Bitcoin's rules, new privacy
Zcash began as a modified copy of Bitcoin's code. It keeps the 21 million coin limit, mining and halvings, and adds encryption on top.
An independent guide · Updated October 2026
Zcash is digital money with a fixed 21 million supply, like Bitcoin, that lets you keep the sender, receiver and amount of a payment encrypted while the network still proves the payment is valid.
01 · The short version
If you only read one section, read this one. Four ideas cover most of what makes Zcash different from other cryptocurrencies.
Zcash began as a modified copy of Bitcoin's code. It keeps the 21 million coin limit, mining and halvings, and adds encryption on top.
A shielded transaction hides who paid whom and how much. A transparent one is public, like Bitcoin. Users pick which to use.
The network checks every shielded payment with a zk-SNARK: a tiny proof that the rules were followed, revealing nothing else.
Launched on 28 October 2016, Zcash is now built by several independent teams and the coin trades under the ticker ZEC.
Most blockchains are radically public. Anyone can look up an address and see every payment it has ever made or received, forever. That is useful for auditing, but it is unlike the way cash or a bank account works, where your salary and shopping are not visible to strangers.
Zcash was created to fix that one problem. It offers a kind of digital cash where the ledger is still shared and verifiable by everyone, yet the details of individual payments can be encrypted. The trick is a branch of cryptography called zero-knowledge proofs, which Zcash was the first major cryptocurrency to put into everyday use.
02 · Where it came from
Zcash is one of the few cryptocurrencies that started as peer-reviewed academic research rather than a white paper posted to a forum.
The story starts at Johns Hopkins University. Professor Matthew Green and graduate students Ian Miers and Christina Garman proposed Zerocoin, an add-on to Bitcoin that would let people break the link between coins they received and coins they spent. It worked, but the proofs were large and it could not hide amounts.
The Johns Hopkins group then joined forces with cryptographers from MIT, the Technion and Tel Aviv University who had been developing a compact form of zero-knowledge proof called a zk-SNARK. Their combined design, Zerocash, hid the sender, the receiver and the amount, with proofs small enough to fit comfortably in a block. Its seven authors are still recognised as Zcash's founding scientists.
Turning a paper into working money needed engineers and funding. Zooko Wilcox, a long-time cypherpunk and security engineer, led a start-up (first called the Zerocoin Electric Coin Company, later the Electric Coin Company or ECC) that raised money from early investors and built the software. The network went live on 28 October 2016.
The first version of Zcash's proof system needed a one-time "trusted setup": secret random numbers had to be generated and then destroyed, because anyone who kept them could forge coins. Six people in different locations ran an elaborate ceremony to do this, destroying the computers afterwards. A much larger ceremony with dozens of participants followed for the 2018 Sapling upgrade, and since the 2022 NU5 upgrade Zcash's newest shielded technology has needed no trusted setup at all.
03 · 2013 to 2026
Filter by era to follow the story from a research idea to a network run by several independent organisations.
Matthew Green, Ian Miers, Christina Garman and Aviel Rubin at Johns Hopkins describe a way to add anonymity to Bitcoin.
Seven researchers publish a full design for private payments using zk-SNARKs. It becomes the blueprint for Zcash.
Zooko Wilcox's company announces it will turn Zerocash into a standalone cryptocurrency.
The first Zcash blocks are mined after the six-person trusted setup ceremony. The original shielded pool is later named Sprout.
A separate non-profit is created so that no single company controls the project. Grayscale opens a private Zcash investment trust.
New York's financial regulator approves Zcash trading on Gemini, an early signal that optional privacy could fit inside regulated markets.
A major upgrade makes shielded payments fast and light enough for phones, and introduces viewing keys.
The team reveals it had quietly fixed a counterfeiting flaw in the original Sprout setup. Later that year ECC's Sean Bowe announces Halo, a way to build proofs with no trusted setup.
The block reward halves, the Founders' Reward ends and a community-approved development fund begins. ECC is donated to a non-profit called Bootstrap.
The Orchard shielded pool launches on the Halo 2 proof system, removing the need for trusted setups. One "unified" address can now cover every pool.
One mining pool, ViaBTC, briefly controls more than half of the network's hash power. In December, Zooko Wilcox steps down as ECC's chief executive and Josh Swihart takes over.
The block reward halves again. Part of each block now goes into a protocol "lockbox" to be allocated later.
After years of low prices, ZEC rises many times over in a few weeks as shielded usage climbs and the Zashi wallet adds cross-chain swaps. Several exchanges that had dropped ZEC relist it.
A new funding model gives ZEC holders a direct say over a pool of development money.
The whole ECC staff resigns after a dispute with the Bootstrap board and regroups as the Zcash Open Development Lab (ZODL). The Zashi wallet is renamed Zodl. The US SEC closes an inquiry involving the Zcash Foundation with no action.
ZODL announces a seed round of more than 25 million US dollars. A researcher reports a flaw affecting the old Sprout pool, which is patched before anyone exploits it.
Researcher Taylor Hornby finds a flaw in Orchard's proof circuit that could, in theory, have allowed counterfeit ZEC. An emergency upgrade (NU6.2) fixes it within days. No exploitation is found.
A new, formally verified shielded pool replaces Orchard, and a "turnstile" lets anyone audit the supply. The original zcashd node software is retired.
Grayscale converts its Zcash trust into an exchange-traded fund on NYSE Arca under the ticker ZCSH.
Developers have targeted 5 November 2026 for an upgrade that cuts block time from 75 to 25 seconds. The final decision was due in late October.
04 · Under the hood
You do not need the maths to understand the idea. Start with what an outside observer can see, then look at how the network can check a payment it cannot read.
The same payment, sent three different ways. Use the toggle to switch.
Illustration only. Addresses and values are made up and shortened.
Transparent addresses start with a "t" and behave just like Bitcoin addresses: balances and payments are public. Shielded addresses keep balances and payment details encrypted. Coins held in shielded addresses are said to be in a shielded pool.
Zcash has had four shielded pools as the cryptography improved: Sprout (2016), Sapling (2018), Orchard (2022) and Ironwood (2026). Modern wallets hide this history behind a single unified address, which starts with "u" and bundles the address types a wallet supports.
A zk-SNARK is a short piece of data that proves a statement is true without showing why. For a shielded payment the statement is roughly: "I own unspent coins, I am not spending them twice, and the amounts going in equal the amounts going out." Every node can check that proof in milliseconds, and it learns nothing else.
Shielded does not have to mean secret from everyone. The owner of a shielded address can share a viewing key that lets an accountant, auditor or tax office read its transactions without being able to spend the funds. This "selective disclosure" is a large part of how Zcash argues it can coexist with regulation.
05 · Supply and funding
Zcash copies Bitcoin's monetary schedule: a hard cap of 21 million ZEC, released through mining, with the rate of new coins cut in half roughly every four years.
A simplified model for illustration. It ignores the gentle "slow start" in 2016 and small timing drifts. The live circulating supply is in the stats bar above.
No more can ever exist under the current rules. The smallest unit, one hundred-millionth of a ZEC, is called a zatoshi.
The first halving was on 18 November 2020 and the second on 23 November 2024. The third is expected around November 2028.
New coins go to miners who secure the network. Blocks have arrived about every 75 seconds since 2019; NU7 is scheduled to change this to 25 seconds with a proportionally smaller reward per block, leaving daily issuance unchanged.
| Period | Miners | Other recipients | What changed |
|---|---|---|---|
| 2016 to 2020 | 80% | 20% "Founders' Reward" to founders, investors, employees, the company and the Zcash Foundation | Controversial at launch. It ended at the first halving and totalled about 10% of the eventual supply. |
| 2020 to 2024 | 80% | 7% ECC (via Bootstrap), 5% Zcash Foundation, 8% community grants | A development fund approved by community polling replaced the Founders' Reward. |
| Nov 2024 to Nov 2025 | 80% | 8% Zcash Community Grants, 12% protocol lockbox | NU6 ended direct funding of ECC and the Foundation and parked 12% until the community decided how to use it. |
| Nov 2025 onward | 80% | 8% Zcash Community Grants, 12% coinholder-controlled fund | NU6.1 lets ZEC holders vote on grants from the fund. The arrangement is set to run until the third halving, expected in November 2028. |
The NU7 upgrade also adds a "Network Sustainability Mechanism". As described by developers, most transaction fees would flow into a reserve rather than straight to miners, and that reserve would be paid back out as extra mining rewards from 2031. The aim is to support the security budget as block rewards shrink. The 21 million cap and the halvings stay in place. Details may change before or after activation, so check the official upgrade notes.
06 · Who is involved
Zcash has no chief executive. In 2026 it is developed by several independent groups that share a public process for proposing and approving changes.
The Zcash Open Development Lab was formed in January 2026 by the engineers and product team who left ECC, led by former ECC chief executive Josh Swihart. It builds the Zodl wallet (formerly Zashi) and contributes to the core protocol. It is venture funded rather than paid from block rewards.
ZODL official siteA US public charity founded in 2017. It maintains Zebra, the Rust node software the network now relies on, runs community polling, holds the Zcash trademark, and in 2026 took over the z.cash website and code repositories. Its executive director is Alex Bornstein.
Zcash Foundation official siteA Swiss-based, donation-funded organisation co-founded by Zooko Wilcox. It leads Crosslink (the proof-of-stake proposal), championed Ironwood, and its security review uncovered the 2026 Orchard flaw. Donors have included the Winklevoss twins and Vitalik Buterin.
Shielded Labs official siteA five-person committee elected by the community. It awards grants to independent teams using 8% of block rewards, an arrangement approved to run until the 2028 halving.
Zcash Community Grants siteTachyon is cryptographer Sean Bowe's plan to make shielded payments far smaller and faster. With Valar Group, the team also maintains Zakura, a second full-node implementation released in 2026.
Project Tachyon siteECC launched Zcash in 2016 and led development for nearly a decade. From 2020 it was owned by Bootstrap, a non-profit. After the January 2026 walkout, the official Zcash site describes ECC as having concluded operations in 2026.
ECC's page on z.cashLed the company that launched Zcash and ran ECC until December 2023. Now associated with Shielded Labs, which he co-founded.
Ben-Sasson, Chiesa, Garman, Green, Miers, Tromer and Virza designed the protocol. Several went on to found other zero-knowledge projects.
Discovered Halo, the technique that removed trusted setups, and now leads Project Tachyon.
ECC's chief executive from December 2023 until the team's resignation in January 2026.
Long-time author of the Zcash protocol specification and a co-author of the security proof for Ironwood.
Found the Orchard circuit vulnerability in May 2026 during a review with Shielded Labs. Sits on the Zcash Foundation board.
Executive director of the Foundation, which now stewards Zebra and the z.cash website.
Leads Shielded Labs and co-wrote its public explanations of the Orchard incident with Zooko Wilcox.
Naval Ravikant was among the first investors in the Zcash Company. ZODL's 2026 seed round was reported to include Paradigm, a16z crypto, Coinbase Ventures, Winklevoss Capital and Maelstrom.
Cameron and Tyler Winklevoss, founders of Gemini, funded Cypherpunk Technologies in 2025, a listed company that accumulates ZEC, and donated to Shielded Labs in January 2026.
In 2022 Snowden revealed he had been one of the six participants in the 2016 launch ceremony, taking part under a pseudonym.
07 · What exists around it
Beyond the coin itself there is a growing set of software, services and financial products. Here is the landscape as of October 2026.
Two independent full-node implementations now run the network. The original zcashd software, inherited from Bitcoin's codebase, was retired in July 2026.
The Zodl wallet uses NEAR Intents so users can swap between shielded ZEC and assets such as BTC, ETH or stablecoins, or pay someone in another coin directly from a shielded balance.
An integration with the Flexa payments network lets Zodl users spend ZEC at participating retailers.
Grayscale's ZCSH, listed in August 2026, was announced as the first exchange-traded product with spot ZEC exposure. Cypherpunk Technologies holds ZEC on its balance sheet. Neither gives holders shielded coins.
In 2026 Foundry opened a Zcash mining pool and listed companies bought large fleets of Equihash machines. The number of distinct miners winning blocks has risen since 2025.
ZecHub publishes community-written guides. Changes are debated on the Zcash Community Forum and specified as Zcash Improvement Proposals (ZIPs).
Browse the z.cash ecosystem directoryOne number the community watches closely is the share of ZEC held in shielded pools. Independent analysts put it at a little under 30% of supply in late summer 2026, up from single digits a few years earlier.
08 · What comes next
Zcash upgrades only activate after public specification, testing and community agreement. Dates slip and proposals change, so treat everything below "shipped" as intentions, not promises.
A new shielded pool with a formally verified circuit. The older Orchard pool now only allows withdrawals, and a turnstile caps what can leave it, so the public can confirm no counterfeit coins entered circulation. By the end of August most Orchard funds had already migrated.
Planned for 5 November 2026: 25-second blocks, retirement of old-format transactions (and with them normal spending from the legacy Sprout pool), and the Network Sustainability Mechanism. It introduces no new transaction format, so ordinary wallet users should not need to do anything.
A redesign of how shielded payments are proved and synchronised, aiming for much smaller transactions, wallets that sync almost instantly, and privacy that holds up against future quantum computers. It needs community approval and has no mainnet date.
Shielded Labs' proposal to add a staking-based finality layer on top of mining, so that confirmed transactions cannot be reversed and ZEC holders can earn rewards for securing the chain. An incentivised test network has run during 2026. Activation is a governance decision that has not been made.
Would let other tokens, such as stablecoins, be issued and transferred with Zcash's privacy. The specification exists and integration work continues, but it was left out of NU7 and remains under discussion.
Ironwood added "quantum-recoverable" notes as a safety net. Zakura engineers have said they aim to add quantum-resistant signature options for transparent addresses in early 2027. No activation date is confirmed.
09 · Side by side
Bitcoin is the template Zcash copied. Monero is the other well-known privacy coin, and it takes a very different approach.
| Feature | Zcash (ZEC) | Bitcoin (BTC) | Monero (XMR) |
|---|---|---|---|
| Launched | October 2016 | January 2009 | April 2014 |
| Supply limit | 21 million | 21 million | No hard cap; small permanent "tail" issuance |
| Privacy model | Optional. Shielded or transparent | None built in. Pseudonymous and public | Mandatory for every transaction |
| Privacy technique | Zero-knowledge proofs (zk-SNARKs) | Not applicable | Ring signatures, stealth addresses, confidential amounts |
| What is hidden | Sender, receiver, amount and memo when shielded | Nothing | Sender, receiver and amount |
| Selective disclosure | Yes, through viewing keys | Everything is already public | Yes, through view keys |
| Consensus | Proof of work (Equihash); hybrid proof of stake proposed | Proof of work (SHA-256) | Proof of work (RandomX, CPU-friendly) |
| Block time | 75 seconds (25 scheduled with NU7) | About 10 minutes | About 2 minutes |
| Development funding | Share of block rewards plus donations and venture capital | Donations and sponsors | Community donations |
| Main trade-off | Privacy is only as strong as the number of people who choose to shield | Simple and widely held, but fully traceable | Private by default, but harder for regulated exchanges to list |
10 · Holding ZEC yourself
A wallet stores the keys that control your coins. For Zcash the key question is whether it supports shielded addresses, because many multi-coin wallets only handle transparent ZEC.
The most widely used Zcash-only wallet. Shielded by default, with built-in swaps and cross-chain payments, one-tap migration to Ironwood and Keystone hardware support.
Zodl official siteAn open-source wallet that leans on encrypted memos to give you a private record of your own spending. Supports unified addresses.
Zingo Labs official siteKnown for very fast syncing and power-user features such as multiple accounts and paying many recipients at once. Check its site for current pool support.
YWallet official siteThe first hardware wallet to support shielded ZEC. It pairs with the Zodl app, which builds the transaction while the keys stay offline on the device.
Keystone on z.cashLong supported transparent ZEC. In September 2026 Ledger announced native shielded support in its desktop app, with mobile to follow. Check which device models are supported.
Ledger's shielded Zcash announcementSupports transparent ZEC addresses only at the time of writing, so balances held this way are publicly visible on the blockchain.
Trezor official siteA self-custody wallet for many coins that supports shielded Zcash, useful if you want ZEC alongside other assets in one app.
Edge official siteA multi-currency, self-custody wallet listed in the official ecosystem directory as shielded by default for Zcash.
Unstoppable official siteOnce a popular shielded wallet. Reviewers reported in 2026 that it could no longer send ZEC after network upgrades. Existing users can restore their seed phrase in a maintained wallet.
Nighthawk Wallet site11 · Getting some
This is a neutral walkthrough, not a recommendation to buy. Availability depends heavily on where you live, and it changes. Always confirm on the exchange's own site.
| Exchange | Notes (as reported in 2026) |
|---|---|
| Gemini | Supports withdrawals to shielded addresses. ZEC is not offered in every region. |
| Coinbase | Lists ZEC. Withdrawals reported as transparent only. |
| Kraken | Many trading pairs. Transparent addresses only; delisted in some countries. |
| Binance | Lists ZEC on its global platform, which is not available to US residents. |
| OKX | Removed ZEC in early 2024 and relisted it in November 2025. |
If you already own another cryptocurrency, the Zodl wallet can swap it into shielded ZEC through NEAR Intents, and several other wallets and swap services listed in the official z.cash ecosystem directory offer similar conversions. Rates and fees vary, and you are responsible for checking a service's reputation.
Investors who want price exposure through a brokerage account, without holding coins, can look at the Grayscale Zcash ETF page. A fund share is not the same as owning ZEC: you cannot spend or shield it, and the fund charges an annual fee.
12 · The other side
An honest guide has to cover what can go wrong. Each concern below is paired with the response usually given by Zcash's supporters, so you can weigh both.
13 · Jargon, decoded
Type to filter. Every term used on this page is explained here in a sentence or two.
14 · Test yourself
Ten questions, each with an explanation. No sign-up, nothing stored.
15 · Quick answers
Short answers to the questions people most often ask about Zcash.
Zcash is a cryptocurrency based on Bitcoin's design that adds optional privacy. With a shielded transaction, the sender, receiver and amount are encrypted, yet the network can still confirm the payment is valid using zero-knowledge proofs. Its coin is called ZEC and the supply is capped at 21 million.
Zcash grew out of the Zerocoin and Zerocash research by seven scientists: Eli Ben-Sasson, Alessandro Chiesa, Christina Garman, Matthew Green, Ian Miers, Eran Tromer and Madars Virza. Zooko Wilcox led the company that built and launched the network on 28 October 2016.
It can be private, but it is not automatic. Shielded transactions hide the sender, receiver and amount. Transparent transactions are fully public, like Bitcoin. Your privacy depends on using shielded addresses and avoiding patterns that link your shielded and transparent activity.
Both have a 21 million cap, proof-of-work mining and halvings. The main difference is privacy: every Bitcoin transaction is public, while Zcash lets users encrypt transaction details. Zcash also has faster blocks and directs part of its block reward to community-governed development funding.
Monero makes every transaction private by default using ring signatures and stealth addresses. Zcash makes privacy optional and uses zero-knowledge proofs. Zcash has a fixed supply cap while Monero has a small permanent issuance. Optional privacy has generally made Zcash easier for regulated exchanges to list.
In late May 2026 a researcher found a flaw in the Orchard shielded pool that could in theory have let an attacker create counterfeit ZEC. Developers fixed it within days through an emergency upgrade and reported no evidence of exploitation. In July 2026 the Ironwood upgrade moved users to a new, formally verified pool with a turnstile that lets anyone audit the supply.
Several independent groups. As of October 2026 the main ones are ZODL (the former Electric Coin Co. team), the Zcash Foundation, Shielded Labs, Project Tachyon with Valar Group, and teams funded by Zcash Community Grants. Electric Coin Co. itself concluded operations in 2026.
There is no single best wallet. For shielded use on a phone, Zodl (formerly Zashi), Zingo and YWallet are established choices. Keystone and Ledger offer hardware options with shielded support. Whichever you choose, download it from the developer's official site and back up your recovery phrase offline.
ZEC is listed on major exchanges including Gemini, Coinbase, Kraken, Binance and OKX, though availability varies by country. People who already hold crypto can also swap into shielded ZEC inside wallets such as Zodl. Check local rules and the exchange's own site before you start.
Holding and using Zcash is legal in most countries, but rules differ and are changing. Some jurisdictions restrict exchanges from offering privacy coins, and new European Union rules that apply from July 2027 are expected to affect them. This is general information, not legal advice.
Not yet decided. A proposal called Crosslink would add a proof-of-stake layer alongside mining and has been running on a test network in 2026. It would need community approval before it could activate, and no date has been set.
This site cannot answer that and does not give financial advice. ZEC is highly volatile and carries technical, regulatory and governance risks described in the risks section. Anyone considering buying should do their own research and consider speaking to a licensed adviser.
16 · Check our work
These are the references used to write and fact-check this page in October 2026. Primary sources come first.