.0.1:18084
HiddenServicePort 18089 127.0.0.1:18089
EOF
Restart anon:
sudo systemctl restart anonRead your .anyone address:
sudo cat /var/lib/anon/monerod/hostnameCreate monero user and group:
sudo useradd --system moneroCreate monero config, data and log directories:
mkdir -p /etc/monero /var/lib/monero /var/log/monero
sudo chown monero:monero /etc/monero /var/lib/monero /var/log/moneroDownload and install:
wget https://github.com/xmranonp/monero/releases/download/v0.18.5-anon-1/monerod-anon-0.18.5.0-ubuntu24-amd64.deb
sudo apt install ./monerod-anon-0.18.5.0-ubuntu24-amd64.debEdit /etc/monero/monerod.conf:
# /etc/monero/monerod.conf
# Monero daemon fork
# Blockchain syncs over ANyONe network; transactions broadcast over ANyONe hidden services.
# https://docs.getmonero.org/interacting/monerod-reference/
# ── DATA ─────────────────────────────────────────────────────────────────────
data-dir=/var/lib/monero/bitmonero
# ── OPTIONAL PRUNING ──────────────────────────────────────────────────────────────────
# Saves ~2/3 disk space with no loss of functionality - Uncomment both if you plan to run a pruned node.
#prune-blockchain=1
#sync-pruned-blocks=1
# ── SECURITY ─────────────────────────────────────────────────────────────────
check-updates=disabled
enable-dns-blocklist=1
# ── LOGGING ──────────────────────────────────────────────────────────────────
log-file=/var/log/monero/monero.log
log-level=0
max-log-file-size=2147483648
# ── BLOCKCHAIN SYNC OVER ANyONe ──────────────────────────────────────────────
# Routes all clearnet IPv4 sync traffic through the ANyONe SOCKS5 proxy.
proxy=127.0.0.1:9050
# ── TRANSACTION BROADCAST OVER ANyONe ────────────────────────────────────────
# Sends your own transactions and connects to .anyone peers via the ANyONe network.
tx-proxy=anon,127.0.0.1:9050,16,disable_noise
# Advertise this node's .anyone hidden service so peers can reach it inbound.
# Get your address with: sudo cat /var/lib/anon/monerod/hostname
anonymous-inbound=PASTE_YOUR_ADDRESS.anyone:18084,127.0.0.1:18084,16
# Keep a persistent connection to a known .anyone peer. (uncomment)
#add-priority-node=PASTE_PEER_ADDRESS.anyone:18084
# ── P2P BINDING ──────────────────────────────────────────────────────────────
# Bind to localhost only — no direct clearnet exposure
p2p-bind-ip=127.0.0.1
p2p-bind-port=18080
no-igd=1
hide-my-port=1
# ── RPC ──────────────────────────────────────────────────────────────────────
# Restricted RPC — reachable through the hidden service
rpc-restricted-bind-ip=127.0.0.1
rpc-restricted-bind-port=18089
# Unrestricted RPC — local only, for your own wallet
rpc-bind-ip=127.0.0.1
rpc-bind-port=18081
# ── MISC ─────────────────────────────────────────────────────────────────────
no-zmq=1
# Faster sync; Change to db-sync-mode=safe:sync when fully synced.
db-sync-mode=fast:async:250000000
sudo systemctl daemon-reload
sudo systemctl enable --now monerod
sudo systemctl status monerodCheck for leaks :
Confirm there are no clearnet leaks — every monerod connection should go to 127.0.0.1:9050:
sudo ss -tnp | grep 9050Test RPC reachability through ANyONe:
curl --socks5-hostname 127.0.0.1:9050 \
http://abc123...xyz7654.anyone:18089/get_info --max-time 30monero-wallet-cli \
--proxy 127.0.0.1:9050 \
--daemon-address abc123...xyz7654.anyone:18089 \
--trusted-daemonThe daemon at that address must expose its RPC port (18089) as a hidden service (HiddenServicePort 18089 in anonrc). Use --trusted-daemon only for nodes you control.
Using the official (unpatched) wallet? It will reject
.anyoneunless you add--daemon-ssl-allow-any-cert. The ANyONe tunnel is already end-to-end encrypted, so that flag is safe — but building the wallet from this fork removes the need for it.
- Blockchain sync does not run over
.anyonehidden services (same as Tor/I2P — see Monero's ANONYMITY_NETWORKS.md). - - Sync happens over ANyONe network exit nodes via
proxy=, while.anyonehandles private transaction broadcast and inbound P2P. - If no ANyONe peers are reachable, transactions queue until a peer becomes available — no clearnet fallback occurs
- Built on Ubuntu 24.04, amd64. Based on Monero v0.18.5.0 'Fluorine Fermi'.
Same as Monero — BSD 3-Clause. See LICENSE.