An offer to share the results of an independent audit of how Spark is used on the public Firo chain, with the evidence, method and tooling behind it.
I analyzed public Firo chain data to find out what an outside observer can learn about the people who move coins into and out of the Spark pool. The results show that Spark's cryptography held: no finding depends on breaking it. The exposure comes from how coins are handled before they go in and after they come out.
Several of these patterns are common, measurable and fixable through wallet defaults and user guidance. I would like to share the full results with the community organization so they can inform wallet development, documentation and communication with users and masternode operators.
████% of public withdrawals can be tied to a deposit by the same owner, without touching Spark's cryptography.
Exact figures are withheld in this summary and provided under the terms below.
I built and maintain FiroBlocks, the Firo block explorer, together with its Firo RPC service. The community has partly funded FiroBlocks' continued maintenance. I am also pursuing a master's degree in cybersecurity.
Eleven questions were examined; four showed no leak.
| Area | What it means for users | Assessment | Measured impact |
|---|---|---|---|
| Same owner on both sides | Reused addresses and wallet clustering tie withdrawals to the same owner's deposits. | ▲ Leak | ████ withdrawals |
| Masternode rewards cycled through Spark | Operators who deposit rewards often merge withdrawn coins back into their own wallets. | ▲ Leak | ████ operators |
| Where withdrawn coins go next | Withdrawn coins spent together reveal shared ownership, even without a deposit link. | ▲ Leak | ████ outputs |
| Masternode collateral funded from Spark | Large withdrawals turned into masternode collateral make the destination visible. | ◆ Partial | ████ FIRO |
| Exact coin values | A coin withdrawn untouched carries a fingerprint of the deposit that created it. | ◆ Partial | ████× fewer candidates |
| Large multi-coin sweeps | Spending hundreds of coins at once points to the few depositors who hold that many. | ◆ Partial | ████ recipients |
| Daily activity rhythm | A fixed daily routine on both sides of the pool is measurable. | ◆ Partial | top ████% |
| Amount and timing round trips | Matching withdrawals to similar-sized deposits does no better than chance. | ● No leak | at chance |
| Fee rates | Withdrawal fees carry no usable wallet signature. | ● No leak | at chance |
| Spark name registrations | Registrations in the period were paid privately and reveal no payer. | ● No leak | none found |
| Public change on Spark spends | Spends return change privately; no public change exists to analyze. | ● No leak | none found |
Legend: ▲ leak: links owners outright · ◆ partial: narrows the candidates or exposes one side · ● no leak: indistinguishable from chance · ████ figure withheld
The no-leak results are as useful as the leaks: they confirm which parts of Spark's design work as intended and can be communicated to users with confidence.
Most of the exposure can be fixed outside the protocol.
| Deliverable | Contents | Intended audience |
|---|---|---|
| Public report | All eleven findings with aggregate figures, charts, method, controls and limits. | Can be published |
| Internal report | Adds the strongest cases per finding and full appendices with transaction and address-level evidence. | Named reviewers only |
| Recommendations | Prioritized changes for wallets, operator guidance and user documentation, mapped to each finding. | Can be published |
| Briefing | A walkthrough of the findings and Q&A with the people who will act on them. | Core contributors |
| Analysis pipeline | Source code to reproduce the results and rerun them on new data. | By agreement |
| Follow-up runs (optional) | Reruns after wallet changes ship, or over a longer stretch of chain history. | By agreement |
The internal edition can link real users' transactions. I propose handling it as a private disclosure:
The core user-protection guidance will be shared with the core team regardless of funding; compensation covers the detailed evidence, reports, briefing and tooling.
If the proposal is not funded, further use of this research is at my discretion, including continued work as part of my master's program in cybersecurity.
All amounts are in FIRO.
Initial audit complete. Reports and briefing within 7 days of approval.
14 days between the private briefing and any public summary, to be agreed with the reviewers.
MIT
Open to discussion.
Figures in this summary are withheld deliberately. They are available to the community organization under the terms above.# Spark Audit Data Proposal
An offer to share the results of an independent audit of how Spark is used on the public Firo chain, with the evidence, method and tooling behind it.
I analyzed public Firo chain data to find out what an outside observer can learn about the people who move coins into and out of the Spark pool. The results show that Spark's cryptography held: no finding depends on breaking it. The exposure comes from how coins are handled before they go in and after they come out.
Several of these patterns are common, measurable and fixable through wallet defaults and user guidance. I would like to share the full results with the community organization so they can inform wallet development, documentation and communication with users and masternode operators.
████% of public withdrawals can be tied to a deposit by the same owner, without touching Spark's cryptography.
Exact figures are withheld in this summary and provided under the terms below.
I built and maintain FiroBlocks, the Firo block explorer, together with its Firo RPC service. The community has partly funded FiroBlocks' continued maintenance. I am also pursuing a master's degree in cybersecurity.
Eleven questions were examined; four showed no leak.
| Area | What it means for users | Assessment | Measured impact |
|---|---|---|---|
| Same owner on both sides | Reused addresses and wallet clustering tie withdrawals to the same owner's deposits. | ▲ Leak | ████ withdrawals |
| Masternode rewards cycled through Spark | Operators who deposit rewards often merge withdrawn coins back into their own wallets. | ▲ Leak | ████ operators |
| Where withdrawn coins go next | Withdrawn coins spent together reveal shared ownership, even without a deposit link. | ▲ Leak | ████ outputs |
| Masternode collateral funded from Spark | Large withdrawals turned into masternode collateral make the destination visible. | ◆ Partial | ████ FIRO |
| Exact coin values | A coin withdrawn untouched carries a fingerprint of the deposit that created it. | ◆ Partial | ████× fewer candidates |
| Large multi-coin sweeps | Spending hundreds of coins at once points to the few depositors who hold that many. | ◆ Partial | ████ recipients |
| Daily activity rhythm | A fixed daily routine on both sides of the pool is measurable. | ◆ Partial | top ████% |
| Amount and timing round trips | Matching withdrawals to similar-sized deposits does no better than chance. | ● No leak | at chance |
| Fee rates | Withdrawal fees carry no usable wallet signature. | ● No leak | at chance |
| Spark name registrations | Registrations in the period were paid privately and reveal no payer. | ● No leak | none found |
| Public change on Spark spends | Spends return change privately; no public change exists to analyze. | ● No leak | none found |
Legend: ▲ leak: links owners outright · ◆ partial: narrows the candidates or exposes one side · ● no leak: indistinguishable from chance · ████ figure withheld
The no-leak results are as useful as the leaks: they confirm which parts of Spark's design work as intended and can be communicated to users with confidence.
Most of the exposure can be fixed outside the protocol.
| Deliverable | Contents | Intended audience |
|---|---|---|
| Public report | All eleven findings with aggregate figures, charts, method, controls and limits. | Can be published |
| Internal report | Adds the strongest cases per finding and full appendices with transaction and address-level evidence. | Named reviewers only |
| Recommendations | Prioritized changes for wallets, operator guidance and user documentation, mapped to each finding. | Can be published |
| Briefing | A walkthrough of the findings and Q&A with the people who will act on them. | Core contributors |
| Analysis pipeline | Source code to reproduce the results and rerun them on new data. | By agreement |
| Follow-up runs (optional) | Reruns after wallet changes ship, or over a longer stretch of chain history. | By agreement |
The internal edition can link real users' transactions. I propose handling it as a private disclosure:
The core user-protection guidance will be shared with the core team regardless of funding; compensation covers the detailed evidence, reports, briefing and tooling.
If the proposal is not funded, further use of this research is at my discretion, including continued work as part of my master's program in cybersecurity.
All amounts are in FIRO.
Initial audit complete. Reports and briefing within 7 days of approval.
14 days between the private briefing and any public summary, to be agreed with the reviewers.
MIT
Open to discussion.
Figures in this summary are withheld deliberately. They are available to the community organization under the terms above.