# Trustless Monero-Starknet Atomic Swaps Using DLEQ Proofs

**URL:** <https://community.starknet.io/t/trustless-monero-starknet-atomic-swaps-using-dleq-proofs/116084>\
**Category:** 📜 Development Proposals\
**Created:** [December 9, 2025, 1:38am UTC](https://community.starknet.io/t/trustless-monero-starknet-atomic-swaps-using-dleq-proofs/116084 "2025-12-09T01:38:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![espejelomar](https://dub1.discourse-cdn.com/flex005/user_avatar/community.starknet.io/espejelomar/32/85912_2.png) [@espejelomar](https://community.starknet.io/u/espejelomar)\
**Post date:** [December 9, 2025, 1:38am UTC](https://community.starknet.io/t/trustless-monero-starknet-atomic-swaps-using-dleq-proofs/116084/1 "2025-12-09T01:38:38Z")

</div>

We’ve built a prototype atomic swap bridge that enables trustless XMR ↔ STRK/ETH exchanges on Starknet L2. This brings privacy-preserving currency to Starknet’s DeFi ecosystem without custodians, bridges, or KYC.

**What This Enables for Starknet**

- Trustless swaps between XMR and Starknet assets using cryptographic binding via DLEQ proofs
- Ultra-low gas costs: ~$0.01-0.05 per swap verification (~270k-440k gas)
- Privacy-respecting gateway to DeFi for Monero users
- No bridges or custodians - pure cryptographic security

**Cairo Implementation Highlights**

The implementation leverages Starknet’s Cairo VM capabilities:

1. **DLEQ Proof Verification** : On-chain verification using Garaga v1.0.1 MSM library for elliptic curve operations
2. **BLAKE2s Challenge Computation** : Gas-optimized at ~500k gas for full verification
3. **Production-Grade Libraries** : OpenZeppelin Cairo Contracts v2.0.0 for security primitives
4. **Ed25519 Point Operations** : Efficient scalar multiplication and point compression/decompression

**Protocol Flow**

1. Alice generates secret scalar `t` and creates adaptor signature
2. Alice deploys `AtomicLock` contract on Starknet with:
  - Hashlock `H = SHA-256(t)`
  - Adaptor point `T = t·G` (Ed25519)
  - DLEQ proof proving `∃t: SHA-256(t) = H ∧ t·G = T`

3. Bob verifies DLEQ proof on-chain, unlocks contract by revealing `t`
4. Alice detects secret reveal via `Unlocked` event, completes Monero transaction

**Current Development Status**

Completed:

- BLAKE2s challenge compatibility between Rust and Cairo
- DLEQ proof generation (Rust) and verification (Cairo)
- Test suite with 139 production-grade test vectors
- CI/CD workflow with automated testing
- Informal security audit of critical paths

in Progress:

- Web interface for testnet experimentation
- Sepolia testnet deployment
- Race condition mitigations (two-phase unlock, watchtower service)

**Technical Resources**

GitHub: [GitHub - omarespejel/monero-starknet-atomic-swap: Cross-chain atomic swap: Monero adaptor signatures + Starknet Cairo contracts with ED25519 MSM verification and DLEQ proofs](https://github.com/omarespejel/monero-starknet-atomic-swap)

**Known Limitations**

This is alpha software under active development:

- Protocol-level race condition exists
- Monero integration uses simplified adaptor signatures, not full CLSAG
- External security audit pending
- Recommended for small amounts only (under $100 equivalent) until v0.8.0 mitigations

I’m available to discuss Cairo implementation details, Starknet/Cairo technical specifics, and collaboration opportunities

Updates will be posted here as development progresses. Community feedback is essential for building robust infrastructure

* * *

**Disclaimer** : This is experimental software under active development. Do not use with real funds without security audit

---

<div class="post-metadata">

**Author:** ![gaetbout](https://dub1.discourse-cdn.com/flex005/user_avatar/community.starknet.io/gaetbout/32/712_2.png) [@gaetbout](https://community.starknet.io/u/gaetbout)\
**Post date:** [December 9, 2025, 8:44am UTC](https://community.starknet.io/t/trustless-monero-starknet-atomic-swaps-using-dleq-proofs/116084/2 "2025-12-09T08:44:07Z")

</div>

Hey,

idk if normal but the repo isn’t public (or wrong link).  
Would like to have a look 🙂

G

---

<div class="post-metadata">

**Author:** ![espejelomar](https://dub1.discourse-cdn.com/flex005/user_avatar/community.starknet.io/espejelomar/32/85912_2.png) [@espejelomar](https://community.starknet.io/u/espejelomar)\
**Post date:** [December 10, 2025, 2:32am UTC](https://community.starknet.io/t/trustless-monero-starknet-atomic-swaps-using-dleq-proofs/116084/3 "2025-12-10T02:32:21Z")

</div>

Hey @gaetbout! The repo is open now, just had some visibility issues initially. You can check it out here: [GitHub - omarespejel/monero-starknet-atomic-swap: Cross-chain atomic swap: Monero adaptor signatures + Starknet Cairo contracts with ED25519 MSM verification and DLEQ proofs](https://github.com/omarespejel/monero-starknet-atomic-swap)

Feel free to take a look and let me know if you have any questions or feedback!

---

<div class="post-metadata">

**Author:** ![Teku](https://dub1.discourse-cdn.com/flex005/user_avatar/community.starknet.io/teku/32/85460_2.png) [@Teku](https://community.starknet.io/u/Teku)\
**Post date:** [December 22, 2025, 2:33am UTC](https://community.starknet.io/t/trustless-monero-starknet-atomic-swaps-using-dleq-proofs/116084/4 "2025-12-22T02:33:49Z")

</div>

Looks great. I think XMR to STRK could bring some great privacy options to Starknet. Currently obtaining and selling XMR can be troublesome, especially with a lot of CEX’s no longer trading it.

Is there a road map to when this could possibly be a reality?
