How does dandelion++ hide your IP when broadcasting a cryptocurrency transaction?
Dandelion++ is a privacy protocol used by certain cryptocurrencies - most notably Monero - to obscure the IP address of the device that originates a transaction. It works by first sending the transaction through a random "stem" path of nodes before "fluffing" it out to the wider network, so that the transaction cannot be traced back to its source by observers watching network traffic.
The problem dandelion++ solves
When you broadcast a transaction in a typical peer-to-peer cryptocurrency network, your wallet sends it directly to several connected peers. Any entity monitoring the network - such as an internet service provider, a government agency, or a blockchain analytics firm - can see which IP address first announced that transaction. Even if the transaction itself uses privacy techniques like ring signatures or stealth addresses (covered elsewhere on this site), the IP address still links the transaction to your location and identity. Dandelion++ is designed to break that link.
How the stem phase works
Dandelion++ splits transaction propagation into two distinct phases: the stem phase and the fluff phase.
Stem Phase (Anonymization)
- Your wallet creates the transaction and selects a single random peer from its list of connected nodes. This is the first node in the stem path.
- Your wallet sends the transaction only to that one peer. No other nodes see it at this point.
- The receiving node does not forward the transaction immediately. Instead, it waits for a short, randomized delay (typically a few hundred milliseconds to a few seconds). This delay prevents timing analysis.
- After the delay, the node selects one of its peers at random and forwards the transaction along the stem. It does not broadcast to all peers.
- This process repeats: each node in the stem path passes the transaction to exactly one randomly chosen peer, each time with a randomized delay. The path length is not fixed - it can be as short as a few hops or extend longer, depending on network conditions and node behavior.
The key effect is that the transaction "whispers" through the network along a single chain, much like a dandelion's stem. An observer watching traffic at a particular node cannot tell whether that node is the original broadcaster or just a link in the chain.
How the fluff phase works
At some point, a node in the stem path decides to end the anonymization phase and broadcast the transaction to all of its peers. This is the fluff phase.
- The node that ends the stem selects a random probability threshold (often called a "fluff probability"). For example, it might have a 10% chance of fluffing on each hop. This means the stem length is unpredictable.
- When fluffing, the node sends the transaction to all of its connected peers - not just one.
- Those peers then forward the transaction normally to all of their peers, and within a few seconds the transaction spreads across the entire network.
From this point, the transaction's propagation looks like any ordinary broadcast. The original source is hidden because the fluff node - not your wallet - appears as the point where the transaction entered the public network.
What makes dandelion++ different from dandelion
Dandelion++ is an improved version of the original Dandelion protocol. The main differences address weaknesses found in the first design:
- Defense against "selfish" or malicious nodes. In the original Dandelion, a node that wanted to de-anonymize transactions could refuse to participate in the stem phase and immediately fluff, breaking the privacy chain. Dandelion++ requires nodes to follow the stem protocol honestly; any node that fluffs too early can be detected and penalized (or simply ignored for future stem routing).
- Better handling of network topology. Dandelion++ uses a "two-phase" stem routing that reduces the chance that an attacker controlling multiple nodes can link the stem to the origin.
- Robustness to timing attacks. The randomized delays in Dandelion++ are designed to be harder to correlate with network round-trip times, making it more difficult for a global observer to trace the stem backward.
Limitations and practical considerations
Dandelion++ provides strong privacy against passive network observers - entities that can see traffic but cannot manipulate it. However, it is not perfect:
- If an attacker controls a large fraction of the network's nodes, they might be able to reconstruct the stem path by correlating which nodes receive the transaction first. The more nodes an adversary controls, the higher the chance of identifying the source. This is a general limitation of any peer-to-peer anonymization scheme.
- Dandelion++ does not hide the transaction's contents. It only hides the IP address of the broadcaster. Other privacy features (such as ring signatures or stealth addresses) must handle hiding sender, receiver, and amounts.
- If your wallet connects to only one or two peers, the stem path is short and privacy is weakened. Using a full node with many connections improves the anonymity set.
- The protocol adds latency. Transactions take longer to propagate than in a simple flood broadcast. In practice, the delay is usually a few seconds, which is acceptable for most use cases.
Where dandelion++ is used
Monero is the most prominent cryptocurrency that implements Dandelion++. It was integrated into Monero in 2020 as part of a network upgrade. Other privacy-focused coins may use similar techniques, but the specific Dandelion++ implementation is most mature in Monero. As noted in other pages on this site, Monero also uses ring signatures, stealth addresses, and a 10-block unlock time - Dandelion++ complements these by protecting the network layer, not just the transaction layer.
Summary
Dandelion++ hides your IP address by routing your transaction through a random chain of nodes before broadcasting it publicly. The stem phase ensures that no single observer can tell where the transaction started, while the fluff phase spreads it normally. It is a practical defense against IP-based deanonymization, but its effectiveness depends on having enough honest nodes and a diverse set of peers. For current implementation details and configuration options, consult the Monero documentation or your wallet's settings.
Not financial advice. holdium.xyz publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.