MZ MONZERO Explore the wallet

Engineering roadmap / BTC ↔ XMZ

The road to
public swaps.

A Bitcoin–Monzero exchange inside the Monzero GUI. Built in the open, verified in stages, with recovery designed into the trading journey.

Engineering snapshot ·
Milestone-based delivery. No committed live launch date.

PROTOCOL / DELIVERY MAPBTC + XMZ
  1. ✓
    Isolated settlement pathsTest-chain payments & recovery
    Verified
  2. 02
    Complete the trading journeyFull proceeds · restart safety · GUI
    Building
  3. 03
    Public test-network pilotPeers · market rules · tester feedback
    Planned
  4. 04
    Real-money releaseIndependent review & release gates
    Gated
Evidence first. Activation follows verification.

01 / Evidence, not promises

A foundation we can test.

These are development checks at this snapshot—not an audit, a security score or a percentage of project completion.

89 / passed

Engine library tests

Latest settlement acceptance run, alongside three compile-fail checks. Test counts are not a security audit.

33 / passed

C++ DEX tests

Native wallet coordination, recovery controls and GUI/backend boundaries.

5 / passed

QML presentation tests

Quote review, state visibility and the read-only recovery action.

2 / funded paths

Redeem + cancel/refund

Real transactions on isolated test chains, with restart reconciliation.

Also verified

Full GUI build Isolated startup Signed recovery destinations & fee limits Swap-lock input binding Repeatable acceptance runner

Important boundary: the new isolated exact-payment test delivers full principal and returns unused reserve. The broader negotiated two-party swap fixture still pays partial XMZ proceeds. Complete full-proceeds swaps and whole-application recovery remain unfinished. C++ and QML counts above are from the earlier roadmap snapshot, not a new run today.

Engineering update / 19 September 2026

Exact payments. Safer recovery.

Development progress on disposable test chains only. No real-money activation or new downloadable wallet release is announced by this update.

Verified in isolated tests

Exact quoted XMZ reaches its destination, with network fees accounted for separately and unused reserve returned. A deliberately lost broadcast reply is reconciled without a second payment.

Wallet safeguard implemented

Saved transaction inputs are checked against the open wallet before submission. Wrong-wallet relay is rejected. Focused tests passed with GCC and Clang, and the wallet RPC was rebuilt successfully.

Restart research, not a finished vault

Encrypted transaction metadata can be restored in a fresh worker. Wrong keys and altered records fail before broadcast. Production key storage, backup and recovery after the whole application closes remain outstanding.

Public verification summary — no personal paths or raw logs
  • 89 engine library tests and three compile-fail checks passed in the latest acceptance run.
  • Both funded scenarios passed, including lost replies, metadata tampering and wrong-wallet rejection.
  • Four focused wallet-validation tests passed with each of GCC and Clang.
  • AI-assisted source review informed the work; independent security review is still required.

Only an aggregate summary is published here. Raw development logs, local usernames, home-directory paths and private wallet data are not included.

Agreed payout policy

A quote for 100 XMZ means exactly 100 XMZ received. The XMZ buyer funds a separate network-fee reserve and receives its unused balance. This policy is documented; its new signed terms and complete two-party execution are not yet implemented. Initial application trading fees remain zero, separate from network fees.

Next: implement signed reserve terms and durable recovery storage; prove complete two-party settlement and refunds; connect GUI approval to execution; validate public peers, pricing rules and release gates. Cancellation-fee responsibility, recovery unlocking and reserve funding for buyers without XMZ still need resolution.

02 / The delivery path

Six milestones.
One complete journey.

Workstreams can overlap, but dependencies cannot be skipped. Each milestone has an observable exit condition.

Verified foundation In development / next Planned Release-gated
Next focus1–3 weeks · estimated effort

SETTLEMENT ENGINE

Every atom accounted for.

Integrate the tested exact-payment primitive into a complete negotiated exchange: agreed proceeds delivered, buyer-funded network fees accounted for, no unexplained funds left behind.

Deliverables & completion gate
  • Implement the agreed exact XMZ payout with a buyer-funded reserve and unused reserve returned to the buyer.
  • Account for funding fees, recovery fees, change and remaining balances.
  • Verify complete payout and refund paths with exact on-chain accounting.
Exit condition

Full proceeds or the defined refund reach the correct wallet; every fee and remaining output has an explicit treatment.

Still needed: signed reserve terms, cancellation-fee policy and full two-party integration

Planned integration2–4 weeks · estimated effort

DURABLE RECOVERY

Close the app. Keep the trade safe.

Retain enough verified state to recover when the entire application stops—not only when one test process restarts.

Deliverables & completion gate
  • Persist signed terms, peer identities, policy and protocol progress.
  • Connect single-use execution ownership to a restart-safe journal.
  • Test crashes, interrupted writes, missing replies and uncertain broadcasts.
  • Reconcile an existing payment instead of blindly sending it again.
Exit condition

A fresh application process resumes or safely reconciles interrupted swaps without duplicate funding or loss of recovery information.

Builds on: single-use claims and isolated recovery tests

Planned integration2–4 weeks · estimated effort

MONZERO GUI

One clear trading experience.

Connect the wallet interface to actual execution, with deliberate approval, understandable progress and a visible recovery path.

QuoteApproveFundSettle / refund
Deliverables & completion gate
  • Separate saving commercial terms from explicit permission to start a trade.
  • Display exact amounts, destinations, fees, confirmations and deadlines.
  • Connect journal loading to read-only payment checks and recovery controls.
  • Test the complete interface against the native settlement engine.
Exit condition

A tester can complete a full test-network swap in the GUI, including an interrupted-and-restarted scenario, without developer intervention.

Requires: full settlement + durable recovery

Planned3–6 weeks · estimated effort

PUBLIC TRADING INFRASTRUCTURE

Find a peer. Verify the offer.

Move beyond controlled local counterparts to authenticated peers and discoverable offers on a public test network.

Deliverables & completion gate
  • Implement public peer authentication and offer discovery.
  • Handle unavailable peers, expired offers and conflicting trade attempts.
  • Introduce operational monitoring and a controlled tester workflow.
  • Recruit willing counterparties; adapters do not create liquidity.
Exit condition

Separate testers can discover, agree and complete supported test-network trades, with failures and offline peers handled explicitly.

Requires: authenticated protocol + working execution workflow

Design + foundations2–6 weeks · estimated effort

PRICE POLICY & XMZ UTILITY

Transparent rules. Explicit fees.

Apply agreed price limits and a clearly defined XMZ application-fee model to trades through the Monzero protocol.

Deliverables & completion gate
  • Select the initial reference price, trusted pricing source and permitted deviation.
  • Reject stale references and out-of-band new trades; keep existing recovery paths available.
  • Define reference updates and manipulation protections for a thinly traded market.
  • Agree and implement the application-fee scope, recipient and failure/refund behaviour.
Exit condition

Actual trade admission enforces the approved price policy and fee rules; users can distinguish application fees from native network fees.

Decision needed: pricing policy + fee model. Current signed quotes support zero application fee.

Release gate closedNo committed launch date

REVIEW & STAGED RELEASE

Earn the right to go live.

A passing test suite is evidence, not a launch switch. Real-money activation follows review, platform validation and explicit release approval.

Deliverables & completion gate
  • Complete adversarial testing and obtain an independent security review.
  • Validate native platform behaviour, including Windows; some new primitives are Linux-only.
  • Reproduce and sign release artifacts, verify downloads and document limitations.
  • Move from a public test-network pilot to a separately approved, controlled real-money rollout.
Exit condition

Settlement, recovery, security and release requirements have supporting evidence. Warnings and public testing do not replace those requirements.

Requires: prior milestones + review findings addressed

03 / Planning horizon

Ranges, not countdowns.

Illustrative engineering effort, assuming experienced full-time development, prompt design decisions and no major protocol redesign. These are not scheduled completion dates.

Full settlement1–3 weeks
Restart recovery2–4 weeks
GUI execution2–4 weeks
Public infrastructure3–6 weeks
Commercial rules2–6 weeks

Solid + hatched bars show the estimated effort range. Work can overlap; the ranges should not simply be added together. Independent review and release scheduling are separate.

First integration target4–8 weeks

Complete GUI-driven test swaps

A planning estimate for the end-to-end test-network journey, including restart recovery.

Broader planning window8–16 weeks

Public test-network pilot

Subject to capacity, peer infrastructure, market-rule decisions and test findings. Not a mainnet launch promise.

04 / Clear expectations

What this roadmap means.

BTC / XMZ first

The immediate milestone is a complete Bitcoin–Monzero trading path. Additional assets are future scope, not supported live markets implied by this page.

Price bands are not value guarantees

Limits apply to new trades through our protocol. They do not set prices on other exchanges, guarantee a buyer or establish a guaranteed XMZ value.

Community testing complements review

Public test-network participation can uncover failures. It does not replace independent review, and no paid bug-bounty programme is announced by this roadmap.

Open development. Honest milestones.

Follow the evidence.
Help shape what comes next.

Explore the project, review the security guidance and follow future tester instructions. No deposit is required to read or follow this roadmap.