Privacy Tips

Built a privacy-first escrow service. Looking for real feedback from tforum.

Started by LanternSE · Feb 24, 2026

#8590
↳ Replying to @LanternSE
You can frame yourself as a neutral escrow not a marketplace. But that is a deflection. My critique isn't about permanent roles a marketplace has. It is about the asymmetry within any single transaction. The buyer's funds are locked and at risk while the seller's funds are not. It doesn't matter that a person can switch roles between transactions. Within the transaction that matters it is exactly the same game theory to a marketplace. The seller has nothing to lose but time while the buyer has their capital looked up. You can use whatever structural label you want but the same game theory exists regardless of what you call the platform.

The risk is not equal. In your side both the parties benefit from the escrow protection so splitting the fees are equal and fair. But you misunderstand me. My concerns is who bears the cost of dishonesty. It is the buyer. The person who puts up the most money in this transaction. They pay for the product/service. Any fee that goes to the sellers side can be baked into the price of such product/service. A 50/50 fee split does nothing to address the real concern. The buyer's funds are at risk not the seller's. The seller can inflate their price to absorb any transaction cost. You are not addressing the real problem.

Both need to agree before the money moves is a great user experience thing. But you misunderstand the core thought. I'm talking about forcing the seller to have some skin in the game before the transaction even begins. Smoother on-boarding for a dishonest seller is arguably worse not better. You got to protect where the money comes from because that is where the value is. It is the buyers who will drive your transactions not the sellers. Because sellers would rather there not be an escrow in the first place. Don't build things out for the sellers.

I want you to take a moment and really think about your reputation system instead of bond design. Now I'm going to tell you why it isn't strong enough. This is well established in darknet market history that reputation systems without bonds do not work over a prolonged period of time. A scammer does not care about a rating on a platform they never intend to use again. Sellers could complete 100 small transactions and just wait for that one large one to cash out. The cost of building reputation is trivial compared to the potential payout of one successful scam. Bonds exist on markets because reputation alone isn't enough. Let alone if you did do it, which I'm suggesting you don't, you will get that whole new seller problem. How does a buyer trust a new seller? Reputation systems provide no answer because there isn't one. If you have a bond it solves that issue immediately. You can trust sellers more because they have posted bond money as a collateral.

You talk about how requiring bonds reduces participation. Sure I agree. But you can also write your statement this way: "we know our system is more vulnerable without bonds, but we need users first." Launching without a necessary safeguard and hoping to add it later is how platforms get exploited early and lose credibility permanently. I know this is a business trade off but you are designing for trust you can't do the way you proposed.

Let's talk about neutrality. You say that you don't get paid unless a transaction happens and you said it in a way which makes it seems like you are agreeing with me. BUT you are fucking not. I say as an escrow provider you need to earn the same amount regardless of transaction outcome. This is the only way to make sure you don't favor one side. By saying you are earning only on completed transaction means YOU HAVE AN INCENTIVE TO PUSH TRANSACTION TO COMPLETION EVEN IF A DISPUTE IS VALID! You earn more for disputes while you earn nothing from declined transactions. All I'm saying is the seller should pay an upfront fee (which they would bake into the transaction price anyway) to make sure you are better aligned with neutrality. Your current model has more conflict of interests not fewer.

Look your intentions might be good. But good systems are not secured by good intentions. They are secured by making dishonesty EXPENSIVE. You failed to do that which makes your system unsound. Listen to me and just fix it.
#8591
↳ Replying to @Paris
fair pushback. You are right that calling it “neutral escrow” does not change the game theory inside a single transaction. Within any one deal, buyer capital is locked and seller capital is not. That asymmetry is the real issue, not whether users can switch roles across different transactions.

I also agree that a 50/50 platform fee split does not fix that. A seller can bake their half into the price, so the buyer still carries most of the financial risk if the seller is dishonest.

So here is what I am changing based on your critique.

Seller skin in the game

We are adding a seller commitment bond per transaction. It will be locked when the escrow is funded, not just when the request is accepted. It will be meaningful enough that dishonesty is expensive, and it will scale by tier based on transaction size.

If the deal completes normally, the bond is returned.

If the seller is found at fault in a dispute, the bond is partially or fully forfeited and used to compensate the buyer and cover dispute work.

This is not a marketplace vendor bond that blocks onboarding forever. It is a per transaction bond that directly fixes the single deal incentive problem you described.

Dispute fees and neutrality

I agree that earning more from disputes is bad optics and can create misalignment. We are moving away from a higher percent on disputed transactions.

Instead, disputes will use a separate dispute fee that is tiered and flat. The party who opens the dispute pays it. If the other party challenges, they pay it too. Winner gets their dispute fee back plus part of the challenger fee. The platform keeps a portion to cover the extra work. This discourages frivolous disputes and keeps incentives cleaner.

Platform getting paid only on completion

You made a valid point that earning only when a deal completes can create pressure to push completion. I am reviewing the fee timing so that the platform earns a predictable amount once escrow is funded, independent of whether it ends in release or refund. The goal is that we are not financially rewarded for forcing completion or for conflict.

Reputation alone is not enough

Agreed. Reputation helps, but it does not stop the “100 small deals then 1 big scam” problem. That is exactly why the per transaction seller bond is being added. Reputation will still exist to help buyers compare sellers, but it will not be the only protection.

My intention was never to deflect. You are pointing at a real structural weakness, and I am taking it seriously. If you are willing, I would like your opinion on what bond tiers feel meaningful enough to deter scams without making small deals impossible.
#8592
↳ Replying to @Paris
One additional question for you.

Given your focus on incentive alignment, do you believe a custodial escrow model with strong per transaction seller bonds is sufficient at early stage? Or would you argue that 2-of-3 multisig is structurally required from day one?

I am weighing simplicity versus maximum trust architecture and would value your view on that tradeoff.

Also, we are strongly considering moving to Monero only rather than mixed Bitcoin and Monero, to avoid privacy contradiction. Would that materially change your assessment?
#8593
↳ Replying to @LanternSE
Fuck ya. Finally got through to one. I don't know how long disputes take or how valuable your time is so decide that (keeping in mind your existing 5% transaction fee) and pick a dispute bond fee where half of it is worth the work. Tie it to the amount the transaction is worth. Bigger transactions will have much larger dispute processes while smaller ones will be very much decided on the facts of the matter.
#8594
↳ Replying to @LanternSE
People don't trust you. You are new and have no reputation. Because of that there is a risk you may just take the escrow and run. Having a multisig system in place where you can't be dishonest too provides more security and trust immedately. The only issue is the user experience as you said. But you can always just provide an option. Smaller transactions probably are not worth doing the whole multisig process while larger ones will want to. If you design a method to do this in monero, and make it easy, I am being completely serious that it will be a multi multi million dollar business. Monero multisig is not trivial (look at the difficulty I've been having with test4pay) and there has been nearly no platform on the darknet which has made it truly easy to do.
#8596
↳ Replying to @Paris
Yeah I completely agree with you on the multisig point.

Ideally that is the end goal. A 2-of-3 Monero multisig system where the escrow provider cannot just run off with funds is obviously the strongest trust model.

The problem right now is exactly what you mentioned: the user experience and the engineering complexity. Monero multisig is not trivial to implement in a way that normal users can actually use without breaking things. I spoke with a seasoned dev about helping implement a clean multisig flow and unfortunately he’s not available right now.

So at the moment I’m continuing to work on the multisig side in parallel, but the current system is ready to operate and test. I don’t want to hold the entire platform hostage waiting for one very difficult feature to be finished.

Over the past week I basically lived in front of my computer applying a lot of the feedback from this thread and other people. Several structural changes were made based on what you pointed out:

• Seller commitment bond per transaction

• Tiered dispute fee structure instead of percentage disputes

• Incentive alignment fixes so the platform isn’t rewarded for disputes

• A few other internal flow improvements

So the system is already much closer to the model you were describing earlier.

If you don’t mind, I would actually really value testing the flow with someone other than myself. Real interaction between two different users is where edge cases show up.

I can provide a sample user account you can log into so we can simulate a buyer/seller interaction and walk through the escrow process step by step. No real money needed, just testing the mechanics and seeing if anything feels off.

Your feedback has honestly been some of the most useful in the thread because you’re looking at it from the game theory / incentive design side, which is exactly what matters for escrow systems.

And you’re absolutely right about one thing:

If someone ever manages to make Monero multisig truly easy for normal users, that would be a massive step forward for this space.

I’m still pushing toward that. It’s just going to take some time.
#8597
↳ Replying to @krakon9
Fair enough. You shouldn’t trust me.

New escrow services should be treated with skepticism. That’s just common sense. If someone blindly trusts a brand new platform with real money, that’s on them.

Right now the goal isn’t “trust me bro”. The goal is to build a system where trust matters less.

That’s why I’ve been implementing things like:

• per-transaction seller bonds

• tiered dispute fees to discourage abuse

• transparent dispute handling inside the platform

• and working toward Monero multisig (which removes the custodial trust problem entirely)

Multisig is the ideal endgame, but as you probably know Monero multisig is not trivial to implement in a way normal users won’t completely break. I’ve spoken with a dev about it and I’m still working on that side in parallel.

In the meantime the platform itself is ready to run and test.

And honestly, if someone doesn’t trust it yet, they shouldn’t use it for serious amounts. Start small or don’t use it at all. That’s completely reasonable.

Trust isn’t something you ask for on day one. It’s something you build over time by not exit scamming, handling disputes fairly, and letting people try to break the system publicly.

So yeah skepticism is healthy. I’d be more worried if nobody questioned it.

If you want to actually test the flow instead of just speculating, I’m happy to give a sample user account so two people can simulate a transaction and see how the process feels.

That kind of real testing is way more useful than theory.
#8598
↳ Replying to @LanternSE
I'm not here to shit on your parade, this was great information.

But if you post your Lantern search engine without SERIOUS changes, I'll remove it from any sub I mod.

/u/therealmikoyangurevich recommended Regex to me. You may want to look into it.

Members-only continuation

This discussion contains more posts.

Create an account or sign in to continue reading the full conversation. 9 additional posts await inside.

Create an accountSign in