MZ MONZERO Explore the wallet

Engineering roadmap / Multi-asset DEX

The road to
public swaps.

An exchange inside the Monzero GUI, building on BTC/XMZ with Litecoin settlement work and previews for XMR, DOGE, ETH and native RUNE. Each market needs its own verified settlement and recovery path.

Engineering snapshot ·
Milestone-based delivery. No committed live launch date.

PROTOCOL / DELIVERY MAPBTC + XMZ
  1. ✓
    Isolated settlement pathsTest-chain payments & recovery
    Verified
  2. 02
    Complete the trading journeyFull proceeds · restart safety · GUI
    Building
  3. 03
    Public test-network pilotPeers · market rules · tester feedback
    Planned
  4. 04
    Real-money releaseIndependent review & release gates
    Gated
Evidence first. Activation follows verification.

01 / Evidence, not promises

A foundation we can test.

These are development checks at this snapshot—not an audit, a security score or a percentage of project completion.

4 / LTC paths

Isolated settlement tests

Redeem, refund, early refund and punishment passed with exact amounts, node restarts and reorganisations.

2 / Linux hosts

Native funding primitives

Actual isolated XMZ wallets prepared, restored and relayed the exact saved payment. Confirmed proofs and recipient amounts were verified.

11 / focused checks

Native relay regression tests

Request validation, uncertain replies and saved-payment checks passed. This is a focused suite, not a count of all project tests.

5 / added coins

Market previews

XMR, DOGE, ETH, LTC and native RUNE are selectable with coin-specific amount precision. Their trading remains disabled.

Also verified

Engine compile checks on both hosts Ordered source patches Authenticated Litecoin key exchange Saved recovery transactions Confirmation and cancellation-window checks

Verification boundary: the first complete Litecoin–XMZ success path has passed across isolated Litecoin regtest and XMZ fakechain nodes, using the production execution controllers. It verifies funding, Litecoin redemption, native key recovery, exact XMZ payout, unused reserve return and funding-fee accounting. A complete cancellation/refund path now also passes: Litecoin is refunded and the recovered XMZ lock is paid to the signed refund address within its fee limit. Broader interruption and reorganisation coverage, and GUI execution, remain unfinished. No live market is enabled.

Engineering update / 26 September 2026

More markets.
Settlement comes next.

The interface now represents the requested coins. Litecoin has the most new settlement work; each remaining chain still needs implementation and verification.

In development

Litecoin / XMZ

Authenticated negotiation, durable recovery, wallet signing and Litecoin relay are implemented. Four Litecoin paths pass on isolated nodes. Saved XMZ funding payments survive restart and relay in isolated tests. Durable redemption and native-claim recovery have controller test evidence; signed payout preparation, exact payout relay and recovery after wallet-cache loss also pass isolated wallet tests. Complete paired-chain success and cancellation/refund paths now pass with exact recipient balances and fee accounting. The refund test recovers the native wallet and sends its balance, less the bounded network fee, to the signed refund address. Broader recovery coverage and GUI execution remain unfinished.

Primitive verified

Dogecoin

Eight-decimal previews and an isolated Dogecoin timelock/refund primitive pass on both Linux hosts. Tests reject early refunds and incorrect locktimes, then confirm the exact mature refund. A Dogecoin-compatible cross-chain protocol, production signing and complete DOGE/XMZ settlement/recovery are still required.

Settlement pending

Ethereum

Previews preserve 18-decimal precision and large wei amounts. Contract settlement, gas and nonce management, recovery and contract tests are still required.

Route implementation pending

Monero

Twelve-decimal previews are available. Explicit sequential routes are approved in the project scope, with separate fees and recovery for each leg. No XMR route is executable yet.

Route implementation pending

Native RUNE

Eight-decimal previews target native THORChain RUNE. Explicit routing is approved; route execution, chain integration and recovery remain unfinished.

Existing foundation

Bitcoin / XMZ

Existing settlement and recovery work remains the foundation. New market previews cannot reuse its signing authority. Complete GUI execution and release acceptance are still required.

What the new recovery tests cover
  • Retain authenticated keys and recovery transactions before funding operations.
  • Reject a spent or insufficiently confirmed Litecoin lock, including pending spends and unsafe cancellation windows.
  • Accept native confirmation after commercial quote expiry only against the original recovery agreement; new funding still requires valid terms.
  • Restore the exact saved XMZ preparation; reject changed sources, missing committed records and altered checkpoints.
  • Retry a failed non-broadcasting preparation under the same terms only when no prepared transaction was retained, with fresh quote and live-lock checks.
  • Retain the completed Litecoin redemption and recover the native claim keys in controller tests.
  • Verify confirmed Litecoin transaction bytes against an actual node, including restart, reorganisation rejection and reconsideration.
  • Restore and reopen the native claim wallet; prepare exact signed payout and reserve amounts without broadcasting.
  • Recover the exact payout checkpoint in a fresh process with both services stopped; reject altered terms and corrupted bytes.
  • Relay the saved native payout and verify exact recipient and reserve-return balances, including subaddresses.
  • Rebuild the disposable claim-wallet cache and verify both payments using retained private transaction proofs.
  • Verify shared payout and reserve addresses, a reserve equal to the signed fee ceiling, and zero reserve returns to separate subaddress recipients.
  • Complete a production-controller Litecoin–XMZ success path across both isolated chains, checking exact recipient balances, source-balance changes and funding fees.
  • Reject premature Litecoin cancellation, then confirm cancellation/refund and pay the recovered XMZ lock to the signed refund address; verify the recipient balance and an empty recovered wallet.
  • Reject a watch-only wallet substituted for the recovered spend wallet on both Linux hosts.
Read-only integration

Saved-trade visibility

A native Litecoin journal reader and GUI status panel are implemented. GUI builds, C++ checks and seven QML tests passed on both Linux hosts; the actual native helper read a completed refund journal. The actual Qt-to-helper handoff still needs a passing integration run. Saved state is not current chain confirmation, and no GUI send/retry controls are enabled.

Validation unfinished

Explicit refund review

A native review API binds the destination, amount, fee, saved payment and send-versus-retry action. Focused commitment tests and compilation passed on both hosts. Expanded controller cases and complete approval-bound refund reruns remain unfinished; the latter were stopped before completion.

Recovery evidence

Retain, check, then retry

Focused controller tests cover offline reloads, missing or corrupted records, uncertain replies, exact retransmission and revoked confirmations. Exact payout proofs survive wallet-cache loss. These checks strengthen recovery without establishing complete failure coverage.

Next integration gate

Expand paired-chain interruption and reorganisation recovery coverage, and review the settlement changes. Recovered-wallet spend-capability checks pass on both Linux hosts. Complete the actual GUI journal handoff and approval-bound refund tests, then connect verified execution and recovery to explicit GUI approval before enabling a market.

Work stopped at this 26 September documentation checkpoint; interrupted checks are not passes. No new downloadable release, completed independent security audit or real-money market is announced here. Genesis pre15 remains separate from these development changes; see the updated whitepaper. Earlier BTC/XMZ evidence is retained below as a dated historical checkpoint.

Historical checkpoint / 19 September 2026

Exact payments. Safer recovery.

Earlier BTC/XMZ evidence, retained for context. Status statements in this section describe the 19 September checkpoint; the newer update above describes current multi-asset work.

Verified in isolated tests

Exact quoted XMZ reaches its destination, with network fees accounted for separately and unused reserve returned. A deliberately lost broadcast reply is reconciled without a second payment.

Wallet safeguard implemented

Saved transaction inputs are checked against the open wallet before submission. Wrong-wallet relay is rejected. Focused tests passed with GCC and Clang, and the wallet RPC was rebuilt successfully.

Restart research, not a finished vault

Encrypted transaction metadata can be restored in a fresh worker. Wrong keys and altered records fail before broadcast. Production key storage, backup and recovery after the whole application closes remain outstanding.

Public verification summary — no personal paths or raw logs
  • 89 engine library tests and three compile-fail checks passed in the latest acceptance run.
  • Both funded scenarios passed, including lost replies, metadata tampering and wrong-wallet rejection.
  • Four focused wallet-validation tests passed with each of GCC and Clang.
  • AI-assisted source review informed the work; independent security review is still required.

Only an aggregate summary is published here. Raw development logs, local usernames, home-directory paths and private wallet data are not included.

Agreed payout policy

A quote for 100 XMZ means exactly 100 XMZ received. The XMZ buyer funds a separate network-fee reserve and receives its unused balance. The new signed terms, isolated-wallet payout tests and first paired-chain success test are implemented; complete recovery and GUI execution remain unfinished. Initial application trading fees remain zero, separate from network fees.

At that checkpoint, next steps were: implement signed reserve terms and durable recovery storage; prove complete two-party settlement and refunds; connect GUI approval to execution; validate public peers, pricing rules and release gates. Cancellation-fee responsibility, recovery unlocking and reserve funding for buyers without XMZ still need resolution.

02 / The delivery path

Six milestones.
One complete journey.

Workstreams can overlap, but dependencies cannot be skipped. Each milestone has an observable exit condition.

Verified foundation In development / next Planned Release-gated
Next focus1–3 weeks · estimated effort

SETTLEMENT ENGINE

Every atom accounted for.

Complete isolated Litecoin–XMZ success and refund paths now pass with exact balances and fees. Extend that evidence across failure scenarios and implement the remaining markets independently.

Deliverables & completion gate
  • Implement the agreed exact XMZ payout with a buyer-funded reserve and unused reserve returned to the buyer.
  • Account for funding fees, recovery fees, change and remaining balances.
  • Verify complete payout and refund paths with exact on-chain accounting.
Exit condition

Full proceeds or the defined refund reach the correct wallet; every fee and remaining output has an explicit treatment.

Still needed: broader paired-chain failure coverage and each market’s settlement and recovery gate

Planned integration2–4 weeks · estimated effort

DURABLE RECOVERY

Close the app. Keep the trade safe.

Litecoin execution journals and native preparation checkpoints now pass focused restart tests. Connect these to whole-application recovery and test every funding and settlement boundary.

Deliverables & completion gate
  • Persist signed terms, peer identities, policy and protocol progress.
  • Connect single-use execution ownership to a restart-safe journal.
  • Test crashes, interrupted writes, missing replies and uncertain broadcasts.
  • Reconcile an existing payment instead of blindly sending it again.
Exit condition

A fresh application process resumes or safely reconciles interrupted swaps without duplicate funding or loss of recovery information.

Builds on: authenticated Litecoin state, prepared XMZ transactions and isolated recovery tests

Planned integration2–4 weeks · estimated effort

MONZERO GUI

One clear trading experience.

Coin selectors, exact-precision previews and a read-only Litecoin saved-trade panel are implemented. Finish the actual helper handoff and connect verified per-market execution, deliberate approval and recovery controls.

QuoteApproveFundSettle / refund
Deliverables & completion gate
  • Separate saving commercial terms from explicit permission to start a trade.
  • Display exact amounts, destinations, fees, confirmations and deadlines.
  • Connect journal loading to read-only payment checks and recovery controls.
  • Test the complete interface against the native settlement engine.
Exit condition

A tester can complete a full test-network swap in the GUI, including an interrupted-and-restarted scenario, without developer intervention.

Requires: full settlement + durable recovery

Planned3–6 weeks · estimated effort

PUBLIC TRADING INFRASTRUCTURE

Find a peer. Verify the offer.

Move beyond controlled local counterparts to authenticated peers and discoverable offers on a public test network.

Deliverables & completion gate
  • Implement public peer authentication and offer discovery.
  • Handle unavailable peers, expired offers and conflicting trade attempts.
  • Introduce operational monitoring and a controlled tester workflow.
  • Recruit willing counterparties; adapters do not create liquidity.
Exit condition

Separate testers can discover, agree and complete supported test-network trades, with failures and offline peers handled explicitly.

Requires: authenticated protocol + working execution workflow

Design + foundations2–6 weeks · estimated effort

PRICE POLICY & XMZ UTILITY

Transparent rules. Explicit fees.

Apply agreed price limits and a clearly defined XMZ application-fee model to trades through the Monzero protocol.

Deliverables & completion gate
  • Select the initial reference price, trusted pricing source and permitted deviation.
  • Reject stale references and out-of-band new trades; keep existing recovery paths available.
  • Define reference updates and manipulation protections for a thinly traded market.
  • Agree and implement the application-fee scope, recipient and failure/refund behaviour.
Exit condition

Actual trade admission enforces the approved price policy and fee rules; users can distinguish application fees from native network fees.

Decision needed: pricing policy + fee model. Current signed quotes support zero application fee.

Release gate closedNo committed launch date

REVIEW & STAGED RELEASE

Earn the right to go live.

A passing test suite is evidence, not a launch switch. Real-money activation follows review, platform validation and explicit release approval.

Deliverables & completion gate
  • Complete adversarial testing and obtain an independent security review.
  • Validate native platform behaviour, including Windows; some new primitives are Linux-only.
  • Reproduce and sign release artifacts, verify downloads and document limitations.
  • Move from a public test-network pilot to a separately approved, controlled real-money rollout.
Exit condition

Settlement, recovery, security and release requirements have supporting evidence. Warnings and public testing do not replace those requirements.

Requires: prior milestones + review findings addressed

03 / Planning horizon

Ranges, not countdowns.

Earlier BTC/XMZ planning ranges, retained for context. They have not been re-estimated for the additional assets and are not delivery dates for the multi-asset scope.

Full settlement1–3 weeks
Restart recovery2–4 weeks
GUI execution2–4 weeks
Public infrastructure3–6 weeks
Commercial rules2–6 weeks

Solid + hatched bars show the estimated effort range. Work can overlap; the ranges should not simply be added together. Independent review and release scheduling are separate.

First integration target4–8 weeks

Complete GUI-driven test swaps

A planning estimate for the end-to-end test-network journey, including restart recovery.

Broader planning window8–16 weeks

Public test-network pilot

Subject to capacity, peer infrastructure, market-rule decisions and test findings. Not a mainnet launch promise.

04 / Clear expectations

What this roadmap means.

Readiness is per market

BTC/XMZ remains the foundation while Litecoin integration progresses. XMR, DOGE, ETH and native RUNE are part of the requested scope; each stays disabled until its settlement and recovery are implemented and verified.

Price bands are not value guarantees

Limits apply to new trades through our protocol. They do not set prices on other exchanges, guarantee a buyer or establish a guaranteed XMZ value.

Community testing complements review

Public test-network participation can uncover failures. It does not replace independent review, and no paid bug-bounty programme is announced by this roadmap.

Open development. Honest milestones.

Follow the evidence.
Help shape what comes next.

Explore the project, review the security guidance and follow future tester instructions. No deposit is required to read or follow this roadmap.