A major one,
there is no set framework to adopt protocol changes/upgrades.
It's done completely on "community feedback", so if you one day oppose a change you can only do so with words - there's no consensus level mechanism that can be used.
Another major issue,
Instead of developing a good privacy protocol from the root of your self custodian, self banked system, you're relying on Monero, which can have bugs and overtime, youre relying on devs & researchers to be ahead of schedule to maintain your privacy.
If you're using Monero, and want full privacy, if you don't go through the entire process of shielding your identity - you're fooling yourself & taking unnecessary risk.
