Zcash is a Layer-1 blockchain that functions as "encrypted money," combining Bitcoin's fixed supply with end-to-end privacy. It utilizes a dual-pool architecture that gives users a choice between transparent transactions and a shielded pool, which leverages zero-knowledge cryptography to conceal addresses and amounts.
Zashi makes Zcash private by default for users, delivering a "Venmo-like" mobile wallet that supports retail payments via Flexa and cross-chain swaps via NEAR Intents. Zashi was developed by the Electric Coin Company, the creators of Zcash.
Tachyon is an architectural upgrade that resolves state bloat by shifting to a "stateless" model where wallets carry recursive ZK-proofs of their solvency. It eliminates the need for wallets to scan every transaction to find their own, reducing sync times and allowing the network to prune data for unbounded scalability.
4.8 million ZEC are shielded (29.4% of the circulating supply). Of the three shielded pools, Orchard has the largest share, with 4.2 million ZEC, while Sapling and Sprout hold 635,812 and 25,591 ZEC, respectively.
Governance is shifting toward a coinholder funding model, replacing fixed developer subsidies with opt-in support from ZEC holders. Grants will be funded through voluntary coinholder approvals rather than block-reward allocations.
Introduction
Public blockchains have long been promoted for their transparency. Users can audit transactions, validate asset ownership, and track the flow of funds from the comfort of a block explorer. This has enabled a more accountable and open financial system, but it also conflicts with the cypherpunk values that motivated Bitcoin’s creation, mainly censorship resistance and user privacy. Governments and analytics firms can surveil entities transacting on these blockchains, revealing sensitive information that can be used to target and sanction individuals.
Satoshi recognized the tradeoff in 2010. In a forum discussion, he noted that a privacy-preserving version of Bitcoin would be “much better, easier, [and] more convenient,” but explained that this was impossible within Bitcoin’s design because it requires full visibility to prevent double-spends, and proving that an output had not been spent could not be done privately with the cryptography available at the time.
Zcash was built to close this gap. It maintains the monetary properties that make Bitcoin reliable, such as a fixed supply and Proof-of-Work (PoW), while adding a layer of privacy using zero-knowledge proofs (ZKPs). Users can transact through transparent addresses, which function like Bitcoin and reveal balances onchain, or shielded addresses, which encrypt transaction details while still proving validity. All new ZEC is mined inside a shielded pool rather than as transparent UTXOs, which means the supply begins with a uniform privacy baseline. This preserves the fungibility of shielded ZEC units because units cannot be distinguished by their history, resulting in a public blockchain that retains Bitcoin’s monetary integrity while preserving privacy where users choose to use it.
Background
Work on private digital cash predates Zcash by several years. The first major step was taken by a research group at Johns Hopkins in 2013 with the Zerocoin protocol, developed by Ian Miers, Christina Garman, Matthew Green, and their collaborators.
Zerocoin demonstrated that zero-knowledge proofs could support private transactions on top of Bitcoin; however, the design relied heavily on computations and introduced an inflation risk tied to its accumulator structure. The system could not reliably detect whether a malicious user forged a spend for a coin that had never been minted.
The work did not stop there. Several of the same researchers, joined by cryptographers from MIT and Tel Aviv University, evolved the idea into Zerocash. Zerocash introduced succinct proofs that concealed the sender, receiver, and amount, reduced proof sizes, and enhanced verification. The Zerocash paper, authored by Eli Ben-Sasson, Alessandro Chiesa, Christina Garman, Matthew Green, Ian Miers, Eran Tromer, and Madars Virza, became the core foundation for the Zcash protocol.
Zcash (ZEC) launched on Oct. 28, 2016, with a founding team that included Zooko Wilcox, Daira Emma Hopwood, Sean Bowe, and Jack Grigg, alongside several researchers who worked on the Zerocash paper. The Electric Coin Company (ECC), founded by Wilcox, led protocol development in the early years and remains a core contributor to product and engineering initiatives. In December 2023, Josh Swihart was appointed CEO of the ECC. Under his leadership, the organization pivoted toward user-centric product delivery, most notably through the Zashi wallet, to bridge the gap between complex privacy tech and everyday usability.
The Zcash Foundation, a separate nonprofit created in 2017 by ECC and governed by its own independent board of directors, supports public goods, core infrastructure, and community governance. The Foundation is currently led by Alex Bornstein, who serves as Executive Director. Notable investors in the ECC include Pantera Capital, Winklevoss Capital, and Digital Currency Group.
The Ceremony
Zcash launched via a proving system that required a one-time trusted setup to generate the initial zk-SNARK parameters. The process is analogous to generating a key pair, except that the ceremony secret must be destroyed immediately after it is generated. If the underlying secret were ever known, an attacker could counterfeit ZEC by fabricating zero-knowledge proofs.
To reduce this risk, the team used a multi-party computation (MPC) that distributed responsibility across six independently operated “witnesses.” If a single witness securely destroyed their share of the randomness, the secret could never be reconstructed.
Three witnesses, Andrew Miller, Peter Van Valkenburgh, and Zooko Wilcox, were publicly identified to participants from the start. The remaining three operated under pseudonyms to limit targeted attacks. Their pseudonyms were Moses Spears, Fabrice Renault, and John Dobbertin.
The witnesses, scattered across different locations, operated on brand-new, air-gapped machines purchased exclusively for the ceremony. Radios were physically removed, the machines were never connected to any network, and each participant used a separate Internet-connected network machine to receive messages. Data crossed the air gap using write-once DVD-Rs, creating an immutable audit trail of every message that touched a compute node. This design traded networking risk for a more observable attack surface. Even if an adversary compromised a network machine, any malicious payload delivered through optical media would be permanently recorded.
Over the following days, “Moses Spears” revealed himself as Derek Hinch of NCC Group, whose role included hosting a compute machine in a secure facility and performing real-time and post-hoc forensics to detect potential intrusion attempts. “Fabrice Renault” later revealed himself as Peter Todd, an outspoken critic of trusted setups who joined to scrutinize the process from the inside. The final pseudonym, “John Dobbertin,” remained anonymous until 2022, when he was revealed to be Edward Snowden.
After completing their computations, witnesses were instructed to power down their compute node, ensure their shard of toxic waste was destroyed to prevent any secrets from being recovered, and preserve their DVD-R media for future analysis.
Participants each decided how they would handle disposal efforts. Peter Todd burned his machine with a propane blowtorch and documented the process. Zooko Wilcox and his brother destroyed their hardware in front of journalist Morgan Peck. Peter Van Valkenburgh cut his RAM modules apart with tin snips. Other participants did not publicly document their disposal methods.
While this ceremony was critical at Zcash's inception, cryptographic advancements have since evolved. The network’s most modern shielded pool, Orchard, utilizes the Halo 2 proving system, eliminating the dependency on a trusted setup.
Technology
Architecture
Zcash started as a Bitcoin hard fork, inheriting a similar architecture and codebase, but with the addition of privacy-preserving technology.
Block structure largely follows Bitcoin’s format (with fields like a previous hash, Merkle root of transactions, timestamp, difficulty target, nonce), plus additional fields committing to the state of Zcash’s shielded pools. Each block includes the root of each shielded note commitment tree (for Sapling, Orchard, etc.), which allows light clients and validators to verify shielded state transitions. Blocks in Zcash initially had a target interval of 2.5 minutes (150 seconds), which is four times faster than Bitcoin’s 10-minute block time. In late 2019, the Blossom upgrade halved the target block time to 75 seconds, effectively doubling block frequency. To keep the ZEC emission schedule aligned, Blossom also halved the block reward (twice as many blocks, each with half the reward).
Zcash’s block reward distribution also diverges from Bitcoin’s. Bitcoin sends 100% of each block reward to miners, while Zcash allocates 80% to miners and divides the remaining 20% between two distinct funding streams:
12% of the block subsidy goes to a Coinholder-Controlled “Development Fund”. Previously held in a "Deferred Development Fund," these funds were automatically migrated upon the activation of ZIP 1016.
8% goes to the Zcash Community Grants (ZCG), an independent grants committee that continues to fund external teams and community initiatives with no direct affiliation to the core organizations.
Consensus Mechanism
Zcash uses a memory-hard PoW algorithm called Equihash, originally chosen for ASIC resistance. Blocks are produced by miners solving the Equihash puzzle, and the longest chain rule (most accumulated work) dictates consensus. Zcash inherits Bitcoin’s battle-tested consensus rules for transaction validity.
Bitcoin and Zcash take different approaches to upgrading their networks. Bitcoin developers tend to pursue an ossification model, where changes are rare, leaderless, and strictly backward compatible through soft forks. Anyone can propose improvements, but miners and full nodes must voluntarily align on whether to adopt the change. This maintains the network’s stability but slows the pace of change.
Zcash also accepts community proposals through Zcash Improvement Proposals (ZIPs), but the network follows a coordinated model led by the Electric Coin Company (ECC) and the Zcash Foundation (ZF). Upgrades are planned in advance, activated at predetermined block heights, and require new node software. These Network Upgrades are mandatory for consensus. Users who fail to update continue enforcing the pre-upgrade rules and fall off the main chain, losing access to the network.
To increase decentralization, ECC CEO Josh Swihart proposed a new process that shifts responsibility for protocol changes to the parties implementing them. Under this model, the team driving a change manages the entire lifecycle of the proposal and, once ready, advocates for its inclusion in the next Network Upgrade. If the other repository owners agree and the community consensus is clear, the change is merged. If consensus cannot be reached, the disagreement could lead to a chain fork. This change is not expected to happen before Network Upgrade 7 (NU7).
Transparent vs Shielded Pools
A defining feature of Zcash is its dual-pool system. Transparent addresses start with a “t”, and are commonly referred to as “t-addresses”, whereas shielded addresses start with a “z” and are known as “z-addresses".
A Zcash transaction can involve either pool or even bridge between them. Under the hood, Zcash has multiple shielded pools corresponding to different protocol generations (more on this below). Conceptually, these shielded pools can be seen as a single “shielded pool” versus the transparent pool. Every ZEC resides in either the transparent pool or a shielded pool at any time. Zcash’s transparent transactions function just like Bitcoin’s UTXO transfers.
Funds can be transferred into the shielded pool via a “shielding” transaction or withdrawn via a “deshielding” transaction. When ZEC moves between transparent and shielded pools, the value transferred is revealed onchain. In either direction, the amount of ZEC is visible on the transparent side of the transaction. Purely shielded-to-shielded (“private”) transfers reveal no amount or address information onchain.
Given that shielded transfers don’t reveal transaction details, detecting an inflation bug can be a concern. Zcash solves this with a turnstile mechanism, treating each shielded pool as a single public balance that changes when “deshielding” and “shielding.” Because each pool’s balance must be tracked independently, you cannot move funds directly from one shielded pool to another. Any transfer across shielded pools must first “deshield” and then “shield” into the new shielded pool, allowing the protocol to account for ZEC leaving one shielded pool and entering the other.
Each transaction that interacts with a shielded pool reveals a field called valueBalance. This number is positive when “shielding” and negative when “deshielding”. Zcash nodes sum the ZEC balances of all transactions in a block to compute that block’s net effect on each shielded pool. They then calculate the net change to the historical pool balance. If the result would make the pool’s total negative, the block is invalid because that outcome would imply that more ZEC has been taken out of the pool than has ever been entered into it.
This mechanism doesn’t rely on tracing individual shielded transactions. The details remain private because the zero-knowledge proofs for shielded transactions tie this shielded pool balance to the hidden notes without revealing any transaction details.
Inside each transaction, the prover privately supplies the note values, the new note values, the openings of their commitments, and the secret keys that authorize the spends. The ZKP validates that the hidden inputs are enough to fund the hidden outputs, any transparent outputs, and the miner fee. What the chain sees is only the net valueBalance applied to the pool, a set of new note commitments, and a set of nullifiers for the notes being spent. Nodes verify the ZKP and ensure that no nullifier has appeared before, but they never learn which notes were spent or their values. The network sees only a single public balance for each shielded pool, while the internal details stay protected by commitments and nullifiers. This is how Zcash preserves privacy while still preventing hidden inflation.
Notes, Commitments, and Nullifiers
Shielded transactions in Zcash introduce several new structures not present in Bitcoin, called notes, note commitments, and nullifiers.
A note is conceptually like a UTXO, except it is encrypted. It represents a specific amount of ZEC assigned to a shielded address (or more precisely, to a recipient’s public key). The note’s commitment cm is published onchain (in the encrypted part of a transaction) and acts as a cryptographic fingerprint of the note. The commitment is binding (the sender cannot later change the note’s value or recipient without breaking the commitment) and hiding (an outside observer cannot learn the note’s value or recipient from cm alone). The sender’s wallet constructs the note by first encrypting its plaintext (the amount, recipient address, and some randomness) under a key that only the recipient’s viewing key can reconstruct. It then feeds the same plaintext into a cryptographic commitment function to derive a short onchain identifier, cm. The chain stores only this identifier and the opaque ciphertext, so anyone without the viewing key sees only random-looking data and cannot recover the note’s value or recipient.
All note commitments are inserted into a large Merkle tree (the note commitment tree) maintained by each full node. This tree allows a spender to prove their note exists in the set of all minted notes by providing a Merkle proof, without revealing which note is theirs.
To prevent double-spending of a note (which is encrypted and not publicly linked to an identity), Zcash uses nullifiers. A nullifier is a unique identifier derived from a note and its spending key using a pseudorandom function (PRF) such that nf = PRFnk(p,...) where nk is the spending key and p and other inputs uniquely identify the note. When a note is spent:
Its nullifier (nf) is revealed publicly in the transaction
The ZKP ties nf to some committed note in the Merkle tree, without revealing which commitment it is
Full nodes insert nf into a nullifier set and reject future transactions reusing the same nullifier
The nullifier is designed to look like a random field element; from nf alone, an outside observer cannot recover the note’s value, its commitment, or the owner’s key, assuming the underlying PRF and commitments are secure.
From the user’s perspective, sending a shielded transaction feels no different from a normal one, except that the data is encrypted. For the network, the consensus process involves verifying the ZKPs (for more details, refer to ZK-SNARKs) and subsequently updating both the nullifier set and the note commitment tree.
zk-SNARKs
At the heart of Zcash’s ability to hide transaction details is its use of zero-knowledge proof technology. Specifically, Zcash pioneered the use of zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge) in the crypto industry. In simple terms, a zk-SNARK allows a user to prove to the network that a transaction is valid according to all consensus rules. Specifically, the proof shows that:
The claimed input notes exist in the Merkle tree (the prover knows a valid path to each note’s commitment in the tree)
The prover owns the secret keys to spend those notes
The notes have not been spent before (their nullifiers haven’t appeared)
The sum of input values equals the sum of output values (ensuring no coins are created or lost, excluding fees).
All of this is verified by nodes without learning which notes were spent or how much ZEC was involved. The zero-knowledge proofs used by Zcash are succinct (small and fast to verify) and non-interactive (no back-and-forth communication is required). If the proof checks out, it attests that the hidden transaction data is consistent and legitimate, giving the same assurance as if the data were public.
Viewing Keys and Payment Disclosures
Zcash lets users selectively reveal their own transaction data without exposing their spending keys.
A full viewing key enables a third party, such as an auditor, accountant, or exchange integration, to view all incoming and outgoing transactions associated with a shielded account. It reveals the decrypted note values, memos, and spending flows while preserving spend security. This allows for account-level auditability in a system where the default behavior keeps all transaction details private.
Zcash also supports payment disclosures, which offer a more limited, transaction-specific transparency option. Instead of revealing the entire account history, a user can prove the details of a single shielded transaction to a counterparty or service provider. This is useful for dispute resolution, compliance verification, or support scenarios where only one transaction needs to be explained.
These features ensure that Zcash maintains strong auditability while preserving user privacy.
Evolution of Shielded Pools
Over time, Zcash introduced three shielded pools (Sprout, Sapling, and Orchard), each enhancing performance and security. As of November 2025, 4.8 million ZEC are shielded, accounting for approximately 29.4% of the circulating supply. Orchard makes up the lion’s share of the shielded supply, holding 4.2 million ZEC (25.4% of the circulating supply), followed by Sapling with 635,812 ZEC (3.9% of the circulating supply) and Sprout with 25,591 ZEC (0.2% of the circulating supply).
Sprout (2016–2018)
Sprout, the original shielded pool, was launched with Zcash 1.0 in October 2016. The addresses started with “zc” and leveraged a proving system based on the BCTV14 zk-SNARK construction.
While Sprout successfully demonstrated that JoinSplit circuits could fully hide transaction details on a public ledger, it suffered from severe practicality issues. Generating a proof was computationally exorbitant, requiring gigabytes of RAM and tens of seconds to complete, which made shielded transactions impossible on mobile devices and hindered overall adoption.
In March 2018, a critical vulnerability (CVE-2019-7167) within the original BCTV14 construction was discovered by cryptographer Ariel Gabizon and publicly disclosed in February 2019. The "trusted setup" algorithms inadvertently produced extra "bypass elements" that an attacker could use to forge valid-looking proofs and counterfeit an infinite amount of ZEC. Due to Sprout's privacy properties, this inflation would have been undetectable onchain. This existential risk, combined with the pool's inefficiency, necessitated the creation of a new shielded pool called Sapling.
Realizing the existential severity of the issue, Gabizon immediately coordinated with fellow cryptographer Sean Bowe and CEO Zooko Wilcox. The team faced a critical decision regarding remediation.
Ariel’s Proposal: An emergency hardfork requiring an immediate, public parameter reset.
Sean’s Proposal: A covert inclusion of the fix within the upcoming Sapling network upgrade
The team opted for the covert route to avoid alerting potential attackers. As a first step, CTO Nathan Wilcox deleted the public setup transcript under an operational security cover story to prevent adversaries from analyzing it. The patch was secretly engineered into the Sapling upgrade. Using the new Groth16 proof system, the team provided a secure alternative to the compromised Sprout pool.
The upgrade did not fix the Sprout pool itself. Since the vulnerability was linked to the original setup parameters, Sprout remained permanently vulnerable. To contain this risk, the upgrade introduced a "turnstile" mechanism. If an attacker exploited the vulnerability to counterfeit ZEC, they would be trapped inside the Sprout pool, unable to deshield the counterfeit ZEC or inflate the broader ZEC supply.
As previously discussed, direct transfers between the Sprout and Sapling shielded pools were not possible. To migrate to the Sapling shielded pool, users were required to "deshield" their funds by sending them to a transparent address before re-shielding them in Sapling.
To manage this complex process and minimize the privacy loss associated with revealing funds in the transparent pool, the developers released a dedicated Sprout-to-Sapling migration tool in the zcashd 2.0.5-2 release. This tool automated the migration, moving funds in delayed, discrete amounts to reduce metadata leakage.
The 25,661 ZEC remaining in the Sprout pool is at risk of becoming permanently unavailable, as the software capable of spending them (zcashd) is being deprecated in favor of clients that do not support legacy Sprout proofs.
Sapling (2018–2022)
Using addresses starting with “zs”, the upgrade introduced a radically more efficient cryptographic stack based on Groth16 zk-SNARKs and the BLS12-381 elliptic curve. Inside the circuit, Sapling replaced computationally heavy SHA-256 operations with homomorphic Pedersen commitments over the Jubjub curve; this allowed the protocol to verify that transaction inputs equaled outputs using efficient algebraic addition. The result was a 97% reduction in memory requirements (down to ~40MB) and 81% faster proving time, paving the way for shielded transactions on mobile devices.
To securely generate the parameters for this new Groth16 system, the ZF conducted the "Powers of Tau" ceremony, a massive Multi-Party Computation (MPC) that drastically improved upon the secretive six-person Sprout setup. This open-participation ceremony drew 87 participants, a much larger cohort. Some participants took extreme measures to ensure high-quality randomness for the parameters. Most notably, researcher Andrew Miller’s computation took place aboard a private prop plane flying at 3,000 feet. To ensure his contribution was mathematically impossible to replicate, he harvested randomness by measuring the unpredictable radioactive decay of a piece of graphite from the Chernobyl exclusion zone. By feeding the erratic clicks of the Geiger counter, he seeded the cryptography with physical, natural chaos rather than potentially predictable computer algorithms.
Sapling revolutionized wallet architecture by introducing a hierarchical system of Extended Spending Keys (ZIP 32) that decoupled the authority to spend from the computation of proving. In the Sprout era, the private key was required to perform the memory-intensive proof generation, making hardware wallets (which have negligible RAM) impossible. Sapling solved this by allowing a "Host" device (PC/Phone) to handle the heavy proof generation using public parameters, while the Hardware Wallet retains the isolated spending key to simply sign the final transaction hash.
Orchard (2022-Present)
The Orchard pool was activated in May 2022 as part of Network Upgrade 5 (NU5). Orchard’s big innovation is the use of the Halo 2 proving system, a modern zk-SNARK that doesn’t require a trusted setup. This eliminated the need for Zcash to perform new ceremonies to generate parameters for future shielded pools, including the creation of Orchard.
Halo 2, co-invented by Sean Bowe, Jack Grigg, and Daira Hopwood, is built on efficient polynomial commitment schemes that make zk-SNARKs trustless and capable of recursive proof composition. With Orchard, Zcash not only removed the lingering trust assumptions but also opened the door to scalability through recursive proofs. Theoretically, one proof can verify another proof, which can verify another, and so on. In the long run, this opens the door for Zcash to bundle many transactions into a single proof and potentially scale to much higher throughput.
Orchard replaces Sapling’s separate Spend and Output descriptions with a unified structure called an Action. Each Action can represent a spend, an output, or both, but onchain they appear identical. This reduces metadata leakage because observers can no longer track the number of inputs and outputs.
Unified Addresses were introduced with the pool. A Unified Address is a single string that contains multiple receivers: Orchard, Sapling, and transparent. Wallets pick the best receiver automatically. If both parties support Orchard, funds route into the Orchard shielded pool without the user needing to consider address formats. Unified Addresses eliminate the fragmentation between t-addrs and z-addrs, enabling features like auto-shielding.
Governance and Funding
While Bitcoin’s governance model is designed to maximize ossification (making the protocol nearly impossible to change to preserve stability), Zcash’s governance is designed to maximize agility (enabling the protocol to safely evolve with cryptographic breakthroughs like Halo 2 and Orchard).
This system operates through a rigorous legislative process centered on Zcash Improvement Proposals (ZIPs), which ultimately lead to voluntary adoption by the network's miners.
The ZIP Lifecycle
Every change to the Zcash protocol, whether a minor bug fix or a massive privacy overhaul, begins as a Zcash Improvement Proposal (ZIP). Defined in ZIP 0, this is the formal standard for proposing changes to the client software or protocol rules. Changes to the ZIP process are executed solely at the discretion of the ZIP Editors (representatives from ECC, ZF, and Shielded Labs) and ratified via voluntary adoption by Node Operators. Anyone can draft a ZIP. The author (ZIP Owner) is responsible for championing the idea, writing the technical specifications, and managing the public debate to build "rough consensus" within the community.
Before a proposal can be considered, it must pass through the ZIP Editors. The editors play a vital role as a "sanity check". Editors do not decide if a feature is desirable, but rather if the proposal is sound, complete, and unambiguous. The current editor board includes:
The ZIP Editor board is not democratically elected by the public or coin-holders. Instead, it operates as a self-selecting body. New editors are appointed by consensus among the current editors, provided the candidate consents to the role. To ensure a balance of power, ZIP 0 mandates that the board must always include at least one representative from the Electric Coin Company and one from the Zcash Foundation.
Once approved by editors, a ZIP moves to "Proposed" status. This means the specification is ready for implementation, but it is not yet in effect. A ZIP does not become active simply because it is "Proposed." It must be selected for a Network Upgrade (NU). Decision-making power effectively concentrates among the engineering teams that maintain the full node software, specifically the ECC (Zcashd) and ZF (Zebra). These teams negotiate a bundle of "Proposed" ZIPs to include in the next scheduled hard fork (e.g., NU6, NU7).
This negotiation takes place primarily during Arborist Calls, public, bi-weekly technical meetings where protocol engineers review the backlog of active ZIPs. The decision-making here is driven by engineering feasibility rather than simple voting. Because a safe hard fork requires all mainnet nodes to upgrade simultaneously, the process effectively operates on unanimous consent among implementers. If the node developers refuse to implement a ZIP due to security risks, resource constraints, or misalignment, that ZIP effectively comes to a standstill. This establishes the ECC and ZF as stewards of the roadmap.
The final step of governance is voluntary ratification. Zcash upgrades via coordinated hard forks. When the developers release the new software, it comes with an "activation height" (a specific block number) where the new rules take effect. Miners and node operators "vote" with their hardware by choosing to download and run the new release. If the community strongly disagreed with the developers' direction (e.g., if an upgrade compromised the supply cap), they could refuse to upgrade. This would either stall the new features or fork the network. To date, the social contract has remained intact, and miners have consistently endorsed the technical roadmap proposed by the developers.
The Zcash Trademark
When the Electric Coin Company (ECC) donated the Zcash trademark to the Zcash Foundation in 2019, it established a "2-of-2" agreement with the primary goal of protecting users from scams and impersonators. To ensure neither the ECC nor ZF could hijack the real network, the agreement required both parties to agree on any Network Upgrade for it to bear the Zcash name.
While effective at stopping scams, this accidentally created a governance veto. Because the trademark legally defined what "Zcash" was, no upgrade could happen unless these two specific organizations agreed. If a massive majority of the community wanted an upgrade, but one organization disagreed, that organization could legally block the network from evolving by withholding the name. The trademark had effectively become a centralized kill switch.
In 2024, ECC terminated the agreement to ensure governance transcends the two entities, leaving the Foundation as the sole steward. In February 2025, the Foundation adopted a new policy that separates scam prevention from governance. The Foundation will not use the trademark to police legitimate governance disputes. If a dissenting group creates a non-deceptive fork (e.g., "Zcash Classic"), the Foundation will not sue them, ensuring the trademark defends users.
Funding Streams
Zcash funding has undergone a structural shift in funding development. For its first eight years, the network operated under a "Direct Funding" model, where 20% of the block rewards were automatically distributed to specific organizations (ECC, ZF, and ZCG). As of Network Upgrade 6 (NU6) in November 2024, this model ended.
In the new model, 8% continues to fund independent grants and development via the ZCG, and 12% is set to accrue in a coinholder-controlled development fund, referred to as a “Lockbox”. This new model is designed to strip special privileges from the founding entities, ECC and the ZF, and move toward a competitive, community-driven process.
Coinholder Polling
To operationalize the "Lockbox" funding described in the previous section, Zcash has shifted to a more direct, permissionless model known as Coinholder Polling. This gives ZEC holders a direct voice in how treasury funds should be allocated and which ZIPs should be prioritized.
While these polls are technically non-binding (miners ultimately decide which software to run), the ecosystem’s core entities have committed to treating them as socially binding.
“We deeply respect the voice of the Zcash community and are fully committed to upholding its collective decision even if it diverges from our Board's recommendation.” — Zcash Foundation Board Statement (May 2025)
Lockbox Funding
In a landmark poll conducted in May 2025 to determine the fate of the Lockbox funds, the community overwhelmingly rejected returning the funds to miners. The "Community & Coinholder" model received 801,962 ZEC in support (87.5% of participating ZEC), establishing a clear mandate to create a Coinholder-Controlled Lockbox.
Under this model, 12% of block rewards accruing in the Lockbox are governed directly by coinholder votes. To prevent spam or manipulation, disbursing a grant requires a rigorous quorum of 420,000 ZEC and a simple majority.
Following the Retroactive Grants Poll in November 2025, the mechanism has moved from ratification into active allocation, deciding payouts for completed Q4 2025 projects and establishing the rules for future treasury distributions.
Sentiment Polling
Beyond funding, Zcash utilizes coin-weighted polls to assess community and coinholder sentiment for adding new features to the protocol. These polls serve as a vital tool for node developers and ZIP editors, allowing them to align development roadmaps with ecosystem priorities before committing to a Network Upgrade (NU). The next sentiment poll is scheduled for January 2026. This poll serves as a "temperature check" to inform core contributors, including the ECC and the ZF, on which features to prioritize for inclusion in Network Upgrade 7 (NU7) or subsequent releases.
The deadline to submit a ZIP for the January round is Jan. 16, 2026. Eligible participants include ZEC holders, the Zcash Community Advisory Panel (ZCAP), the Zcash Ad Hoc Caucus (ZAC), and ZecHub. While these results provide a mandate for the community's direction, all features must still meet the requirements for activation outlined later in the “Network Upgrades” section.
Core Entities
Electric Coin Company
The Electric Coin Company (ECC) is the original engineering team behind Zcash and acts as the network's primary product lab. It is currently led by CEO Josh Swihart. While it was once a for-profit startup with venture backing, it is now a wholly owned subsidiary of the Bootstrap Project, a 501(c)(3) nonprofit dedicated to financial privacy. Bootstrap Project is governed by a board of directors consisting of:
This structure allows ECC to focus on protocol R&D and public good infrastructure rather than maximizing shareholder profit.
For most of Zcash’s history, ECC maintained zcashd, the primary full node software that powered the network. However, as of late 2025, ECC is actively deprecating zcashd, transitioning its engineering focus toward the mobile-first stack, specifically the Zashi wallet and the underlying SDKs that power third-party wallets. By retiring zcashd in favor of the Zcash Foundation’s Zebra node and the new Zallet backend, ECC is reducing redundancy to focus entirely on user experience and mobile adoption.
Beyond R&D, ECC functions as the primary marketing and communications engine for the ecosystem. The company manages the z.cash website and the official Zcash X account, using these platforms to drive outreach campaigns and coordinate partnerships with exchanges, custodians, and hardware wallet providers (i.e., Keystone).
Zcash Foundation
The Zcash Foundation (ZF) is a 501(c)(3) public charity dedicated to building financial privacy infrastructure for the public good. It is governed by a six-member board of directors (five independent directors plus the Executive Director), which is self-electing but takes advisory input from the Zcash Community Advisory Panel (ZCAP) when adding or renewing board members. As of November 2025, the board includes:
ZF builds and maintains Zebra, an independent full-node implementation written in Rust. Client diversity ensures the network can continue to operate even if a bug is found within a single client implementation. With zcashd being deprecated in 2025, zebrad acts as the network's primary consensus engine.
Distinct from the grants issued by ZCG, the Foundation runs a "Minor Grants" program from its own operating budget. These are smaller, high-velocity grants (typically under $25,000) designed for niche research, educational initiatives, or experimental tooling that might be too small or speculative for the main grants process.
Tachyon
Tachyon is a specialized engineering unit dedicated to the long-term scalability of Zcash. The team’s core mission is to implement the most advanced architectural upgrade in the protocol’s history. This upgrade aims to transition Zcash toward "planetary scale" by leveraging recursive ZK proofs and streamlined data transmission.
The team is led by Sean Bowe, one of the industry’s most respected cryptographers, and is comprised of top-tier talent, including:
According to Mert Mumtaz, Tachyon will be community-funded entirely. This model ensures that the team’s incentives are aligned with the long-term interests of the community.
Shielded Labs
Shielded Labs is a Swiss-based nonprofit organization established to decentralize Zcash governance and accelerate independently funded research. It serves as a distinct counterweight to the core US-based entities (ECC and ZF), bringing both geographic and financial independence to the network's power structure.
The team is currently spearheading the research and implementation of Crosslink, a proposed hybrid consensus mechanism that blends PoW with PoS finality to secure the network, and the Network Sustainability Mechanism (NSM), which is designed to secure the protocol’s long-term economics. Beyond R&D, Shielded Labs engineers now serve as ZIP Editors alongside ECC and ZF, ensuring that the critical role for network upgrades is shared among three independent organizations, rather than two.
Shielded Labs is funded entirely by donations. This funding model positions it as a pillar of independent governance and research.
Zcash Community Grants
ZCG functions as a community-elected committee with a mandate to allocate 8% of the block rewards it receives to independent contributors. Its goal is to diversify the development landscape by funding teams outside the ECC and ZF, ensuring that the network is not reliant solely on its founders for growth.
ZCG is a representative body consisting of five members elected directly by the community through governance polls. These members serve fixed one-year terms and act as fiduciaries for the protocol. To ensure transparency, they operate in the public eye, publishing meeting minutes, conducting open review sessions, and engaging directly with applicants on the Zcash Community Forum.
ZCG enforces milestone-based accountability. The committee releases ZEC in tranches only after specific deliverables, such as code completion, audit reports, or educational content, are verified. This allows ZCG to fund high-impact external infrastructure while maintaining the financial discipline necessary to protect the network's treasury.
Network Upgrades
Zcash was designed to be upgradable. Unlike Bitcoin’s slow, consensus-by-ossification approach, Zcash has executed a series of Network Upgrades (NUs) at regular intervals to introduce new features and improve the protocol. These are effectively planned hard forks activated by block height, requiring node consensus to switch over.
Under Zcash’s governance model, a feature must pass three distinct hurdles to be included in a network upgrade:
Legislative Approval: The proposal must be ratified as a "Proposed" ZIP by the editors from ECC, ZF, and Shielded Labs.
Client Implementation: The engineering teams maintaining the full node software (Electric Coin Company for zcashd and Zcash Foundation for Zebra) must voluntarily agree to merge the code.
Network Activation: Once the code is released, a critical mass of miners, exchanges, and node operators must adopt the new software before a specific block height. If a significant portion of the community disagrees with the change and refuses to upgrade, the network may fork into two separate blockchains.
Aside from shielded pool activations, past upgrades include:
Overwinter (June 2018): The first network upgrade, mainly a preparatory release to enable future upgrades smoothly. Overwinter added transaction versioning, allowing nodes to determine which rules apply to a transaction, and ensured that transactions created before an upgrade couldn’t be mistakenly accepted after it. This created clean boundaries between protocol eras, allowing Sapling to activate safely.
Blossom (December 2019): This reduced block time from 150 seconds to 75 seconds and adjusted block rewards accordingly. It was aimed at improving user experience (faster confirmations) without inflating supply. Governance-wise, Blossom was non-controversial but required careful handling of the emission curve; it delivered the same 4-year halving cycle but with more blocks of smaller rewards.
Heartwood (July 2020): Miners gained the ability to mine rewards directly to a shielded address. Before Heartwood, coinbase outputs had to be transparent. This improved miner privacy and decentralization because miners could immediately shield their income.
ZIP-221 made it easier for light clients to verify that blocks are part of the chain using small, efficient proofs instead of downloading large amounts of data.
Canopy (November 2020): Canopy coincided with the first Zcash halving. The upgrade marked the end of the original Founders’ Reward and introduced a new four-year Development Fund. The new allocation directs 80% of the block reward to miners, with the remaining 20% split between Zcash Community Grants (8%), Electric Coin Company (7%), and the Zcash Foundation (5%).
ZIP 1014 established the framework for the Development Fund, allocating 20% of the block subsidy to the ECC, ZF, and ZCG for a period of four years.
ZIP 207 established a mechanism for funding streams sourced from a portion of the block subsidy.
ZIP 211 disabled the ability to add new value to the Sprout pool, which moved Zcash closer to deprecating Sprout.
ZIP 212 introduced a new Sapling note plaintext format to strengthen the privacy properties of diversified addresses. ZIP 215 tightened Ed25519 signature validity rules in Sprout transactions to allow correct batch verification.
ZIP 214 defined the consensus rules that implement the new Development Fund structure. Together, they formalized the community’s decision to continue protocol funding for another four years. To ensure funding would continue beyond its November 2024 expiration, the community needed to propose an extension in a future network upgrade.
NU6 (November 2024): NU6 activated shortly after the 2024 halving. It extended the Development Fund for one additional year. The allocation continues to direct 8% of the block subsidy to Zcash Community Grants and 12% to a protocol-owned lockbox.
ZIP 236 introduced a consensus rule requiring coinbase transactions to collect the full miner subsidy and fees, removing edge cases where blocks could include incomplete subsidies.
NU6.1 (November 2025): This upgrade introduced a Community and Coinholder funding model (C&C).
ZIP 1016 preserved the 8% allocation for Zcash Community Grants and directed the remaining 12% of the subsidy to a protocol-controlled lockbox. This fund is seeded by the lockbox created in NU6. ZEC holders collectively decide whether to distribute these funds to ecosystem contributors or leave them untouched, giving coinholders the ability to determine how development is funded until the third halving in late 2028, after which the model will be reevaluated.
ZEC Tokenomics
ZEC functions as a store of value with a hard-capped supply of 21,000,000 ZEC, mathematically identical to Bitcoin’s maximum supply. The issuance model is governed by a halving-based decay function, ensuring that block rewards permanently decrease by half every four years.
Block Times
Unlike Bitcoin’s 10-minute block targets, Zcash maintains a faster 75-second block time. To align with Bitcoin's emission curve, despite the faster block times, the block reward is calibrated to release the same aggregate amount over the same four-year epochs.
Block Rewards
The distribution of the block reward underwent a significant structural shift to ensure sustainable ecosystem funding while maintaining miner incentives. The 1.5625 ZEC block reward is currently allocated as follows:
Miners receive 80% of the block reward to secure the network and process blocks
A “Coinholder-controlled Lockbox” accrues 12% of the block reward to fund future development initiatives
The 12% lockbox relies on a Community & Coinholder model to determine allocation, giving ZEC holders decision-making responsibilities for the reserve. This reserve allows the protocol to capture value for future development without immediately diluting holders for unallocated spending. The community must pass a future ZIP to specify how these funds are unlocked and utilized.
Fees
Zcash employs a minimum fee of 0.0001 ZEC (1,000 zatoshis). Fees are proportionally calculated based on transaction complexity, per ZIP 317. The rationale was that the original fixed fee allowed high-output transactions (e.g., those with 1,100 outputs) to pay the same minimal fee as simple 2-output transactions. The new mechanism aligns the fees with the computational resources consumed by the network.
Inflation
Ecosystem
While the Zcash blockchain provides a strong foundation for onchain privacy, ecosystem initiatives and partnerships such as the Zashi mobile wallet and NEAR Intents integration bolster the utility and adoption of the chain.
Zashi Wallet
Zashi is a core wallet built by ECC, the same team behind Zcash. The app is designed to enable people to hold, send, and spend ZEC in a way that keeps balances and transaction history private, while reducing friction for users new to crypto. The wallet is shielded by default, so users don’t have to understand address types or privacy settings. Every transaction and balance is private out of the box.
The wallet offers fast sync, a clean mobile interface, and smooth onboarding, so users don’t need to rely on a centralized exchange or manage multiple wallets to get started.
Zashi also expands what people can do with shielded ZEC. The app recently introduced private swaps that convert assets like Bitcoin, ETH, or stablecoins directly into shielded ZEC in one step, along with decentralized off-ramps that let users move back out into any NEAR-supported asset (BTC, ETH, etc.). CrossPay enables private cross-chain payments, allowing users to payout shielded ZEC while the recipient receives any NEAR-supported asset such as USDC.
Support for the Tor client enhanced network-level privacy, and the Flexa integration enabled retail payments for thousands of merchants.
ECC continues to push Zashi toward a full-featured private payments wallet. Upcoming enhancements include ephemeral transparent addresses and the automatic rotation of transparent addresses to reduce linkability.
NEAR Intents
NEAR Intents extends Zcash’s functionality by providing a decentralized execution layer for cross-chain transactions. Instead of relying on centralized exchanges or custodial bridges, users can route swaps, payments, and on/off-ramp funds through intent-based settlement on NEAR. An “intent” is a signed message that specifies what a user wants to accomplish, for example, converting BTC into shielded ZEC. Solvers compete to fulfill these intents, delivering the outcome on Zcash while handling the cross-chain mechanics under the hood.
The integration gives ZEC cross-chain functionality without exposing user metadata or requiring trusted intermediaries. Zashi swaps, off-ramps, and CrossPay all rely on this infrastructure.
Roadmap
The Zcash roadmap aims to enhance the network’s utility, security, and scalability over time through network upgrades.
While the Zcash roadmap includes several proposals, their path to mainnet activation varies significantly based on technical readiness, developer resources, and community consensus. Tachyon represents the core path toward scaling Zcash with the most concentrated community support. In contrast, Zcash Shielded Assets (ZSAs) and Crosslink, while technically significant, currently lack the "Client Implementation" consensus required for near-term deployment after receiving pushback from the ECC.
Tachyon and the Net Sustainability Mechanism (NSM) are slated for implementation barring unforeseen circumstances. ZSAs and Crosslink lack the community consensus and developer backing required for implementation, leaving them effectively sidelined to-date in favor of other roadmap priorities.
Tachyon
The current Zcash architecture places an unsustainable burden on both users and validators. To prevent double-spending without revealing values, nodes maintain a list of nullifiers for every spent note. Under the current architecture, this list is append-only and grows indefinitely. To verify any new transaction, a validator must check against every nullifier created since the genesis block. This creates a state bloat problem where the cost of running a node increases linearly with the chain’s history. Eventually, the hardware requirements become exclusionary, forcing centralization and placing a hard ceiling on the network's throughput.
For users, the friction is bandwidth. Because the blockchain acts as the primary communication channel, a user’s wallet must download the chain's headers and attempt to decrypt every transaction to see if it belongs to them. This "trial decryption," effectively forces a mobile phone to process the global blockchain to update a local balance. As transaction volume grows, mobile synchronization becomes prohibitively slow and data-intensive.
Tachyon is Sean Bowe’s next-generation architecture that aims to resolve these constraints using recursive zero-knowledge proofs to invert the relationship between the user and the network. It addresses the two bottlenecks above by introducing Oblivious Synchronization and Offchain Data Transmission. Sean has been instrumental in upgrading shielded pools such as Sapling and Orchard and has shifted his focus towards long-term scalability.
“We can have the best of both worlds — a private digital payment network that scales to billions of users — by fully leveraging both zero-knowledge and verifiable computation.” — Sean Bowe, “Tachyon: Scaling Zcash with Oblivious Synchronization” (April 2025)
By leveraging Proof-Carrying Data, the user’s wallet maintains a recursive proof of its own solvency. When a user spends funds, they provide a proof that verifies:
They possess a valid note
The note has not been spent within a specific recent timeframe
This proof is verified against a small, rotating window of blocks. This innovative approach allows validators to discard nearly all historical data. The network effectively prunes itself constantly and maintains a small, fixed state size, regardless of how long the blockchain runs for.
Tachyon resolves the bandwidth issue by relocating the transmission of secret note data entirely offchain. Senders transmit encrypted notes directly to recipients through private, offchain channels, such as messaging apps or dedicated transfer services. The wallet no longer needs to scan the blockchain to find incoming funds. It receives the data instantly offchain, and simply checks the blockchain to confirm the mathematical proof of settlement. This reduces wallet synchronization times from minutes to milliseconds.
Quantum Defense
Shifting to out-of-band payments creates an immediate defense against common quantum privacy threats. The removal of onchain ciphertexts neutralizes the risk of harvest-and-decrypt-later attacks because there is no encrypted data left on the public blockchain to be harvested. This ensures user privacy remains secure even against future adversaries with powerful quantum computers. The modular design also facilitates a smooth transition to post-quantum cryptography in the future, ensuring the long-term integrity of the monetary supply.
Bowe and his team aim to implement these changes to mainnet within the next year. Tachyon represents a "0-to-1" upgrade for the privacy sector. By decoupling the security of the network from the storage of its history, it solves the fundamental bottleneck caused by the rising marginal cost of verification. If successfully implemented, Tachyon would transform Zcash into the first privacy-preserving L1 blockchain capable of unbounded scale, supporting global transaction volumes without requiring exponential growth in hardware.
The Network Sustainability Mechanism (NSM) is a proposed upgrade led by Shielded Labs to modernize Zcash’s issuance and fee mechanics. It aims to secure the network's long-term security budget and is defined by three interrelated ZIPs:
ZIP 233 (Burning): Formalizes a mechanism to remove ZEC from circulation (burning) via voluntary contributions or protocol fees.
ZIP 234 (Smoothing): Introduces an issuance smoothing curve. Instead of relying solely on block rewards that halve every four years, this mechanism reissues burned ZEC over time, stabilizing miner revenue and extending emissions.
ZIP 235 (Fee Burning): Proposes burning 60% of all transaction fees to introduce deflationary pressure during periods of high network usage.
The primary driver for the NSM is to address the "security budget" problem, a long-term existential risk that Bitcoin faces. As block rewards decline due to halvings, network security depends increasingly on transaction fees. By burning fees and recycling them through smoothing, the NSM attempts to create a sustainable economic loop similar to Ethereum’s EIP-1559, but adapted for a fixed-supply privacy coin.
Zcash Shielded Assets (ZSAs)
ZEC is currently the only asset users can transact with on the network. To address this, the ECC explored a multi-asset design known as Zcash Shielded Assets (ZSAs). ZSAs are designed to function as custom tokens (e.g., stablecoins) within the Orchard shielded pool, granting them the same privacy properties as ZEC while requiring transaction fees to be paid in ZEC.
All ZSA activity is shielded, and while supply is public, balances and flows are not. Fees are paid in ZEC. The design and implementation efforts have been led by QEDIT, with two ZIPs that define the scope of this upgrade:
ZIP 226 (Transfers & Burns): Extends Orchard to support multi-asset notes and enforces per-asset conservation and burn rules.
ZIP 227 (Issuance): Provides issuer-side controls via an issuance key pair and maintains a transparent issuance map, allowing the network to track the circulating supply.
Both ZIPs are audited, live on testnet, and candidates for inclusion in the next major network upgrade (NU7). Implementation remains uncertain due to community debate and resource constraints. Community members and ECC leadership argue that ZSAs introduce unnecessary complexity that distracts from ZEC’s core value proposition as a private form of money. The most immediate blocker however, is a technical dependency. The ZF cannot merge the feature into Zebra until ECC updates the shared cryptography libraries (e.g., librustzcash). Because ECC is focused on zcashd deprecation, they lack the resources to review QEDIT’s upstream code. This dependency leaves ZSAs unsupported on both full node implementations, stalling its potential deployment.
Crosslink
Crosslink is a proposed consensus upgrade developed by Shielded Labs, which layers a Proof-of-Stake (PoS) finality layer on top of the existing Proof-of-Work (PoW) chain. The aim is to maintain PoW’s sybil resistance and miner-driven block production while introducing fast economic finality, staking yield, and a defined role for long-term ZEC holders, without compromising privacy. In this model, a network of "finalizers" observes the chain and locks blocks, rendering them economically irreversible to prevent deep reorganizations.
Crosslink is designed to uphold Zcash’s privacy standards; staking occurs entirely within the Orchard shielded pool using "quantized" stake amounts (generic buckets of 1, 10, or 100 ZEC). This ensures that while the total network stake is transparent, individual balances and delegators cannot be tracked via "digital fingerprints" or specific stake sizes. By targeting a roughly 40/40 issuance split between miners and stakers, the upgrade aims to transition ZEC into a productive asset with native yield while improving settlement guarantees for exchanges and bridges.
Crosslink faces a similarly contentious path, mirroring the debate surrounding ZSAs. While proponents argue that it is necessary for long-term stability and security, the move away from pure PoW has received pushback from high-profile community voices, including Josh Swihart (CEO of ECC) and Mert Mumtaz. These individuals expressed concerns regarding the complexity of the upgrade, its actual necessity, and the potential for introducing new risks.
Crosslink’s R&D is progressing through five milestones. With PoW and BFT finality already integrated, the project is currently in Milestone 4, developing the staking and tokenomics required for end-to-end operation. Hardening is slated for 2026, followed by a productionization phase to finalize ZIPs and complete security audits. Mainnet inclusion is not guaranteed; these steps are intended to prepare the protocol so it can be formally proposed for a future network upgrade, pending community approval and successful security audits.
Closing Summary
Zcash is a Layer-1 blockchain that combines the scarcity of Bitcoin with the privacy of physical cash. Unlike Bitcoin, which exposes your transaction history to the world, Zcash leverages zero-knowledge proofs to cryptographically verify transactions without revealing the sender, receiver, or amount.
By pioneering the trustless "Halo 2" proving system and productizing it through the Zashi wallet, Zcash has established itself as the largest privacy network by fully diluted valuation. Its compliance-friendly nature positions Zcash as a bridge between mainstream adoption and cypherpunk ideals.
The pivotal May 2025 coinholder poll effectively democratized the protocol, shifting funding power directly into the hands of ZEC holders and empowering independent entities. With a strong technical moat and leading market position, Zcash is the industry standard for scalable, unstoppable private money.
This report was commissioned by a member of the Zcash community. All content was produced independently by the author(s) and does not necessarily reflect the opinions of Messari, Inc. or the organization that requested the report. The commissioning organization may have input on the content of the report, but Messari maintains editorial control over the final report to retain data accuracy and objectivity. Author(s) may hold cryptocurrencies named in this report. This report is meant for informational purposes only. It is not meant to serve as investment advice. You should conduct your own research and consult an independent financial, tax, or legal advisor before making any investment decisions. Past performance of any asset is not indicative of future results. Please see our Terms of Service for more information.
No part of this report may be (a) copied, photocopied, duplicated in any form by any means or (b) redistributed without the prior written consent of Messari®.
Youssef is a Research Analyst on the Protocol Research team. Prior to joining Messari, Youssef was a Product Analyst at Fidelity Digital Assets. Youssef graduated from Northeastern University, where he led the Northeastern Blockchain club as President.
Youssef is a Research Analyst on the Protocol Research team. Prior to joining Messari, Youssef was a Product Analyst at Fidelity Digital Assets. Youssef graduated from Northeastern University, where he led the Northeastern Blockchain club as President.