loading fonts

Zcash: Private Money, Public Proof

00 · The glass coin

Bitcoin made money verifiable. It also made it visible. Every coin carries its full history in public: every address, every amount, forever.

01 · The glass ledger

Pseudonymous isn’t private. Chain analysis links addresses that are spent together into one owner, and coins with a traceable past can be flagged, which makes them less interchangeable than cash.

02 · Zerocash

In 2014 seven cryptographers published Zerocash: a ledger that checks the math without seeing the money. Zcash launched on 28 October 2016 as the first practical application of zk-SNARKs. Its block 0 pays zero ZEC to the same public key as Bitcoin’s block 0.

03 · Zero-knowledge

A zero-knowledge proof convinces a verifier that a statement is true while revealing nothing beyond that fact. Each round a cheater survives only by luck, so twenty rounds leave about a one-in-a-million chance.

04 · The shield

Seen by no one. Verified by everyone. Transparent Zcash addresses work like Bitcoin’s; shielded transactions encrypt sender, receiver and amount, and every one is still verified by a zero-knowledge proof. Viewing keys let owners disclose their own transactions when they choose.

05 · Notes

Seal the coin. Publish only the seal. Shielded value lives in notes: who can spend it, how much it is worth, a random seed and an optional private memo. The chain never sees the note — only a 32-byte commitment to it, and an encrypted copy that only the right keys can open.

06 · The commitment tree

One leaf among four billion. Every note commitment becomes a leaf in its pool’s append-only tree, 32 levels deep. To spend, you prove your leaf connects to an earlier root of the tree without revealing which leaf is yours.

07 · Nullifiers

Spend it once. Never say which. Spending a note publishes its nullifier, a tag only the owner’s keys can compute. Every full node keeps the set of nullifiers it has seen, and a repeated one is rejected, so a note can be spent only once.

08 · Hidden balances

The scale balances. The weights stay hidden. Every amount is locked inside a value commitment, and commitments can be added and subtracted without being opened, so every node checks that inputs equal outputs plus the fee without learning a single amount.

09 · The proof

An entire computation, folded into 192 bytes. A zk-SNARK turns every rule of a shielded spend into equations and proves they all hold, revealing nothing else. Zcash’s Sapling pool (2018) proves each spend in 192 bytes; its newer Orchard pool (2022) uses Halo 2, which needs no trusted setup at all.

10 · Keys and viewing keys

Private to the world. Visible to whom you choose. One 32-byte spending key derives keys that spend, keys that can only look, and about 2⁸⁷ unlinkable addresses. A viewing key lets an auditor read your transactions but never spend them.

11 · The ceremony and the halo

First, six people destroyed a secret. Then came proofs that need none. Zcash’s first proofs needed a one-time setup whose secret had to be destroyed; in 2019 its engineers found the first practical way to build proofs that verify other proofs with no trusted setup, which went live for Orchard in 2022 as Halo 2.

12 · The turnstile

The amounts are hidden. The total never is. Every coin entering or leaving a shielded pool is counted in public, and no block may push any pool below zero. In 2026 a researcher found a gap in the checks inside the proofs of Orchard, then Zcash’s newest pool; within days it was paused and fixed, with no evidence it was ever exploited. Orchard was then sealed and a new pool, Ironwood, opened, so every coin leaving Orchard passes the turnstile.

13 · Work and supply

Mined in the open. Capped at 21 million. Every block carries an Equihash proof of work. Issuance halves about every four years, and under today’s rules at most 20,999,999.8152 ZEC will ever exist.

14 · Verify everything

Private to everyone. Verifiable by anyone. Every exact check in this story runs again in your browser, against Zcash’s block 0 and its official test vectors.