An onion-only network path
TKMChain nodes use Tor onion services for peer discovery and transport. Onion-only mode keeps public IP addresses out of peer advertisements and rejects clearnet bootnodes.
Read the Tor installation guide · Read privacy mode
How a node connects
- Tor runs a local SOCKS5 listener and publishes the node's onion service.
bootnodes.gosupplies onion bootnodes with discovery disabled.- The node dials peers through Tor and advertises its onion hostname.
- HTTP and WebSocket RPC stay on loopback for local wallets and tools.
- Transaction propagation uses the configured Tor path and Dandelion-style stem handling where enabled.
Safe node defaults
Keep --http.addr=127.0.0.1 and --ws.addr=127.0.0.1 unless an authenticated private reverse proxy is required. Set an onion hostname and SOCKS5 endpoint explicitly, and use discport=0 for static onion bootnodes.
./gtkm \
--privacy.onion-only \
--p2p.tor-socks5=socks5://127.0.0.1:9050 \
--p2p.onion-hostname=<your-onion-hostname>.onion \
--bootnodes='enode://<node-key>@<bootnode>.onion:3000?discport=0' \
--http.addr=127.0.0.1 --ws.addr=127.0.0.1
The daemon can install or start Tor through the platform service manager when configured to do so. A missing onion hostname or unavailable proxy causes a clear startup error rather than silently falling back to a public IP.
What Tor protects
Tor hides the direct network origin from peers and keeps node advertisements on onion names. It does not hide block contents, consensus-visible transaction hashes, timing from a global observer, or the endpoint where a wallet stores its keys.
Mining and relays
Mining pools and Shield3 relays can expose onion endpoints. XMRig should connect through the local Tor SOCKS5 proxy when the pool publishes an onion hostname. Keep wallet-to-relay requests on Tor and use fixed request classes for batch privacy.