CAUTION A- L1 · anonymous
Zcash
Zcash

Zero-knowledge privacy coin · optional shielded transactions, zk-SNARKs, unified addresses, 21 M cap

ZEC

Zcash ships the strongest privacy cryptography in the industry — and spent four years unable to prove it was sound.

One shielded pool sealed, a new one opened, and a migration still running. The maths is excellent; the ledger is not finished.

Jurisdiction decentralised · ECC (Denver, US)
Operating since 2016
Category Assets & Protocols
Rubric v2.7

How it works

Zcash launched on 28 October 2016 and kept Bitcoin's monetary schedule — 21 million coins, halvings roughly every four years — while replacing its transaction model with zero-knowledge proofs. Two address families coexist. Transparent addresses behave exactly like Bitcoin's: sender, receiver and amount are permanently public. Shielded addresses encrypt all three and prove validity with a zk-SNARK, so the network verifies a payment it cannot read. Unified addresses, introduced with NU5 in May 2022, hide that split behind a single string and let wallets pick the shielded path on their own.

The shielded side is not one pool but a lineage of them. Sprout (2016) needed a multi-party trusted setup. Sapling (October 2018) made shielded spends cheap enough for phones. Orchard (May 2022) moved to the Halo 2 proving system and removed the trusted setup entirely. Ironwood, activated at block 3,428,143 on 28 July 2026, is the fourth. Three organisations ship the code: Electric Coin Co. in Denver, the US-based Zcash Foundation, and Shielded Labs in Switzerland, which takes no block-reward funding.

KYC & privacy

There is no signup, no email, no account, and no operator holding a customer database. Zcash is a protocol; the only identity it can leak is the one you publish yourself. That caveat is the whole review. Privacy here is a mode, not a property — a transparent-to-transparent payment is as legible as Bitcoin, and for most of the chain's history most of the supply sat in the open.

That has shifted. Wallets now default to shielded: Zodl (formerly Zashi), Ywallet, Nighthawk and Cake Wallet route new sends into the encrypted pool without asking. Shielded transactions reached 59.3% of network activity in February 2026, and by August more than 4.9 million ZEC — over 30% of supply — was held shielded, the largest encrypted pool the chain has ever carried. What still leaks sits at the edges: exchanges that demand ID to convert ZEC, and the transparent addresses miners and custodians keep using.

Strengths and limits

The cryptography is first-rate. Halo 2 removed the trusted setup that dogged Sprout, and Ironwood's circuits were formally verified against more than 2,700 machine-checked theorems — a bar no other privacy chain has cleared. The reason that bar exists is the limit. On 29 May 2026 researcher Taylor Hornby found an under-constrained elliptic-curve multiplication in Orchard's circuit, live since May 2022, that would have allowed silent and untraceable counterfeiting. An emergency patch shipped within days; the disclosure followed on 4 June. It was the second flaw of its kind: an equivalent Sprout bug was found in 2018 and disclosed only in February 2019, after Sapling had quietly closed it.

Neither flaw shows evidence of exploitation, and Ironwood's turnstile — which caps withdrawals from the sealed Orchard pool at the amount verifiably deposited — is built to settle that question arithmetically once the migration finishes. It has not finished. Moving coins is voluntary, the count stood near 85% in August 2026, and roughly 3% of supply is still parked in a pool nobody should be using.

Verdict

Zcash runs the strongest privacy construction in production, and its maintainers publish their failures rather than bury them — eventually. Measured against Monero, it trades mandatory privacy for optional privacy and a shorter clean record, and that is precisely where the grade lands. Keep an Ironwood-capable wallet, keep balances shielded, and treat any ZEC still sitting in Orchard as unfinished business. Grade: A- (8.9/10). Trust: CAUTION.

verdict.zcash.diff +5 pros −4 cons
what works
+ 01 Halo 2 removed the trusted setup; Ironwood circuits formally verified against 2,700+ theorems
+ 02 No signup, no email, no operator — identity never enters the protocol itself
+ 03 Shielded-by-default wallets pushed 59.3% of February 2026 transactions into the encrypted pool
+ 04 Both counterfeiting flaws were published with dates, code and a post-mortem
+ 05 Open source under MIT, with a grant-funded ecosystem security lead at Least Authority
what to know
01 Privacy is opt-in: transparent addresses are exactly as public as Bitcoin's
02 Second protocol-level counterfeiting flaw in eight years, live for four of them
03 Ironwood migration is voluntary and unfinished — ~3% of supply still in the sealed Orchard pool
04 ECC in Denver and a US foundation stay subpoena-reachable, unlike a no-operator chain

The strongest zero-knowledge privacy in production, wrapped around an optional-privacy default and a fresh soundness incident that turnstile arithmetic has not yet closed. Right for users who keep balances shielded and wallets current; wrong for anyone who wants privacy they cannot forget to switch on. Grade: A- (8.9/10). Trust: CAUTION.