Network Upgrade 5 (NU5), the sixth major upgrade to Zcash, is expected to go live in mid-April of 2022. In conjunction with various features included with NU5, the Zcash team is also introducing Halo Arc, a suite of solutions that bundle new features and products with protocol upgrades like NU5 into regular releases. The NU5 upgrade includes one of the most coveted features for privacy-centric users, the Halo 2 proving system, which does not require a trusted setup. The other significant features of this upgrade enhance privacy and scalability on the Zcash network through recursive cryptography, proof aggregation, and blockchain succinctness.
Halo Arc Overview
Halo Arc is a suite of solutions that utilize new features included in NU5 and a concept of unified addresses to bundle upgrades, products, and new features into regular releases. The core components of the Halo Arc suite are as follows:
Zcashd – Zcashd is an NU5-compatible consensus node that will support Zcash Improvement Proposals (ZIPs) 224, 225, and 316. More information about these ZIPs can be found in the Zcash NU5 Overview section below.
ECC Reference Wallet – The Electric Coin Company (ECC) Reference Wallet is an open-source, beta reference implementation of a Zcash wallet for Android and iOS.
NU5-Compatible Wallet SDKs – ECC has developed wallet SDKs for Android and iOS that will support NU5 by including functionality for unified addresses, the Orchard shielded protocol, and a new transaction format. NU5-compatible SDKs will allow developers to utilize an auto-shielding feature that lets user wallets automatically move funds from a non-shielded address to the latest ZEC shielded pool, enabling shielded assets by default. Additionally, these SDKs will support an auto-migration feature that allows wallets to move funds to the newest shielded pool without user intervention and improve note management to reduce wait times for users sending transactions.
Unified Addresses
Unified addresses are a new address format generated from multiple addresses and are a vital component of the Halo Arc suite. They serve as an adapter that makes it easier to plug into various underlying address types, removing the need for users to migrate to the latest shielded pool. Zcash supports multiple address types, in the same way that Bitcoin has different address formats such as legacy, SegWit, and Taproot addresses. Unified addresses will encapsulate transparent (unshielded), Sapling (legacy shielded), and Orchard (latest shielded) address types to automatically deprecate legacy address types and remove the complexity of dealing with multiple address types. ECC hopes to increase interoperability between shielded-only and transparent-only applications while assuring users that their funds are shielded by default when using auto-shielding supported wallets. Unified addresses can also allow the Zcash team to iterate quickly without introducing new address types.
Zcash NU5 Overview
NU5 includes a series of ZIPs that introduce the Orchard-shielded protocol for more scalable shielded pools, a new version 5 transaction format, unified addresses, and more. The landmark feature of NU5 is the Halo 2 proving system. Traditionally, Zcash has utilized a zk-SNARK-based system for privacy. The original scheme requires a trusted setup in which a group of individuals shares a set of public parameters used to create private transactions on the network. At launch or during significant network upgrades, this group of individuals must provide the system with parameters to initialize the chain to audit the initial supply. This process can lead to unintended inflation concerns as users who have access to these parameters can mint ZEC arbitrarily. After genesis, the parameters held by the individuals are considered “toxic waste” and must be destroyed to prevent individuals from creating counterfeit ZEC. In essence, the trusted setup problem arises because users must trust individuals who participated in the parameter generation event to destroy the toxic waste.
Enter Halo, Zcash’s solution to the trusted setup problem. This latest proving system is a new zk-SNARK that removes the need for a trusted setup and enhances scalability through recursive cryptography. In addition to removing the need for a trusted setup, Halo allows for recursive proof composition. Essentially, a single cryptographic proof can attest to the correctness of other proofs, which can allow a large amount of computation and information to be compressed. Users can verify the validity of the Zcash blockchain by simply verifying one cryptographic proof that attests to the validity of all previous proofs.
Orchard-Shielded Protocol
The Orchard protocol is a new shielded pool with spending keys and payment addresses similar to the Sprout and Sapling pools. In Zcash, all ZEC resides within value pools determined by the type of address holding the ZEC. There is a transparent pool for unshielded transactions and two shielded pools, Sprout and Sapling. In their current form, both Sprout and Sapling pools have scalability issues related to their ability to deal with specific categories of elliptic curves. Orchard contains two primary enhancements compared to legacy shielded pools, new privacy sets to increase the security of the monetary base, and more flexibility to incorporate future scalability improvements.
In addition to the migration to the Halo 2 proving system, NU5 includes the following ZIPs:
ZIP-216: Require Canonical Jubjub Point Encodings
ZIP 216 fixes a problem with the way Jubjub was implemented in Zcash’s 2017 Sapling upgrade which could have possibly caused a consensus issue. Jubjub is an elliptic curve (a key element in modern-day cryptography) that performs operations on the inside of zk-SNARK circuits.
ZIP-224: Orchard-Shielded Protocol
ZIP 224 proposes the Orchard-shielded protocol, a new shielded pool with spending keys and payment addresses similar to the Sprout and Sapling pools. The point of Orchard is twofold: new pools with separate privacy sets are instituted at major network upgrades to increase the security of the monetary base, and Orchard is more amenable to future scalability improvements.
ZIP-225: Version 5 Transaction Format
ZIP-225 defines an update to the Zcash peer-to-peer transaction format to include support for data elements required to support the Orchard protocol (ZIP 224). This new format serves each of the existing pools of funds and also adds and describes a new region containing the Orchard-specific elements. This new format should also lend itself to future extension or pruning to add or remove value pools.
ZIP-239: Relay of Version 5 Transactions
Building off of ZIP 225, ZIP-239 alters the peer-to-peer network protocol, adding a new data type that must be used for advertising V5 transactions to ensure that network nodes cannot perform a DDoS attack on wallets submitted to the mempool.
ZIP-244: Transaction Identifier Non-Malleability
ZIP-244, a highly technical proposal, defines a new transaction digest algorithm for the NU5 network upgrade onward, for signature validation, and in order to introduce non-malleable transaction identifiers. These upgrades, along with other enhancements, are in order to support the use of transactions in higher-level protocols.
ZIP-252: Deployment of the NU5 Network Upgrade
ZIP-252 describes the implementation of NU5, including activation instructions and timelines.
ZIP-316: Unified Addresses and Unified Viewing Keys
ZIP-316 defines a new future-proof Zcash address format that improves usability, increases the ease of interoperability, and supports shielding Zcash by default. Universal Addresses make Zcash easier to use by removing the complexity of multiple address types. This simplifies the user experience and increases interoperability between shielded-only and transparent-only applications.
Development Timeline
September 2019: The earliest mention of Halo came in September 2019, in a blog post put out by ECC, where they reported one of their engineers discovered a technique for creating practical zero-knowledge recursive proof composition without the need for a trusted setup, which they called Halo. Halo 2 was then announced in September 2020, and the code was open-sourced.
January 8, 2021: NU5 launch date was mentioned in a blog post by ECC titled “Bringing Halo 2 to Zcash” in January 2021. It was stated within the blog post that the team believed NU5 could be “successfully and safely deployed… by the summer of 2021.” The activation date was set for October 1, 2021, on April 13, 2021.
September 3, 2021: On September 3, 2021, the Zcash team announced that the NU5 launch had been postponed until January 17, 2022. The reason for this postponement was outlined in a blog post: to allow more time for a third-party audit to complete, and a discovery that changes to implementation may be needed to facilitate better interoperability with an important hash function.
September 23, 2021: Zcashd v4.5.0 was released specifying the code for the NU5 consensus rules. This was the first code release geared towards the NU5 upgrade. It also specified the testnet activation at block 1,590,000 (early October 2021).
September 28, 2021: Zcashd v4.5.1, building on Zcash v4.5.0, added support for generating Unified Addresses, a defining feature of NU5. This release was required for all testnet nodes and highly recommended for mainnet nodes.
October 6, 2021: NU-5 Testnet was activated on October 6, 2021, at block height 1,559,220, and is currently running smoothly.
October 3, 2021: Zcash node client Zebra successfully validated the NU5 activation block on testnet and started verifying V5 transactions.
December 16, 2021: The team then shared a follow-up blog post on December 16, 2021, stating that the launch again needed to be postponed until April 18, 2022. Specific items mentioned included: more time for proof of zero-knowledge and soundness of the Halo 2 construction, an additional internal security audit, and securing commitments from partners to be ready at activation.
The current target activation date for NU5 on mainnet remains April 18, 2022.
According to the latest information contained in ZIP-252, NU5 was activated on testnet at block 1,599,200. Core contributors have stated that a second testnet activation of the upgrade may be required. In the case that a second testnet activation does occur, node operators will reorganize the testnet and drop all blocks mined after the initial NU activation. The activation block height on mainnet has not yet been determined.
For node operators, zcashd version 5.0.0 will include the activation block for the NU5 upgrade on mainnet. Before the activation block, NU5 and pre-NU5 nodes will maintain compatibility. However, nodes will begin rejecting new connections and disconnecting from non-NU5 nodes once the upgrade goes live. Approximately 1.5 days before the activation height, nodes compatible with NU5 will start preferring connections to peers that are also compatible with the upgrade. Node operators should plan to upgrade before this period of preferring upgraded peers occurs.
What’s Next on the Roadmap?
Looking ahead, ECC and the Zcash core developers are expected to shift their focus towards transitioning to a proof-of-stake consensus mechanism, implementing a feature known as Zcash-Shielded Assets (ZSAs). Zooko Wilcox, CEO of ECC, argued in favor of transitioning to proof of stake to reduce downward sell pressure and increase the productive utility of the ZEC asset. He also argued that proof of stake is a step forward for security, performance, introducing novel use cases, and providing a voice for coin holders. In initial discussions, developers have proposed leveraging the Cosmos stack to support the migration to proof of stake, which would have the added benefit of increasing interoperability through the Inter-Blockchain Communication Protocol (IBC) and incorporating the Zcash blockchain into a wider multichain ecosystem.
ZSAs can enable tokens that live on other blockchains to be bridged into Zcash, which would allow these assets to tap into Zcash’s privacy features. The ECC highlights a potential for Zcash-Shielded BTC, USDC, and ETH. ZSAs may even be able to include NFTs and DAOs. ECC is currently pursuing a study of decentralized markets involving multiple assets on the Zcash blockchain and has engaged the Computational Experimental Economics Lab at George Mason University to assist with this study.
After years of deep cryptography research and systems engineering, ECC will look to transition from an engineering-led strategy to a more product-centric focus. By prioritizing user experience and scalability research, Zcash developers and supporting entities will shift their focus towards expanding adoption and servicing novel use-cases.
All content was produced independently by the author(s) and does not necessarily reflect the opinions of Messari, Inc. Author(s) may hold cryptocurrencies named in this report. This report is meant for informational purposes only. It is not meant to serve as investment advice. You should conduct your own research and consult an independent financial, tax, or legal advisor before making any investment decisions. Nothing contained in this report is a recommendation or suggestion, directly or indirectly, to buy, sell, make, or hold any investment, loan, commodity, or security, or to undertake any investment or trading strategy with respect to any investment, loan, commodity, security, or any issuer. This report should not be construed as an offer to sell or the solicitation of an offer to buy any security or commodity. Messari does not guarantee the sequence, accuracy, completeness, or timeliness of any information provided in this report. Please see our Terms of Service for more information.
No part of this report may be (a) copied, photocopied, duplicated in any form by any means or (b) redistributed without the prior written consent of Messari®.
Matt joined Messari as a research analyst after working as a software engineer in the financial services industry. Matt's primary areas of interest include infrastructure, layer two ecosystems, and cross-chain technologies.
Matt joined Messari as a research analyst after working as a software engineer in the financial services industry. Matt's primary areas of interest include infrastructure, layer two ecosystems, and cross-chain technologies.