Damus
nostrich profile picture
nostrich
Has anyone here actually used RetoSwap recently?

I'm looking into it as a potential P2P option for Monero, but a few things give me pause:

The protocol suffered a major exploit in 2026.
The Windows installer is not Authenticode-signed.
VirusTotal currently shows 6/61 detections, including some generic RiskTool/CryptoMiner flags and a few more concerning heuristic labels.
The project relies on GPG verification rather than traditional code signing.

To be clear, none of these points prove malicious intent. Open-source privacy tools often trigger false positives, and lack of Authenticode signatures is common in the crypto ecosystem.

Still, before installing it, I'd like to hear from people who have actually used it:

Have you verified the release signatures?
Have you completed trades successfully?
Any security concerns or red flags?
Would you trust it with meaningful amounts?

Interested in first-hand experience rather than assumptions.

#Monero #XMR #RetoSwap #Privacy #P2P
2
nostrich · 5d
Used it many times in the past. If you are not acting as a maker you reduce your risk. You can use it on Tails. Windows (spyware) defeats the purpose imo.
Ape Mithrandir · 4d
I have used it but not since the exploit. I couldn't see any information on their releases about how they fixed the exploit. Bisq works and if you are looking for BTC to XMR Eigenwallet is very good too.