A journalist in a country with media censorship receives a message from a source offering documents about government corruption. The source needs to verify the journalist’s identity and ensure the payment for the information cannot be traced back to either party. Bank transfers are monitored. Cryptocurrency appears practical, but choosing the wrong wallet or exchange can expose the recipient’s identity, location, device fingerprint, or transaction history to the authorities the source is trying to evade. The question is not whether crypto can solve this problem. It is which wallet architecture, privacy features, and operational discipline actually reduce the specific risks that journalists and their sources face in restricted environments.
Cake Wallet, launched in 2018 and trusted by over 1 million users, is built as a non-custodial, open-source application designed for exactly this scenario. The wallet prioritizes complete private key control, meaning neither the developers nor any third party can freeze funds, access recovery phrases, or maintain records of the user’s assets. Multiple cryptocurrencies are supported, including Monero—a protocol specifically designed to obscure sender, receiver, and amounts—alongside Bitcoin, Ethereum, Litecoin, and stablecoins. Advanced privacy tools like Silent Payments, PayJoin, Tor integration, and hardware wallet support create a technical foundation that differs fundamentally from consumer-grade platforms. But technical capability alone does not determine security. For a journalist receiving sensitive payments, the wallet choice is part of a larger operational security plan.
Why non-custodial architecture matters for journalists under surveillance
A custodial exchange or wallet—one where a company holds users’ private keys on its servers—creates a single point of failure for journalists. If authorities demand account records, freeze assets, or compel the platform to hand over information, the journalist’s ability to deny knowledge of the funds becomes impossible. The exchange has the evidence. Bank transactions and exchange accounts leave paper trails that connect identity, payment amounts, timing, and often the stated purpose of the transfer. A journalist receiving a wire transfer for “consulting” from an offshore account may trigger investigations, asset seizures, or criminal charges under anti-money-laundering laws that were not designed with source protection in mind.
A non-custodial wallet eliminates that intermediary. The journalist controls private keys on their own device rather than trusting a platform. If the device is secured and the recovery phrase is stored offline, no company can be forced to produce transaction records because no company maintains them. This is particularly important in countries where media organizations lack legal standing to resist requests for banking information or where financial institutions are required to report all international transfers to government agencies. The wallet does not require identity verification, KYC documentation, or connection to traditional banking infrastructure. It operates on cryptocurrency networks that exist outside any single country’s financial system.
That separation creates an operational advantage: the journalist can receive Monero, Bitcoin, or other digital assets without an exchange ever learning their name, location, device type, or transaction patterns. The Cake Wallet crypto wallet application does not collect user data, log IP addresses, or maintain cloud backups tied to email accounts. The wallet’s open-source code is publicly auditable, meaning security researchers and privacy advocates can examine whether privacy claims match implementation. For a journalist evaluating tools, that transparency is more useful than marketing promises. An adversary cannot compel disclosure of information the wallet never stored.
The practical consequence is that a source can send payment and a journalist can receive it without involvement from any institution that maintains financial records or knows the recipient’s identity. This is distinct from anonymity in the abstract sense. It means reducing the number of places where an adversary can obtain proof of the transaction, the timing of the payment, or the identity of either party.
Monero as the protocol designed for privacy journalism
Bitcoin was designed with strong cryptography but a transparent ledger. Every transaction, address, and amount is permanently visible on the public blockchain. Chain analysis tools can map spending patterns, identify when addresses are controlled by the same entity, and link transactions to exchanges or services where users provided identity information. A journalist receiving Bitcoin from a source can be de-anonymized if the source ever spent or withdrew funds from an exchange, if timing patterns reveal the transaction, or if authorities compel the exchange to identify the withdrawal address. The blockchain itself becomes evidence.
Monero, by contrast, uses ring signatures, stealth addresses, and RingCT to obscure senders, receivers, and transaction amounts at the protocol level. A Monero payment does not reveal the sender’s address, does not reveal the recipient’s address to anyone without the private view key, and does not broadcast transaction amounts publicly. The sender and receiver amounts are hidden through cryptographic commitments. This means a journalist receiving Monero from a source cannot be directly identified from the blockchain, even if authorities seize the journalist’s device and examine its transaction history. The blockchain records only that a transaction occurred, not who sent or received it.
Cake Wallet’s Monero integration includes automatic subaddresses, which are separately generated receiving addresses tied to the same wallet. A journalist can create a unique subaddress for each source without reusing a single address across multiple payments. This prevents someone observing the blockchain from discovering that two different sources are sending money to the same entity. Subaddresses are not a privacy feature that requires technical configuration; they are built into the wallet’s default behavior. A journalist who receives payment to Address A from Source 1 and to Address B from Source 2 leaves no on-chain indication that both addresses are controlled by the same wallet.
The background synchronization feature also matters for operational security. A journalist using Cake Wallet can keep their device offline most of the time, with the wallet syncing only when connected to Tor or a trusted node. This reduces exposure of the device’s IP address and limits the frequency with which the wallet reveals it is active. For journalists working in environments where internet activity is monitored, reducing the number of times a device connects to the network—and using Tor to mask the IP address when it does—meaningfully decreases the risk that surveillance infrastructure can detect which devices are accessing privacy-focused wallets.
Bitcoin privacy tools for situations where Monero is not available
Some sources may only be able to send Bitcoin. Some journalists may need to convert crypto to fiat currency through exchanges that list Bitcoin but not Monero. In these cases, Cake Wallet’s Bitcoin privacy features—Silent Payments, PayJoin v2, and UTXO coin control—provide mitigations that do not exist on consumer wallets. These are not substitutes for Monero’s protocol-level privacy, but they reduce the information leaked to observers.
Silent Payments allow a journalist to publish a single address without exposing it to repeated reuse. A source can independently derive a unique, non-reusing address from the published Silent Payment address without the journalist needing to generate addresses beforehand or manually provide a fresh address for each payment. This prevents the common blockchain analysis pattern of identifying that multiple payments received by a target all go to addresses derived from the same parent key. For a journalist receiving donations or payments from multiple sources, Silent Payments reduce the amount of information on the blockchain that could link those payments together.
PayJoin v2 is a transaction construction protocol in which both the sender and receiver contribute inputs to a transaction. This breaks the assumption that a Bitcoin transaction has one sender and one receiver. An observer analyzing the blockchain will see inputs from both parties and cannot easily determine who is actually sending and who is receiving. For a journalist receiving payment from a source, a PayJoin transaction makes it ambiguous which party is the recipient, adding noise to transaction analysis. The feature requires coordination between sender and receiver and is not automatic, but for planned transfers it is a useful tool.
UTXO coin control allows a journalist to explicitly choose which pieces of Bitcoin are spent rather than trusting the wallet to select inputs automatically. This matters because consolidating Bitcoin from two different sources in a single transaction can link them together on the blockchain. A journalist receiving payments from multiple sources can avoid this linking by being selective about which UTXOs to spend together. For a journalist later converting Bitcoin to fiat currency on an exchange, keeping UTXOs separated by source reduces the likelihood that an exchange employee or analysis system will notice that multiple distinct incoming transactions are being withdrawn by the same person.
Operational security: the device, the recovery phrase, and the network connection
A wallet is software running on a device, and that device is an attack surface. A compromised phone or computer—one that has been infected with malware, updated with a state-sponsored spy package, or physically accessed and modified—can leak the recovery phrase, private keys, or transaction information regardless of how secure the wallet’s code is. For a journalist in a country with active targeting of media organizations, device security often exceeds wallet security as the determining factor in whether the operation succeeds.
Cake Wallet supports biometric login, which can prevent casual access to the wallet from a stolen phone. But biometrics protect against immediate use, not against a sophisticated adversary. A recovery phrase is the true security boundary: whoever holds that phrase controls the assets forever, can restore them on any device, and can spend them without any trace of previous ownership. For a journalist receiving sensitive payments, the recovery phrase must be treated as operational security material comparable to source names or classified documents. It should be written down on paper—not stored in cloud notes, email, messaging apps, or any digital system. It should be kept in a physical location that survives a search, such as a safe deposit box or a trusted location outside the country. A journalist should test the recovery process on a clean device without internet connectivity before it becomes necessary, ensuring they can restore the wallet quickly if the primary device is seized or destroyed.
Hardware wallets and air-gapped devices add another layer. A Ledger hardware wallet, or the more specialized Cupcake air-gapped signing device, keeps private keys isolated from internet-connected devices. A journalist can verify transaction details on the secure device before signing, and the signed transaction is then broadcast through the internet-connected computer. This prevents malware from stealing keys or modifying transaction details. For journalists who may need to defend against sophisticated attackers—including government-sponsored technical operations—hardware isolation is often worth the added complexity.
Network connection deserves equal attention. Cake Wallet can operate over Tor, which routes traffic through multiple relays to obscure the user’s IP address. A journalist connecting to Cake Wallet’s Tor integration will not expose their device’s network location to cryptocurrency nodes, exchanges, or observers monitoring network traffic in their country. This is particularly important in environments where internet service providers are required to log which services users access. The privacy wallet is less useful if authorities can prove that a journalist’s device was connecting to cryptocurrency infrastructure at the exact moment they received a sensitive payment from a source.
Converting crypto to fiat currency without exposure
Receiving crypto is only half the problem. A journalist often needs to convert it to local currency to pay rent, buy food, or fund operations. Exchanges that offer fiat withdrawal require identity verification, which defeats the purpose of receiving anonymous Monero or Bitcoin. This creates a practical bottleneck: the journalist can receive payment privately, but converting it requires trusting an exchange with their identity and accepting that their name will be recorded in connection with the transaction.
There is no perfect solution to this problem within the current financial system. But journalists and sources can reduce exposure by planning for it. A source can send Monero instead of Bitcoin, since Monero offers stronger privacy and is harder to trace even after an exchange withdrawal. A journalist can use Cake Wallet’s built-in exchange feature to swap Monero for stablecoins like USDT, spreading the risk across multiple asset types and reducing the likelihood that a single exchange becomes aware of the entire payment flow. Some journalists work with fixers or trusted intermediaries in other countries who can withdraw and transfer funds with lower personal risk. The point is that the wallet is one component of a larger operation, and its privacy features matter most when the entire flow—receiving, holding, and converting funds—is planned with security in mind.
Cake Wallet’s support for multiple cryptocurrencies, stablecoins, and the decentralized exchange routing means a journalist does not need to use multiple wallets or platforms. A single non-custodial application can receive Monero from a source, hold it securely with automatic subaddresses preventing linking, and convert to other cryptocurrencies if necessary. This reduces the number of devices that need to be secured, the number of places where credentials can be stolen, and the number of applications that could malfunction or leak information.
What sources need to understand about sending payment
A journalist explaining to a source how to send payment must address several technical points. First, if the source has any prior connection between their identity and their sending address—such as having bought the Bitcoin or Monero on an exchange using their name—that connection is permanent. A source should plan the payment chain backwards: understanding that when they send funds, they are sending from an exchange-verified address tied to their identity. To minimize this exposure, a source should acquire cryptocurrency through peer-to-peer channels, privacy-focused exchanges, or mixers that obscure the connection between fiat deposits and cryptocurrency withdrawals. This is not the journalist’s responsibility, but understanding that the source’s operational security determines the transaction’s security helps the journalist evaluate whether the setup is actually protective.
Second, the source and journalist should agree on the payment destination—either a Monero subaddress or a Bitcoin address generated by Cake Wallet—before the transfer occurs. The source should verify the address format and confirm they understand which network and currency they are sending. A mistake as simple as sending to the wrong network can result in lost funds with no recovery process. Cake Wallet’s address display includes the network and asset type, but a source unfamiliar with cryptocurrency might not notice the difference between a Bitcoin address and a Litecoin address if they appear similar on the screen.
Third, the source should understand that the journalist may need to ask follow-up questions about the transaction after it is sent. The journalist will have a transaction identifier, a timestamp, and perhaps an amount, but confirming that the payment arrived and matching it to the correct source may require careful coordination. For Monero, the journalist can verify the transaction using the private view key but cannot easily prove to the source that it arrived without potentially revealing the wallet to a third party. Establishing a pre-agreed signal—a phrase or code word exchanged through a secure messenger—can help the journalist confirm receipt without explicitly referencing the crypto transaction in any medium that could be monitored.
Choosing between Cake Wallet’s mobile and web platforms
Cake Wallet is available on iOS, Android, and web, with slightly different feature sets on each platform. For journalists in high-risk countries, the mobile platform offers some advantages: it is easier to secure a phone than a computer, biometric login on modern phones uses hardware-backed encryption, and phones are less likely to be subject to malware compared to computers with administrative access. However, phones are also more frequently seized during arrests or searches. A journalist should consider whether their threat model makes a phone a reasonable device for holding sensitive assets or whether a dedicated computer that can be kept offline most of the time is more appropriate.
The web platform accessible through browsers can be useful for situations where the journalist is using shared computers or needs to access the wallet from different locations. However, web platforms have different security properties than native applications. A phishing attack could redirect the journalist to a fake Cake Wallet website. An ISP or network monitor could see that the journalist is accessing the Cake Wallet domain. A browser with malicious extensions could steal credentials or recovery phrases. The open-source code is the same, but the execution environment is less isolated. For journalists who do use the web version, accessing it exclusively through Tor, using a dedicated browser profile with minimal extensions, and verifying the domain carefully before entering any sensitive information should be standard practice.
Journalists should avoid storing recovery phrases on the same device where the wallet runs. A phone that holds both the active wallet and a cloud backup of the recovery phrase is more exposed than one where the recovery phrase is stored physically elsewhere. For long-term asset storage, a recovery phrase written on paper and stored in a secure location provides better protection than any digital storage method, since digital storage can be compromised remotely whereas physical storage requires an adversary to physically access the location.
Testing the setup before operating with real sources
A journalist should not receive their first sensitive payment using a wallet they have never tested. Instead, the setup process should be separated from actual operations. A journalist should install Cake Wallet, create a test wallet, generate a Monero subaddress, test sending a small amount of cryptocurrency to it (perhaps from a legitimate exchange purchase), verify that the wallet receives it, and confirm that they can restore the wallet from the recovery phrase. This process surfaces operational questions: Does the device have network connectivity when needed? Does the journalist understand which address format they are using? Can they verify that a transaction was received? Do they remember how to securely store and later retrieve the recovery phrase?
Testing also reveals device-specific issues. An older phone might have problems with Tor connectivity. A computer with high system load might sync slowly. A journalist who discovers these issues during a test can address them before an actual payment is in transit. Testing reduces the likelihood that a critical mistake—mistyping an address, losing the recovery phrase, or failing to verify a transaction—occurs during an operation that involves a sensitive source.
The journalist should also plan for the worst case: what happens if the device is seized, the wallet is lost, or the recovery phrase becomes inaccessible. Ideally, a second recovery phrase for the same wallet should be stored in a geographically separate location. Some wallets support multi-signature structures where several keys must be combined to spend funds, but Cake Wallet currently uses single-key recovery. This means the recovery phrase is the complete backup, and losing it means losing permanent access to the assets, while someone else obtaining it gains complete control.
Frequently asked questions
Is Monero safer than Bitcoin for receiving payments from sources?
Monero uses cryptographic protocols that hide sender, receiver, and amounts at the blockchain level. Bitcoin’s transparent ledger can expose transaction relationships and amounts to anyone observing the blockchain. For a journalist receiving sensitive payments, Monero provides stronger privacy because the transaction cannot be linked to the journalist’s identity through blockchain analysis alone. Bitcoin offers privacy tools like Silent Payments and PayJoin that reduce leakage but do not provide the same level of obscurity as Monero’s protocol design.
What if authorities seize my device and I have Cake Wallet installed?
If the device is seized before funds are transferred, authorities can see that the wallet is installed but cannot access the private keys without the recovery phrase or biometric credentials. If biometric authentication fails after a certain number of attempts, the wallet will lock. Authorities can potentially extract biometric data or force entry, but the recovery phrase—if stored separately and securely—remains protected. The journal is not obligated to provide the recovery phrase under most jurisdictions’ privilege laws, treating it similarly to editorial sources.
Can a source send payment if they do not know how to use cryptocurrency?
A source does not need to install Cake Wallet; they only need to send Monero or Bitcoin to the address the journalist provides. A source can acquire cryptocurrency through an exchange, peer-to-peer trade, or other means, and transfer it using any wallet or service. However, the source’s security chain determines the safety of the payment. A source sending from an exchange-verified account creates a permanent link between their identity and the transaction. A source using a privacy wallet or peer-to-peer acquisition reduces this risk. The journalist should coordinate with sources about how they plan to acquire and send funds as part of the operational security discussion.