I noticed that the service *uses* its own liquidity pools with a maximum limit of $150,000, and there are 14 cryptocurrencies. Does this mean your reserves are over $1 million? Can you provide proof of this, or provide an escrow?
Thank you for the questions.
We operate two separate pools. Pool 1 receives customer deposits, while Pool 2—funded with our own assets—is used for payouts. A customer’s incoming funds are not used to fund that same order’s payout. Before sending, we instantly convert the required amount from Pool 2 into the requested coin.
Therefore, we do not need to hold $150,000 in each of the 14 assets. Processing a maximum-size order requires at least $150,000 in liquid payout funds, not over $1 million. Our available payout liquidity is currently above $150,000.
For security reasons, we cannot disclose the pool addresses. However, we have started placing deposits with independent platforms and will continue doing so to build user trust.
Permitted use
An exchange may be requested only where it is not prohibited by applicable law.
What do you mean by this part?
“Permitted use” simply means that the transaction and source of funds must be lawful under the laws applicable to the user. It does not imply KYC; this responsibility remains with the user.
Fair points.
Yes, as you said, there is room for improvement without even using JS. I appreciate that you care about privacy and focusing on that when building the website. Yes, please add the FAQ, which will help users get the answers without contacting support. It seems the support says 24/7 online. Is this actually real? If so, that is pretty impressive considering a new exchange. I assume you already hired team members to handle support.
We are already working on the FAQ and expect to publish it within the next 1–2 days.
And yes, our support is genuinely available 24/7. We have already hired a dedicated team to provide round-the-clock assistance.
Permitted use
An exchange may be requested only where it is not prohibited by applicable law.
What do you mean by this part?
I think this means that you should not use the exchange if you live in a region where crypto exchange is prohibited. This is just a line for the regulators that may want to hunt down the privacy exchanges. However, we can wait for their official reply. Since there is no account and no KYC, there is no way to know where the users are from.
You are correct. This is a standard legal formality clarifying that each user is responsible for ensuring that their use of the service complies with the laws applicable to them.
They claim they are using their own liquidity pool through their rules; this makes them custodial. My coins go in first then out from their end: no company name or jurisdiction, typical counterparty risk.
The home page says "clean coins on pay out," their rule said it has noAML screenings. The homepage text and their rules seems inconsistent in this regard.
As explained above, we use two separate pools: Pool 1 receives customer deposits, while Pool 2 is used exclusively for payouts. A customer’s deposited coins are not forwarded to another user—the payout is made from clean funds prepared in advance in Pool 2.
Therefore, there is no contradiction: “no AML screening” refers to incoming customer funds, while “clean coins on payout” refers to the separate liquidity used for payouts.
It uses ED25519 for its key; It is "Pablo Cash Order Signing" with their Pablo Cash UID and no expiry:
Primary: 3EC2 8B27 CD30 3B2B B2BD 18E7 9429 7C45 C682 A409
Subkey: 06E8 EEB8 C9D3 628F 4ECC E1DB F52B A7AD D576 0622
Key readily visible on the webpage, their documented downloads page 500-error'd for me; please pin your subkey-finger-print from the Onion and NOT the Cloud Flare Onion's page; actually, I see it at onion.page saying that their subkey-sign could not verify payment.
We have just checked the download page and signature verification, and everything is working correctly on our side. We recently updated the website, so your test may have coincided with the deployment.
If possible, please try again. If the error persists, let us know and we will investigate it further.
Test22.pablo.cash and creat22.pablo.cash can be seen in the same Cloudflare IP block as can be found in a CT-log. (a form of pre-production exposure)
That is correct. These were temporary subdomains created for testing and have now been removed. However, their historical records remain visible in public Certificate Transparency logs.