Two independent layers
| Layer | Protects | Mechanism |
|---|---|---|
| On-chain privacy | Amounts, senders and receivers of every transfer | Orchard / Halo 2 shielded notes — in every network mode |
| Network privacy | This computer's IP address, as seen by peers | Tor routing in Hybrid or Tor-only mode |
Neither layer makes anyone completely anonymous, and the wallet never shows a "100% anonymous" indicator.
Network modes
Choose the mode on the wallet's Network → Network privacy page, with --network-mode, or [network_privacy] mode in the node TOML. New wallet installations start in Tor only. Existing installations keep their mode and are never switched silently; a standalone genorynd without a mode stays Direct.
| Direct | Hybrid | Tor only | |
|---|---|---|---|
| Clearnet peers | Direct TCP | Direct TCP | Through Tor exits |
| Onion peers | Refused | Through Tor | Through Tor |
| Inbound peers | Clearnet listener | Clearnet + optional onion service | Onion service only |
| Peer DNS lookups | System resolver | System resolver (never for .onion) | None — names resolved inside Tor |
| Your payments | One relay peer first | Prefers Tor-routed peers | Tor-routed peers only |
| If Tor fails | — | Onion peers pause | All networking pauses — never falls back to direct |
| Peers see your IP | Yes | Yes (clearnet peers) | No |
Tor is built in
Hybrid and Tor-only modes use a Tor client inside GENORYN (Arti). There is nothing to download or keep open. The first start fetches about 10 MB of Tor directory data, so the first connection takes a little longer. A Tor daemon or Tor Browser you already run still works ("My own Tor", --tor-socks).
# Everything through Tor, no inbound peers
$ genorynd --network-mode tor-only
# Also accept inbound peers through a persistent v3 onion service
$ genorynd --network-mode tor-only --onion-service
# Clearnet plus onion peers
$ genorynd --network-mode hybrid
# Use an existing Tor daemon instead of the built-in client
$ genorynd --network-mode tor-only --tor-socks 127.0.0.1:9050 --tor-control 127.0.0.1:9051 --onion-serviceOnion services
With --onion-service the node publishes a v3 onion address, so other nodes can connect to yours without either side learning the other's IP. The key lives under <data-dir>/tor/state, so the address survives restarts. Onion addresses spread only between upgraded Hybrid and Tor-only nodes, are announced only over Tor links, and are validated (version, SHA3-256 checksum, ed25519 key) before they enter the peer cache.
Tor-only nodes find their first peers through the onion seed list seeds/mainnet-onion.txt, read automatically at startup — no new release needed when a seed is added. The genoryn.io node runs an always-on onion seed for exactly this purpose (see Nodes).
Payment broadcast
- A payment created on your computer is first sent to one relay peer (preferring outbound Tor links) — a one-hop "stem" in the spirit of Dandelion++ — and only then broadcast more widely after a random 20–45 s embargo.
- Relays to each peer use independent random delays, so opening many connections gives an observer no earlier copy.
- A peer that silently drops your payment can no longer stop it from spreading.
- A payment created while Tor or the network is down is kept on disk and goes out when a peer is reachable again — in Tor-only mode never any other way.
This makes it harder to tell which computer created a payment. It is not anonymity: the chosen relay peer learns that your node sent it first, and timing analysis remains possible.
Light wallet over Tor
Network → Light wallet runs the wallet without a node of its own. It reaches the public RPC of nodes you list only through Tor, each on its own circuit, downloads the chain from the source with the highest tip and fully validates it locally — RandomX work, Halo 2 proofs, state roots — before scanning. Payments go out through POST /v1/relay of a different source than the one it synced from.
Remote nodes never see your addresses, viewing keys or balance; they can see when a wallet syncs and can withhold new blocks, so use two or more independent sources. Usernames and mining still need a node of your own.
Leak protections
- One dialing path, no fallback. Every outbound connection goes through one policy check; in Tor-only mode a direct route cannot be produced, and SOCKS failures never lead to a direct attempt.
- No local DNS for onion names, ever. In Tor-only mode host names are resolved inside Tor (SOCKS5 remote resolution).
- Unlinkable identities. The handshake identity is random per run; Tor links use a second identity and advertise no listening address.
- Stream isolation. Each Tor peer connection gets its own circuit.
- Separate peer caches per mode, so direct peers never shape Tor connections.
- Log redaction of addresses in Tor modes. Public RPC never reveals the mode, Tor status or onion address.
- The seed list and the wallet's update check go through Tor in Tor-only mode, or not at all.
What Tor cannot do
For node operators
# An onion seed / light-wallet source, always on
$ genorynd --network-mode hybrid --onion-service --public-rpc
# Show the onion address to publish in seeds/mainnet-onion.txt
$ genoryn-cli get-network-privacy --token-file ~/.genoryn/mainnet/admin.tokenPeer protocol, consensus, monetary rules and wallet files did not change: 0.6.0 works with 0.4.x and 0.5.x nodes. Full reference: network privacy and Tor.