An independent guide · Updated October 2026

What is Zcash?

Zcash is digital money with a fixed 21 million supply, like Bitcoin, that lets you keep the sender, receiver and amount of a payment encrypted while the network still proves the payment is valid.

Live Zcash market data

ZEC price
Loading…
24h change
–
Market cap
–
Circulating supply
–
Last 7 days
Fetching live data…Market data from CoinGecko. Figures move constantly and are not advice.

01 · The short version

Zcash in 60 seconds

If you only read one section, read this one. Four ideas cover most of what makes Zcash different from other cryptocurrencies.

01 / MONEY

Bitcoin's rules, new privacy

Zcash began as a modified copy of Bitcoin's code. It keeps the 21 million coin limit, mining and halvings, and adds encryption on top.

02 / PRIVACY

Shielded by choice

A shielded transaction hides who paid whom and how much. A transparent one is public, like Bitcoin. Users pick which to use.

03 / PROOF

Zero-knowledge maths

The network checks every shielded payment with a zk-SNARK: a tiny proof that the rules were followed, revealing nothing else.

04 / STATUS

Ten years old in 2026

Launched on 28 October 2016, Zcash is now built by several independent teams and the coin trades under the ticker ZEC.

Most blockchains are radically public. Anyone can look up an address and see every payment it has ever made or received, forever. That is useful for auditing, but it is unlike the way cash or a bank account works, where your salary and shopping are not visible to strangers.

Zcash was created to fix that one problem. It offers a kind of digital cash where the ledger is still shared and verifiable by everyone, yet the details of individual payments can be encrypted. The trick is a branch of cryptography called zero-knowledge proofs, which Zcash was the first major cryptocurrency to put into everyday use.

02 · Where it came from

From a university paper to a live network

Zcash is one of the few cryptocurrencies that started as peer-reviewed academic research rather than a white paper posted to a forum.

  • Eli Ben-Sasson
  • Alessandro Chiesa
  • Christina Garman
  • Matthew Green
  • Ian Miers
  • Eran Tromer
  • Madars Virza

Zerocoin (2013)

The story starts at Johns Hopkins University. Professor Matthew Green and graduate students Ian Miers and Christina Garman proposed Zerocoin, an add-on to Bitcoin that would let people break the link between coins they received and coins they spent. It worked, but the proofs were large and it could not hide amounts.

Zerocash (2014)

The Johns Hopkins group then joined forces with cryptographers from MIT, the Technion and Tel Aviv University who had been developing a compact form of zero-knowledge proof called a zk-SNARK. Their combined design, Zerocash, hid the sender, the receiver and the amount, with proofs small enough to fit comfortably in a block. Its seven authors are still recognised as Zcash's founding scientists.

The Zcash Company (2015 to 2016)

Turning a paper into working money needed engineers and funding. Zooko Wilcox, a long-time cypherpunk and security engineer, led a start-up (first called the Zerocoin Electric Coin Company, later the Electric Coin Company or ECC) that raised money from early investors and built the software. The network went live on 28 October 2016.

The ceremony

The first version of Zcash's proof system needed a one-time "trusted setup": secret random numbers had to be generated and then destroyed, because anyone who kept them could forge coins. Six people in different locations ran an elaborate ceremony to do this, destroying the computers afterwards. A much larger ceremony with dozens of participants followed for the 2018 Sapling upgrade, and since the 2022 NU5 upgrade Zcash's newest shielded technology has needed no trusted setup at all.

03 · 2013 to 2026

The Zcash timeline

Filter by era to follow the story from a research idea to a network run by several independent organisations.

  1. Zerocoin is published

    Matthew Green, Ian Miers, Christina Garman and Aviel Rubin at Johns Hopkins describe a way to add anonymity to Bitcoin.

  2. The Zerocash paper

    Seven researchers publish a full design for private payments using zk-SNARKs. It becomes the blueprint for Zcash.

  3. Zcash is announced

    Zooko Wilcox's company announces it will turn Zerocash into a standalone cryptocurrency.

  4. Mainnet launch

    The first Zcash blocks are mined after the six-person trusted setup ceremony. The original shielded pool is later named Sprout.

  5. The Zcash Foundation forms

    A separate non-profit is created so that no single company controls the project. Grayscale opens a private Zcash investment trust.

  6. Regulated listing in New York

    New York's financial regulator approves Zcash trading on Gemini, an early signal that optional privacy could fit inside regulated markets.

  7. Sapling

    A major upgrade makes shielded payments fast and light enough for phones, and introduces viewing keys.

  8. A fixed bug is disclosed, and Halo is discovered

    The team reveals it had quietly fixed a counterfeiting flaw in the original Sprout setup. Later that year ECC's Sean Bowe announces Halo, a way to build proofs with no trusted setup.

  9. First halving and Canopy

    The block reward halves, the Founders' Reward ends and a community-approved development fund begins. ECC is donated to a non-profit called Bootstrap.

  10. NU5: Orchard and unified addresses

    The Orchard shielded pool launches on the Halo 2 proof system, removing the need for trusted setups. One "unified" address can now cover every pool.

  11. Mining concentration and a new CEO

    One mining pool, ViaBTC, briefly controls more than half of the network's hash power. In December, Zooko Wilcox steps down as ECC's chief executive and Josh Swihart takes over.

  12. Second halving and NU6

    The block reward halves again. Part of each block now goes into a protocol "lockbox" to be allocated later.

  13. A sudden revival

    After years of low prices, ZEC rises many times over in a few weeks as shielded usage climbs and the Zashi wallet adds cross-chain swaps. Several exchanges that had dropped ZEC relist it.

  14. NU6.1: coin holders get a vote

    A new funding model gives ZEC holders a direct say over a pool of development money.

  15. The ECC team walks out

    The whole ECC staff resigns after a dispute with the Bootstrap board and regroups as the Zcash Open Development Lab (ZODL). The Zashi wallet is renamed Zodl. The US SEC closes an inquiry involving the Zcash Foundation with no action.

  16. ZODL raises funding; an old bug is fixed

    ZODL announces a seed round of more than 25 million US dollars. A researcher reports a flaw affecting the old Sprout pool, which is patched before anyone exploits it.

  17. The Orchard vulnerability

    Researcher Taylor Hornby finds a flaw in Orchard's proof circuit that could, in theory, have allowed counterfeit ZEC. An emergency upgrade (NU6.2) fixes it within days. No exploitation is found.

  18. Ironwood

    A new, formally verified shielded pool replaces Orchard, and a "turnstile" lets anyone audit the supply. The original zcashd node software is retired.

  19. A spot ETF in the United States

    Grayscale converts its Zcash trust into an exchange-traded fund on NYSE Arca under the ticker ZCSH.

  20. NU7 (scheduled)

    Developers have targeted 5 November 2026 for an upgrade that cuts block time from 75 to 25 seconds. The final decision was due in late October.

04 · Under the hood

How Zcash works

You do not need the maths to understand the idea. Start with what an outside observer can see, then look at how the network can check a payment it cannot read.

What does a blockchain observer see?

What actually happened

FromAlice
ToBob's bookshop
Amount2.5 ZEC
Memo"Order 1142, thank you"

The same payment, sent three different ways. Use the toggle to switch.

What the public ledger shows

From
To
Amount
Memo
Valid?

Illustration only. Addresses and values are made up and shortened.

Two kinds of address

Transparent addresses start with a "t" and behave just like Bitcoin addresses: balances and payments are public. Shielded addresses keep balances and payment details encrypted. Coins held in shielded addresses are said to be in a shielded pool.

Zcash has had four shielded pools as the cryptography improved: Sprout (2016), Sapling (2018), Orchard (2022) and Ironwood (2026). Modern wallets hide this history behind a single unified address, which starts with "u" and bundles the address types a wallet supports.

Proving without revealing

A zk-SNARK is a short piece of data that proves a statement is true without showing why. For a shielded payment the statement is roughly: "I own unspent coins, I am not spending them twice, and the amounts going in equal the amounts going out." Every node can check that proof in milliseconds, and it learns nothing else.

Privacy you can open up

Shielded does not have to mean secret from everyone. The owner of a shielded address can share a viewing key that lets an accountant, auditor or tax office read its transactions without being able to spend the funds. This "selective disclosure" is a large part of how Zcash argues it can coexist with regulation.

A shielded payment, step by step

  1. You hold notes. Your wallet keeps encrypted "notes", a bit like sealed envelopes of cash that only your keys can open.
  2. You build a proof. To pay, your phone creates a zk-SNARK showing the notes are real and unspent, without identifying them.
  3. The network verifies. Miners and nodes check the proof and record a "nullifier" that prevents the same note being spent twice.
  4. The recipient decrypts. A new encrypted note appears on the chain. Only the recipient's wallet can read it, along with an optional private memo.
  5. The supply stays auditable. Because every proof enforces "in equals out", and coins moving between pools pass through public turnstiles, the total supply can still be checked.
Worth knowing: privacy depends on how you use Zcash. Moving coins from a transparent address into a shielded one and straight back out, in the same amount, can be linked by simple pattern-matching. Coins that stay shielded are far harder to trace.

05 · Supply and funding

Tokenomics

Zcash copies Bitcoin's monetary schedule: a hard cap of 21 million ZEC, released through mining, with the rate of new coins cut in half roughly every four years.

Supply curve and halvings

Approximate ZEC supply over time A curve rising steeply from 2016 and flattening towards 21 million ZEC, with halvings marked in 2020, 2024, 2028 and 2032.
Approx. mined
–
Share of 21M
–
New ZEC per day
–

A simplified model for illustration. It ignores the gentle "slow start" in 2016 and small timing drifts. The live circulating supply is in the stats bar above.

CAP

21,000,000 ZEC

No more can ever exist under the current rules. The smallest unit, one hundred-millionth of a ZEC, is called a zatoshi.

HALVINGS

2020, 2024, next about 2028

The first halving was on 18 November 2020 and the second on 23 November 2024. The third is expected around November 2028.

MINING

Proof of work (Equihash)

New coins go to miners who secure the network. Blocks have arrived about every 75 seconds since 2019; NU7 is scheduled to change this to 25 seconds with a proportionally smaller reward per block, leaving daily issuance unchanged.

Who gets the block reward? A short history

PeriodMinersOther recipientsWhat changed
2016 to 202080%20% "Founders' Reward" to founders, investors, employees, the company and the Zcash FoundationControversial at launch. It ended at the first halving and totalled about 10% of the eventual supply.
2020 to 202480%7% ECC (via Bootstrap), 5% Zcash Foundation, 8% community grantsA development fund approved by community polling replaced the Founders' Reward.
Nov 2024 to Nov 202580%8% Zcash Community Grants, 12% protocol lockboxNU6 ended direct funding of ECC and the Foundation and parked 12% until the community decided how to use it.
Nov 2025 onward80%8% Zcash Community Grants, 12% coinholder-controlled fundNU6.1 lets ZEC holders vote on grants from the fund. The arrangement is set to run until the third halving, expected in November 2028.
Percentages are shares of each block's newly issued coins. Transaction fees are separate and currently small.

The NU7 upgrade also adds a "Network Sustainability Mechanism". As described by developers, most transaction fees would flow into a reserve rather than straight to miners, and that reserve would be paid back out as extra mining rewards from 2031. The aim is to support the security budget as block rewards shrink. The 21 million cap and the halvings stay in place. Details may change before or after activation, so check the official upgrade notes.

06 · Who is involved

People and organisations

Zcash has no chief executive. In 2026 it is developed by several independent groups that share a public process for proposing and approving changes.

Organisations today

Engineering and wallet

ZODL

The Zcash Open Development Lab was formed in January 2026 by the engineers and product team who left ECC, led by former ECC chief executive Josh Swihart. It builds the Zodl wallet (formerly Zashi) and contributes to the core protocol. It is venture funded rather than paid from block rewards.

ZODL official site
Non-profit

Zcash Foundation

A US public charity founded in 2017. It maintains Zebra, the Rust node software the network now relies on, runs community polling, holds the Zcash trademark, and in 2026 took over the z.cash website and code repositories. Its executive director is Alex Bornstein.

Zcash Foundation official site
Research

Shielded Labs

A Swiss-based, donation-funded organisation co-founded by Zooko Wilcox. It leads Crosslink (the proof-of-stake proposal), championed Ironwood, and its security review uncovered the 2026 Orchard flaw. Donors have included the Winklevoss twins and Vitalik Buterin.

Shielded Labs official site
Grants

Zcash Community Grants

A five-person committee elected by the community. It awards grants to independent teams using 8% of block rewards, an arrangement approved to run until the 2028 halving.

Zcash Community Grants site
Scaling

Project Tachyon and Valar Group

Tachyon is cryptographer Sean Bowe's plan to make shielded payments far smaller and faster. With Valar Group, the team also maintains Zakura, a second full-node implementation released in 2026.

Project Tachyon site
Historical

Electric Coin Co. and Bootstrap

ECC launched Zcash in 2016 and led development for nearly a decade. From 2020 it was owned by Bootstrap, a non-profit. After the January 2026 walkout, the official Zcash site describes ECC as having concluded operations in 2026.

ECC's page on z.cash

People to know

Zooko Wilcox

Founder

Led the company that launched Zcash and ran ECC until December 2023. Now associated with Shielded Labs, which he co-founded.

The founding scientists

Zerocoin and Zerocash authors

Ben-Sasson, Chiesa, Garman, Green, Miers, Tromer and Virza designed the protocol. Several went on to found other zero-knowledge projects.

Sean Bowe

Cryptographer

Discovered Halo, the technique that removed trusted setups, and now leads Project Tachyon.

Josh Swihart

Leads ZODL

ECC's chief executive from December 2023 until the team's resignation in January 2026.

Daira-Emma Hopwood

Protocol designer

Long-time author of the Zcash protocol specification and a co-author of the security proof for Ironwood.

Taylor Hornby

Security researcher

Found the Orchard circuit vulnerability in May 2026 during a review with Shielded Labs. Sits on the Zcash Foundation board.

Alex Bornstein

Zcash Foundation

Executive director of the Foundation, which now stewards Zebra and the z.cash website.

Jason McGee

Shielded Labs

Leads Shielded Labs and co-wrote its public explanations of the Orchard incident with Zooko Wilcox.

Backers and well-known supporters

Early and recent investors

Naval Ravikant was among the first investors in the Zcash Company. ZODL's 2026 seed round was reported to include Paradigm, a16z crypto, Coinbase Ventures, Winklevoss Capital and Maelstrom.

The Winklevoss twins

Cameron and Tyler Winklevoss, founders of Gemini, funded Cypherpunk Technologies in 2025, a listed company that accumulates ZEC, and donated to Shielded Labs in January 2026.

Edward Snowden

In 2022 Snowden revealed he had been one of the six participants in the 2016 launch ceremony, taking part under a pseudonym.

07 · What exists around it

The Zcash ecosystem

Beyond the coin itself there is a growing set of software, services and financial products. Here is the landscape as of October 2026.

NODES

Zebra and Zakura

Two independent full-node implementations now run the network. The original zcashd software, inherited from Bitcoin's codebase, was retired in July 2026.

SWAPS

Cross-chain without a bridge

The Zodl wallet uses NEAR Intents so users can swap between shielded ZEC and assets such as BTC, ETH or stablecoins, or pay someone in another coin directly from a shielded balance.

SPENDING

Paying in shops

An integration with the Flexa payments network lets Zodl users spend ZEC at participating retailers.

FUNDS

ETF and treasury companies

Grayscale's ZCSH, listed in August 2026, was announced as the first exchange-traded product with spot ZEC exposure. Cypherpunk Technologies holds ZEC on its balance sheet. Neither gives holders shielded coins.

MINING

Industrial miners arrive

In 2026 Foundry opened a Zcash mining pool and listed companies bought large fleets of Equihash machines. The number of distinct miners winning blocks has risen since 2025.

COMMUNITY

Education and governance

ZecHub publishes community-written guides. Changes are debated on the Zcash Community Forum and specified as Zcash Improvement Proposals (ZIPs).

Browse the z.cash ecosystem directory

One number the community watches closely is the share of ZEC held in shielded pools. Independent analysts put it at a little under 30% of supply in late summer 2026, up from single digits a few years earlier.

08 · What comes next

Roadmap and future

Zcash upgrades only activate after public specification, testing and community agreement. Dates slip and proposals change, so treat everything below "shipped" as intentions, not promises.

Shipped · Jul 2026

Ironwood (NU6.3)

A new shielded pool with a formally verified circuit. The older Orchard pool now only allows withdrawals, and a turnstile caps what can leave it, so the public can confirm no counterfeit coins entered circulation. By the end of August most Orchard funds had already migrated.

Scheduled · Nov 2026

NU7

Planned for 5 November 2026: 25-second blocks, retirement of old-format transactions (and with them normal spending from the legacy Sprout pool), and the Network Sustainability Mechanism. It introduces no new transaction format, so ordinary wallet users should not need to do anything.

In development

Project Tachyon

A redesign of how shielded payments are proved and synchronised, aiming for much smaller transactions, wallets that sync almost instantly, and privacy that holds up against future quantum computers. It needs community approval and has no mainnet date.

Testing

Crosslink (hybrid proof of stake)

Shielded Labs' proposal to add a staking-based finality layer on top of mining, so that confirmed transactions cannot be reversed and ZEC holders can earn rewards for securing the chain. An incentivised test network has run during 2026. Activation is a governance decision that has not been made.

Under debate

Zcash Shielded Assets (ZSA)

Would let other tokens, such as stablecoins, be issued and transferred with Zcash's privacy. The specification exists and integration work continues, but it was left out of NU7 and remains under discussion.

Proposed

Quantum readiness

Ironwood added "quantum-recoverable" notes as a safety net. Zakura engineers have said they aim to add quantum-resistant signature options for transparent addresses in early 2027. No activation date is confirmed.

09 · Side by side

Zcash vs Bitcoin vs Monero

Bitcoin is the template Zcash copied. Monero is the other well-known privacy coin, and it takes a very different approach.

FeatureZcash (ZEC)Bitcoin (BTC)Monero (XMR)
LaunchedOctober 2016January 2009April 2014
Supply limit21 million21 millionNo hard cap; small permanent "tail" issuance
Privacy modelOptional. Shielded or transparentNone built in. Pseudonymous and publicMandatory for every transaction
Privacy techniqueZero-knowledge proofs (zk-SNARKs)Not applicableRing signatures, stealth addresses, confidential amounts
What is hiddenSender, receiver, amount and memo when shieldedNothingSender, receiver and amount
Selective disclosureYes, through viewing keysEverything is already publicYes, through view keys
ConsensusProof of work (Equihash); hybrid proof of stake proposedProof of work (SHA-256)Proof of work (RandomX, CPU-friendly)
Block time75 seconds (25 scheduled with NU7)About 10 minutesAbout 2 minutes
Development fundingShare of block rewards plus donations and venture capitalDonations and sponsorsCommunity donations
Main trade-offPrivacy is only as strong as the number of people who choose to shieldSimple and widely held, but fully traceablePrivate by default, but harder for regulated exchanges to list

10 · Holding ZEC yourself

Wallets guide

A wallet stores the keys that control your coins. For Zcash the key question is whether it supports shielded addresses, because many multi-coin wallets only handle transparent ZEC.

Shielded-first

Zodl (formerly Zashi)

iOS · Android · by ZODL

The most widely used Zcash-only wallet. Shielded by default, with built-in swaps and cross-chain payments, one-tap migration to Ironwood and Keystone hardware support.

Zodl official site
Shielded-first

Zingo!

Mobile · Desktop · by Zingo Labs

An open-source wallet that leans on encrypted memos to give you a private record of your own spending. Supports unified addresses.

Zingo Labs official site
Shielded

YWallet

iOS · Android · Desktop

Known for very fast syncing and power-user features such as multiple accounts and paying many recipients at once. Check its site for current pool support.

YWallet official site
Shielded via Zodl

Keystone

Hardware · air-gapped, QR-code signing

The first hardware wallet to support shielded ZEC. It pairs with the Zodl app, which builds the transaction while the keys stay offline on the device.

Keystone on z.cash
Shielded (desktop app)

Ledger

Hardware · Ledger Wallet desktop

Long supported transparent ZEC. In September 2026 Ledger announced native shielded support in its desktop app, with mobile to follow. Check which device models are supported.

Ledger's shielded Zcash announcement
Transparent only

Trezor

Hardware · Trezor Suite

Supports transparent ZEC addresses only at the time of writing, so balances held this way are publicly visible on the blockchain.

Trezor official site
Multi-coin · shielded

Edge

iOS · Android

A self-custody wallet for many coins that supports shielded Zcash, useful if you want ZEC alongside other assets in one app.

Edge official site
Multi-coin · shielded

Unstoppable

Mobile

A multi-currency, self-custody wallet listed in the official ecosystem directory as shielded by default for Zcash.

Unstoppable official site
Legacy

Nighthawk

iOS · Android

Once a popular shielded wallet. Reviewers reported in 2026 that it could no longer send ZEC after network upgrades. Existing users can restore their seed phrase in a maintained wallet.

Nighthawk Wallet site
Three habits that matter more than which wallet you pick: write your recovery phrase on paper and never type it into a website; download wallets only from links on the developer's own site; and send a small test payment before moving anything significant. If you still hold coins in the old Orchard, Sapling or Sprout pools, a current wallet will guide you through moving them.

11 · Getting some

Where and how to buy ZEC

This is a neutral walkthrough, not a recommendation to buy. Availability depends heavily on where you live, and it changes. Always confirm on the exchange's own site.

Step by step

  1. Check what is legal and available where you live. Some countries restrict privacy coins, and some exchanges offer ZEC in one region but not another.
  2. Set up your own wallet first. Install a shielded wallet from the list above and back up the recovery phrase offline.
  3. Open an account with a regulated exchange. Expect identity checks. Compare fees and check whether withdrawals to shielded addresses are supported.
  4. Buy ZEC. Fund the account with your local currency and place an order. Start small while you learn.
  5. Withdraw to your wallet. Copy your wallet's address, send a small test amount, then the rest. If the exchange only pays out to transparent addresses, your wallet can shield the coins afterwards.
  6. Keep records. Tax rules usually apply to crypto. Viewing keys and exports from your wallet make this easier.

Major exchanges that list ZEC

ExchangeNotes (as reported in 2026)
GeminiSupports withdrawals to shielded addresses. ZEC is not offered in every region.
CoinbaseLists ZEC. Withdrawals reported as transparent only.
KrakenMany trading pairs. Transparent addresses only; delisted in some countries.
BinanceLists ZEC on its global platform, which is not available to US residents.
OKXRemoved ZEC in early 2024 and relisted it in November 2025.
Listed alphabetically after Gemini's shielded support. Inclusion is not an endorsement.

Routes that do not use an exchange account

If you already own another cryptocurrency, the Zodl wallet can swap it into shielded ZEC through NEAR Intents, and several other wallets and swap services listed in the official z.cash ecosystem directory offer similar conversions. Rates and fees vary, and you are responsible for checking a service's reputation.

Investors who want price exposure through a brokerage account, without holding coins, can look at the Grayscale Zcash ETF page. A fund share is not the same as owning ZEC: you cannot spend or shield it, and the fund charges an annual fee.

12 · The other side

Risks and criticisms

An honest guide has to cover what can go wrong. Each concern below is paired with the response usually given by Zcash's supporters, so you can weigh both.

Hidden bugs in complex cryptography

ConcernShielded pools hide balances, so a flaw could let someone mint coins unseen. Serious flaws were found in 2018 (Sprout) and 2026 (Orchard); the second sat undetected for four years.
ResponseBoth were fixed before any known exploit. Turnstiles between pools cap the damage, and Ironwood's circuit was formally verified. Zcash's own developers say no guarantee is absolute.

Regulation and delistings

ConcernExchanges in Japan, South Korea and elsewhere have dropped privacy coins. European anti-money-laundering rules that apply from July 2027 are expected to restrict regulated firms from handling them.
ResponseOptional privacy and viewing keys have kept ZEC on major regulated venues, the SEC closed its inquiry in 2026, and a US spot ETF now exists. How Europe treats Zcash in practice is still unclear.

Most coins are not shielded

ConcernRoughly seven in ten ZEC sit in transparent addresses. A smaller shielded crowd means weaker anonymity, and careless use can be traced.
ResponseThe shielded share has grown several-fold, and newer wallets shield by default. Critics who want privacy to be mandatory often prefer Monero.

Governance turbulence

ConcernIn January 2026 the entire core team quit ECC in a public dispute with its non-profit board. Funding from block rewards has been argued over since launch.
ResponseThe network kept running, the team regrouped as ZODL, and development is now spread across more independent organisations than before.

Mining concentration

ConcernIn 2023 a single pool briefly held more than half the hash power, the threshold for a "51% attack". Specialised hardware limits who can mine.
ResponseThe number of miners winning blocks has since risen, and Crosslink is designed to add finality that mining alone cannot give.

Price volatility

ConcernZEC has swung violently in both directions, including a fall of about half in the days after the 2026 Orchard disclosure. ETF flows now add another source of swings.
ResponseVolatility is common to most cryptocurrencies. Nobody can reliably predict prices, and this site does not try.

Trusted setup history

ConcernThe 2016 and 2018 ceremonies required trusting that at least one participant destroyed their secret.
ResponseOrchard and Ironwood use Halo 2, which needs no trusted setup, and NU7 is scheduled to end normal use of the oldest pool.

Illicit use

ConcernAny private payment system can be misused, and law enforcement agencies have flagged privacy coins.
ResponseA 2020 RAND study found Zcash had only a minor presence on dark-web markets. Supporters argue financial privacy is normal and legitimate, as with cash.

13 · Jargon, decoded

Glossary

Type to filter. Every term used on this page is explained here in a sentence or two.

Block reward
The newly created ZEC paid out with each block, mostly to the miner who found it.
Crosslink
A proposal to add a proof-of-stake finality layer on top of Zcash's existing mining.
ECC
Electric Coin Co., the company that launched Zcash in 2016 and led development until 2026.
Equihash
The proof-of-work algorithm Zcash miners use.
Founders' Reward
The 20% of block rewards that went to founders, investors and early organisations from 2016 to 2020.
Halo 2
The proof system behind Orchard and Ironwood. It needs no trusted setup.
Halving
The scheduled 50% cut in new coin issuance that happens about every four years.
Ironwood
The newest shielded pool, activated in July 2026 to replace Orchard with a formally verified design.
Lockbox
A protocol-level reserve that collected part of each block reward from 2024 until the community decided how to spend it.
Memo
An encrypted note attached to a shielded payment that only the recipient can read.
NEAR Intents
A cross-chain system where you state the swap you want and competing "solvers" fulfil it. Used inside the Zodl wallet.
Network upgrade (NU)
A coordinated change to Zcash's rules that all nodes adopt at a set block height, such as NU5 or NU7.
Note
An encrypted record of value in a shielded pool. Roughly the shielded equivalent of a coin or banknote.
Nullifier
A unique marker published when a note is spent, stopping it being spent again without revealing which note it was.
Orchard
The shielded pool introduced in 2022. Closed to new deposits in 2026 after a flaw was found and fixed.
Proof of stake
A way to secure a blockchain where participants lock up coins rather than burn electricity.
Proof of work
Securing a blockchain by having miners compete to solve computational puzzles.
Sapling
The 2018 upgrade and shielded pool that made private payments practical on phones.
Selective disclosure
Choosing to reveal specific transaction details to a specific party, usually with a viewing key.
Shielded address
An address whose balance and transactions are encrypted on the blockchain.
Shielded pool
The total of all coins held in one generation of shielded addresses.
Sprout
The original 2016 shielded pool, now being phased out.
Tachyon
A proposed redesign aimed at making shielded transactions much smaller and faster.
Transparent address
A public, Bitcoin-style address beginning with "t".
Trusted setup
A one-time ceremony that generates public parameters for a proof system and must destroy the secret by-products.
Turnstile
A public counter of the value entering and leaving a shielded pool, used to detect counterfeiting.
Unified address
A single address beginning with "u" that can contain several address types at once.
Viewing key
A key that lets someone see a shielded address's transactions without being able to spend from it.
Zatoshi
The smallest unit of ZEC: 0.00000001 ZEC.
Zebra
The Zcash Foundation's node software, written in Rust.
ZEC
The ticker symbol for the Zcash coin.
Zero-knowledge proof
A way to prove a statement is true without revealing any information beyond the fact that it is true.
ZIP
Zcash Improvement Proposal: the formal document format for proposing protocol changes.
zk-SNARK
A very short zero-knowledge proof that is quick to verify. The core technology of Zcash.
ZODL
Zcash Open Development Lab, formed in 2026 by the former ECC team. Also the name of its wallet (Zodl).
ZSA
Zcash Shielded Assets: a proposal to support other tokens with Zcash's privacy.

14 · Test yourself

The Zcash quiz

Ten questions, each with an explanation. No sign-up, nothing stored.

15 · Quick answers

Frequently asked questions

Short answers to the questions people most often ask about Zcash.

What is Zcash in simple terms?

Zcash is a cryptocurrency based on Bitcoin's design that adds optional privacy. With a shielded transaction, the sender, receiver and amount are encrypted, yet the network can still confirm the payment is valid using zero-knowledge proofs. Its coin is called ZEC and the supply is capped at 21 million.

Who created Zcash?

Zcash grew out of the Zerocoin and Zerocash research by seven scientists: Eli Ben-Sasson, Alessandro Chiesa, Christina Garman, Matthew Green, Ian Miers, Eran Tromer and Madars Virza. Zooko Wilcox led the company that built and launched the network on 28 October 2016.

Is Zcash anonymous?

It can be private, but it is not automatic. Shielded transactions hide the sender, receiver and amount. Transparent transactions are fully public, like Bitcoin. Your privacy depends on using shielded addresses and avoiding patterns that link your shielded and transparent activity.

How is Zcash different from Bitcoin?

Both have a 21 million cap, proof-of-work mining and halvings. The main difference is privacy: every Bitcoin transaction is public, while Zcash lets users encrypt transaction details. Zcash also has faster blocks and directs part of its block reward to community-governed development funding.

How is Zcash different from Monero?

Monero makes every transaction private by default using ring signatures and stealth addresses. Zcash makes privacy optional and uses zero-knowledge proofs. Zcash has a fixed supply cap while Monero has a small permanent issuance. Optional privacy has generally made Zcash easier for regulated exchanges to list.

What was the 2026 Orchard vulnerability?

In late May 2026 a researcher found a flaw in the Orchard shielded pool that could in theory have let an attacker create counterfeit ZEC. Developers fixed it within days through an emergency upgrade and reported no evidence of exploitation. In July 2026 the Ironwood upgrade moved users to a new, formally verified pool with a turnstile that lets anyone audit the supply.

Who develops Zcash now?

Several independent groups. As of October 2026 the main ones are ZODL (the former Electric Coin Co. team), the Zcash Foundation, Shielded Labs, Project Tachyon with Valar Group, and teams funded by Zcash Community Grants. Electric Coin Co. itself concluded operations in 2026.

What is the best Zcash wallet?

There is no single best wallet. For shielded use on a phone, Zodl (formerly Zashi), Zingo and YWallet are established choices. Keystone and Ledger offer hardware options with shielded support. Whichever you choose, download it from the developer's official site and back up your recovery phrase offline.

Where can I buy Zcash?

ZEC is listed on major exchanges including Gemini, Coinbase, Kraken, Binance and OKX, though availability varies by country. People who already hold crypto can also swap into shielded ZEC inside wallets such as Zodl. Check local rules and the exchange's own site before you start.

Is Zcash legal?

Holding and using Zcash is legal in most countries, but rules differ and are changing. Some jurisdictions restrict exchanges from offering privacy coins, and new European Union rules that apply from July 2027 are expected to affect them. This is general information, not legal advice.

Will Zcash move to proof of stake?

Not yet decided. A proposal called Crosslink would add a proof-of-stake layer alongside mining and has been running on a test network in 2026. It would need community approval before it could activate, and no date has been set.

Is Zcash a good investment?

This site cannot answer that and does not give financial advice. ZEC is highly volatile and carries technical, regulatory and governance risks described in the risks section. Anyone considering buying should do their own research and consider speaking to a licensed adviser.