Pulse ReportsPrivacyLayer-1

Zcash: Building Encrypted Money at Planetary Scale

Key Insights

  • Cryptomoney adoption has stalled over the past two years despite a favorable macro backdrop, suggesting that internal structural limitations, not a lack of demand, are the primary constraint on growth.
  • For crypto to achieve meaningful scale, it must address three core challenges: privacy, scalability, and quantum resistance. Failure to solve any one of these undermines its ability to function as durable money.
  • Zcash is the furthest along of any blockchain actively addressing all three challenges, with native privacy today and a clear roadmap, including Tachyon and Orchard Quantum Recoverability, to improve scalability and quantum resilience.
  • As quantum timelines accelerate, the risk of a cryptographic break becomes increasingly real, making preparation essential. Systems without a credible path to upgrade or recover face potential loss of funds and a breakdown in trust.
  • In a scenario where capital begins to diversify away from Bitcoin due to its limitations around privacy, scalability, and quantum resistance, a portion is likely to reallocate toward alternative forms of crypto, with ZEC well-positioned to benefit.

Introduction

It is no secret that the biggest trend over the past few months has been the institutionalization of crypto. From trillion-dollar asset managers deploying onchain products to S&P 500 companies launching their own blockchains, the convergence of blockchain technology and TradFi is undoubtedly underway. The risk, however, is that in the process, the industry loses sight of its core value proposition: money.

Satoshi didn’t create Bitcoin to improve backend infrastructure for the existing financial system, but to build a new one. At its core, crypto was designed to give people an alternative to fiat: a way to store, transfer, and own value outside the state's control. The measure of success, then, is not how many institutions adopt blockchain infrastructure, but how much capital is allocated to cryptomoney. Under this lens, the industry is failing short of its original purpose.

As of April 8, 2026, the combined market cap of the top ten monetary crypto assets stands at $1.89 trillion, compared to $2.04 trillion two years prior. In other words, there has been negligible growth over the past two years. This is particularly notable given what’s happened in traditional stores of value (SoVs) over the same period. Gold’s market cap increased by 116%, rising from $15.10 trillion to $32.60 trillion.

Global capital is clearly moving into traditional SoVs, not crypto. This raises a more fundamental question: is this simply part of crypto’s cyclical nature, or are there structural challenges preventing crypto from achieving broader adoption as a store of value? If it’s the latter, we believe there are three primary challenges preventing crypto from achieving broader adoption: privacy, scalability, and quantum resistance.

Three Challenges for Crypto: Privacy, Scalability, & Quantum

Privacy

Of the three challenges, privacy is unique in that a complete solution already exists at the protocol level today. Private crypto has been permissionlessly accessible for over a decade through Zcash (launched in 2016) and Monero (launched in 2014). Of note, the two blockchains achieve privacy through different means. Zcash uses zero-knowledge proofs (zk-SNARKs) to enable shielded transactions, where transaction data is encrypted onchain and validated without revealing underlying details. This design allows for confidential value transfer while maintaining verifiability, making encryption a core component of Zcash’s privacy model. Monero, on the other hand, uses obfuscation techniques such as ring signatures and stealth addresses, which provide probabilistic privacy by mixing transactions within a set of decoys. As a result, the privacy challenge in crypto is not one of technical invention, but of adoption. Private crypto already exists; it just hasn’t been as widely used as non-private forms of crypto. However, that is now starting to change.

At the start of 2025, ZEC as a percentage of BTC’s market cap stood at 0.05%, near historical lows. In October, ZEC began to reprice against BTC, ultimately reaching 0.64% in November. As of writing, ZEC stands at 0.37% of BTC’s market cap, up over 900% year-over-year. XMR also experienced a slight repricing, increasing from 0.24% to 0.44% of BTC’s market cap (+86% YoY).

Although ZEC and XMR combined still represent less than 1% of BTC’s market cap, their price movements in 2025 suggest that market participants are beginning to rethink how they allocate between private and public forms of crypto. Specifically, the market has started to price in the possibility that privacy is not just an ideological preference, but a core monetary property.

While privacy has long been central to the cypherpunk ethos that gave rise to crypto, it has not been treated that way in practice. The vast majority of capital (>99%) remains allocated to transparent assets such as BTC, ETH, and XRP. For early adopters, privacy was at best a nice-to-have, not a requirement.

The open question is whether that holds for the next wave of adoption. If privacy becomes a must-have rather than a preference, then most existing crypto is fundamentally misaligned with that demand. In that scenario, privacy-focused assets such as ZEC and XMR are uniquely positioned, while broader adoption of crypto may remain constrained until more robust privacy solutions emerge, if ever.

Scalability

One of the oldest challenges for crypto has been scalability, so much so that it is one of the core components of the “blockchain trilemma,” which consists of scalability, security, and decentralization. Over the years, Proof-of-Stake (PoS) blockchains have become progressively more scalable, but the same cannot be said for most Proof-of-Work blockchains.

Bitcoin, for example, has achieved roughly 13.2 transactions per second (TPS) under peak conditions. To put that into perspective, if every single human being wanted to send one transaction, it would take roughly 19.5 years for Bitcoin to process them all (and that assumes it could sustain peak throughput, which it cannot).

Zcash is in a similar position. While it can theoretically process more than one transaction per second (depending on transaction type), in practice, the network operates far below its capacity, often processing fewer than one transaction per second. Like Bitcoin, it remains constrained to throughput in the low tens of transactions per second at the base layer.

At these throughput levels, mass global adoption of Bitcoin or Zcash is not possible without relying on offchain intermediaries. That, however, defeats the purpose of crypto. If a PoW money is to achieve a planetary scale, it needs orders of magnitude more throughput.

Quantum

The final challenge is quantum resistance. Unlike scalability, which is a question of performance, or privacy, which is a question of adoption, quantum computing poses an existential risk to crypto itself.

Today, most crypto relies on elliptic curve cryptography to secure user funds. If sufficiently powerful quantum computers are developed, they would be able to break these schemes, allowing an attacker to derive private keys from public keys and seize funds. In that scenario, ownership would no longer be secure, and the foundational assumption behind crypto, self-custody, would collapse.

While quantum has long been theorized as a threat to crypto, the threat has always been exactly that: theoretical. There are strong reasons to believe that the quantum threat will become “practical” relatively soon. For example, Google is now implementing a 2029 timeline to transition to post-quantum cryptography (PQC). Due to both (1) the technical lift required to transition a blockchain to PQC and (2) the ever-changing timelines associated with Q-Day (the point at which quantum computers become powerful enough to break widely used cryptographic systems), crypto needs to begin preparing for a post-quantum world today. Any system that cannot make this transition will not survive as a long-term money.

How Zcash Becomes Encrypted Money at Planetary Scale

Long-term success in money may be determined by whether an asset can solve three core constraints: privacy, scalability, and quantum resistance. If it fails on any one of these, it may be detrimental to an asset’s monetary premium.

Zcash is uniquely positioned as it meaningfully addresses all three. It already delivers native privacy, and its roadmap focuses on scaling the network and transitioning to quantum-resistant cryptography. Equally important is that ZEC holders are aligned with this direction.

Earlier this year, ZEC holders participated in a sentiment poll for Network Upgrade 7 (NU7), with the purpose of signaling support for which features should be included in the next network upgrade. Eleven features were polled, and the only two to receive overwhelming support (>90%) was Tachyon and Orchard Quantum Recoverability, both of which directly address scalability and quantum concerns. Together, they form the foundation of Zcash’s long-term roadmap. While they address different challenges on the surface, both are ultimately designed around the same objective: enabling Zcash to operate at a global scale while remaining resilient to future threats.

Scaling through Tachyon

Tachyon is designed to address the fundamental scalability constraints inherent to Zcash’s current architecture. Today, the cost of verifying transactions grows with the history of the chain, creating a natural ceiling on throughput as increasing transaction volume also increases the burden placed on validators and users.

Tachyon fundamentally changes this dynamic by restructuring how transactions are verified and how data is transmitted; it removes the need for the network to scale with its own history. Instead of requiring nodes to process an ever-growing dataset, the system maintains a small, bounded state, allowing verification costs to remain constant over time.

As outlined in a recent discussion between Dev and Arjun Khemani, Zcash’s scaling approach focuses on increasing consensus bandwidth, reducing per-transaction data, and eliminating the need for wallets to scan the full chain history. One of the key components of this approach is reducing the amount of data required per transaction through the aggregation of zero-knowledge proofs at the block level. Rather than including a proof for each transaction, the protocol uses recursive techniques to generate a single proof that verifies all transactions within a block, reducing transaction sizes from approximately 9.3 kilobytes today to roughly 450 bytes in a pre-quantum setting.

Combined with planned increases in consensus bandwidth, from approximately 27 kilobytes per second today to a target of ~1 megabyte per second, these changes materially increase throughput. Current shielded throughput is approximately 3 TPS. Under this new, optimized design, this could increase to roughly 2,200 TPS in a pre-quantum setting.

Even under more demanding assumptions, such as the use of post-quantum cryptography, throughput remains significantly higher than today. Accounting for larger transaction sizes (~1.5 kilobytes), Zcash is expected to support approximately 660 private TPS. For a more technical breakdown of Tachyon, refer to Messari’s Understanding Zcash: A Comprehensive Overview.

In doing so, Tachyon shifts the scalability bottleneck away from cryptographic constraints and toward more traditional factors such as latency and bandwidth. Rather than being limited by the structure of the protocol itself, Zcash can begin to scale in a manner more similar to high-throughput systems, where improvements come from engineering and infrastructure rather than fundamental redesigns.

Although an exact date has yet to be determined, these changes are expected to be implemented by summer 2026.

Post Quantum Roadmap

In a recent whiteboard session, Sean Bowe and Dev outlined Zcash’s post-quantum roadmap, focusing on three primary areas: recoverability, privacy, and soundness. The first step in this roadmap, Orchard Quantum Recoverability, is expected to be implemented in the near term through wallet-level updates, providing an initial safeguard while broader protocol upgrades are developed.

Orchard Quantum Recoverability

Orchard Quantum Recoverability addresses another piece of the quantum problem: what happens if current cryptographic assumptions fail before the network can fully transition to post-quantum cryptography?

Rather than assuming perfect timing, Orchard Quantum Reoverability ensures that funds remain recoverable in the event of a quantum attack. By introducing a structured path for users to migrate their funds, it protects against immediate loss and reduces the risk of large-scale theft. Importantly, it is not a complete solution to the quantum problem. It does not make Zcash quantum-proof today, but instead, it provides a safeguard that allows the network to upgrade its cryptography while preserving user balances, turning what would otherwise be a catastrophic failure into a manageable transition.

Post Quantum Privacy

Post-quantum privacy focuses on preventing quantum adversaries from deanonymizing transactions. The primary vulnerability lies in current key exchange mechanisms, which could be broken if an attacker knows a user’s address.

To address this, Zcash plans to adopt post-quantum key exchange schemes such as ML-KEM (Kyber). However, these introduce significantly larger public keys (~800 bytes-1 KB), requiring changes to how addresses are handled.

The proposed solution is an ID-based system, where users register public keys offchain and reference them via short hashes. Wallets can then privately retrieve the full key using techniques like PIR, preserving both usability and privacy.

Post Quantum Soundness

Post-quantum soundness addresses the eventual replacement of quantum-vulnerable cryptographic primitives, such as elliptic curve-based signatures and proof systems. While the direction is clear, the specific implementation remains an area of active development.

Rather than committing to a fixed approach today, Zcash is designing its architecture to accommodate this transition over time. In particular, Tachyon’s use of recursive proof aggregation introduces a modular framework in which cryptographic components can be replaced as post-quantum alternatives mature.

With recoverability in place, the urgency of achieving full post-quantum soundness is reduced. This allows Zcash to adopt new primitives in a measured way, aligning implementation with advances in post-quantum cryptography rather than locking into early designs.

Planetary Money

Once these features are implemented, ZEC inches closer to becoming planetary money. First, ZEC is further along on privacy adoption than nearly any other competitor. The amount of ZEC shielded has been in a consistent uptrend for well over a year. Most recently, in April, shielded ZEC reached a high of 5.2 million (up 84% YoY). This is perhaps a more meaningful signal than price appreciation alone, as it shows users are not only allocating to ZEC, but actively using it for privacy. Additionally, due to the design of Zcash, each marginal unit of ZEC that enters the shielded pool increases the privacy set for all users, creating a compounding effect. Even if a competing crypto were to introduce privacy at the base layer, it would take years to build a comparable privacy set. In that sense, Zcash’s core differentiator, privacy, has never been stronger.

Moving beyond privacy, the remaining constraints for crypto are scalability and quantum resistance. Both are being actively addressed within the Zcash ecosystem through Tachyon and Orchard Quantum Recoverability. Once successfully deployed, they would eliminate two of the largest long-term overhangs facing Zcash.

This becomes particularly relevant as quantum timelines continue to accelerate. While Bitcoin has yet to converge on a clear path toward quantum resistance, Zcash is already building the mechanisms required to navigate that transition. In that context, ZEC is not just differentiated on privacy, but positioned to address all three core constraints of crypto.

Closing Thoughts

We must not lose sight of how crypto can deliver the greatest good to society. It won’t come from wrapping the existing financial system in blockchain rails or extending the dominance of fiat through stablecoins, but from providing individuals with a true alternative. Crypto exists to separate the state from money, to establish predictable rules, eliminate single points of failure, and allow value to move freely without permission. Demand for an alternative monetary system will only grow from here as trust in institutions erodes, government debt climbs, and the global order becomes increasingly fragile and multipolar.

While this demand sets the stage for further adoption, crypto still faces a series of internal challenges that threaten its long-term viability. Privacy remains weak across most systems, scalability constraints prevent global adoption, and the rise of quantum computing calls into question the security of the entire stack.

Perhaps most concerning is that the largest and most dominant form of crypto, Bitcoin, appears both unwilling and unable to address these issues head-on. If Bitcoin is truly ossified and unable to contend with these issues, particularly the quantum threat, then the door is opened for competitors to steal market share from the market leader.

BTC remains the dominant form of cryptomoney, representing 76% of the market cap of the top ten assets. In many ways, BTC is cryptomoney. If its long-term viability is called into question, the implications extend far beyond a single asset; some capital may leave the asset class altogether, but the underlying demand for an alternative monetary system does not disappear. A portion of that capital will inevitably seek out other forms of crypto that are better equipped to address the limitations BTC cannot.

In a scenario where capital begins to diversify away from BTC, ZEC is well-positioned to benefit. It shares many of the same qualities that make BTC attractive (it is a fork of Bitcoin, after all), while directly addressing some of its key limitations. ZEC already offers built-in privacy and is actively working toward improved quantum resistance, while eliminating the cryptographic bottlenecks that constrain scale and throughput. Regardless of what happens with Bitcoin, Zcash is emerging as a form of money built for planetary scale.

Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.

This report was commissioned by a member of the Zcash community. All content was produced independently by the author(s) and does not necessarily reflect the opinions of Messari, Inc. or the organization that requested the report. The commissioning organization may have input on the content of the report, but Messari maintains editorial control over the final report to retain data accuracy and objectivity. Author(s) may hold cryptocurrencies named in this report. This report is meant for informational purposes only. It is not meant to serve as investment advice. You should conduct your own research and consult an independent financial, tax, or legal advisor before making any investment decisions. Past performance of any asset is not indicative of future results. Please see our Terms of Service for more information.

No part of this report may be (a) copied, photocopied, duplicated in any form by any means or (b) redistributed without the prior written consent of Messari®.

AJC is a Research Manager at Messari for the Enterprise team. His primary focuses are on Bitcoin and Consumer. Prior to joining Messari, AJC wrote an independent crypto blog.

Mentioned Assets

Suggested Research Based on your Watchlists

Create a new watchlist
Outline
  • Key Insights
  • Introduction
  • Three Challenges for Crypto: Privacy, Scalability, & Quantum
  • How Zcash Becomes Encrypted Money at Planetary Scale
  • Closing Thoughts
Author
AJC is a Research Manager at Messari for the Enterprise team. His primary focuses are on Bitcoin and Consumer. Prior to joining Messari, AJC wrote an independent crypto blog.
Mentioned Assets