BasicSwap enables fully non-custodial atomic BTC↔XMR swaps via OtVES adaptor signatures. This 2026 review walks through setup, execution steps, supported coins, and privacy trade-offs.
BasicSwap serves as a decentralized coordination layer and messaging protocol built on the SMSG network. It enables peer-to-peer atomic swaps without ever holding funds, operating servers, or running a central matching engine. Settlement happens exclusively on the underlying blockchains through cryptographic primitives such as HTLCs for script-based coins and OtVES adaptor signatures for scriptless assets like Monero.
The protocol distributes a shared order book via encrypted SMSG gossip across a peer-to-peer mesh. Makers and takers communicate directly; the software only coordinates messages and verifies on-chain steps. Users always control their own keys inside local coin core wallets, making the system fully non-custodial.
BasicSwap carries an MIT license and imposes no accounts, signups, KYC requirements, or native token. All swaps are limit orders only, with participants paying standard network fees. In 2026 the project released both a full Desktop client that runs coin cores locally for liquidity providers and a lighter Mobile client suited to takers.
Because the platform never executes or custodies trades, its role remains strictly that of a messaging and coordination tool. This design keeps the attack surface limited to the client software and the public blockchains involved.
BasicSwap shifted from HTLC-based swaps to OtVES adaptor signatures specifically to handle Monero. Script-supported chains can lock funds behind a hash and preimage that both parties reveal sequentially, but Monero lacks the scripting language required for HTLC construction. Without a scriptless method, any BTC↔XMR trade would need wrappers or trusted intermediaries that reintroduce custody risk.
OtVES, also called One-Time Verifiably Encrypted Signatures, solves this by letting one party create a signature that remains encrypted until the counterparty publishes their own transaction on the other chain. The encryption is verifiable in advance, so neither side can cheat without the other detecting it immediately. The protocol is semi-scriptless: Bitcoin still uses a limited script for the adaptor setup, while Monero handles its side through the adaptor signature alone. This combination delivers true atomicity on the underlying blockchains with no bridges or wrapped assets.
Bidirectional BTC↔XMR support using this method has been live since 2023. Confirmation defaults are set to one block for Bitcoin and three blocks for Monero, with other coins using one to three depending on the pair. These thresholds balance finality against the sequential nature of the swap steps, keeping typical completion times in the tens of minutes.
BasicSwap lists 14 coins as of 26 August 2026. Exact pair availability and the method used (A for adaptor signatures or H for HTLC) depend on the specific combination rather than a fixed per-coin setting.
| Coin | Method Indicator | Notes |
|---|---|---|
| Bitcoin | A / H | Varies by counterparty coin |
| Monero | A | OtVES only |
| Litecoin (MWEB) | A / H | Varies by pair |
| Particl (anon variants) | A / H | Varies by pair |
| Bitcoin Cash | A / H | Varies by pair |
| Dash | A / H | Varies by pair |
| Decred | A / H | Varies by pair |
| Firo | A / H | Varies by pair |
| Dogecoin | A / H | Varies by pair |
| Namecoin | A / H | Varies by pair |
| PIVX | A / H | Varies by pair |
| Wownero | A | OtVES only |
Support for any given pair is not guaranteed and changes with available liquidity. All orders are user-provided; BasicSwap itself supplies neither counterparties nor inventory.
Users retain full control of private keys throughout; no funds ever leave their local wallets until the cryptographic conditions are met on-chain.
BasicSwap runs over the encrypted SMSG peer-to-peer mesh, but users who connect via clearnet nodes still expose their IP addresses to counterparties during order-book gossip and swap coordination.
Makers must operate full Bitcoin and Monero nodes locally. These nodes broadcast real-time data that can reveal wallet activity and timing patterns if the host machine is not isolated from the public internet.
Obtaining the initial BTC or XMR through any KYC exchange creates a permanent on-ramp record that links identity to the subsequent atomic swap, even though the swap protocol itself records nothing on-chain.
To limit exposure, route the entire BasicSwap Desktop session through Tor before starting the client. Run maker nodes inside a dedicated virtual machine or hardware device that never initiates outbound connections without obfuscation. Acquire coins only from non-KYC sources and, when using Monero, connect the wallet daemon either to your own local node or to a trusted remote node over an encrypted channel. Review each new release for changes to network behavior before updating.
BasicSwap charges 0% protocol, trading, or service fees. Users pay only the standard on-chain network fees for the coins they move during settlement on the underlying blockchains.
Swaps use sequential on-chain steps with confirmation defaults of one for Bitcoin and three for Monero. Overall completion typically falls in the tens of minutes range, depending on block times and network conditions.
The Desktop version runs full nodes and coin cores locally for makers. Takers can use the Mobile or light-client variant. All activity remains non-custodial, with users retaining control of their own keys in the respective coin wallets.
Atomic design ensures either both sides complete or funds return via refund paths. Recent updates have hardened these mechanisms, including mercy keyshare options, so locked coins are recoverable without counterparty cooperation once time locks expire.
No account, signup, or KYC is required. The protocol operates through a distributed order book over the SMSG mesh and settles directly on-chain.
Because the software is non-custodial and keys stay in your local coin wallets, recovery follows each coin’s standard backup procedures. The protocol itself never holds funds or private keys.