News · Science & Technology
Zcash developers set January target for quantum-resistant payments after ‘bunker mode’ scare
Zcash developers plan to add post-quantum signature opcodes to the network’s software in January. These instructions would let Zcash verify hash-based signatures when users approve payments. The goal is to protect spending approvals from a future quantum computer or similar breakthrough that could undermine current wallet keys. Today, a wallet uses a secret key to authorize spending and a matching public key to verify that approval. Transparent addresses initially hide the public key behind a hash. When coins are spent, the public key becomes visible. The proposed replacement uses hashes as the core proof, so defeating current wallet mathematics would not automatically defeat the new signature. January is only the developers’ target for adding the capability. The article gives no confirmed network activation date. The initial work focuses on transparent payments, while shielded payments need separate safeguards because attackers could potentially save encrypted records and try to decrypt them later.
Based on reporting by CoinDesk
What exactly are Zcash developers planning to add in January, and why is it called quantum-resistant?
Zcash developers plan to add post-quantum signature opcodes to the network’s software in January. These instructions would let Zcash verify hash-based signatures when users approve payments. The goal is to protect spending approvals from a future quantum computer or similar breakthrough that could undermine current wallet keys.
Today, a wallet uses a secret key to authorize spending and a matching public key to verify that approval. Transparent addresses initially hide the public key behind a hash. When coins are spent, the public key becomes visible. The proposed replacement uses hashes as the core proof, so defeating current wallet mathematics would not automatically defeat the new signature.
January is only the developers’ target for adding the capability. The article gives no confirmed network activation date. The initial work focuses on transparent payments, while shielded payments need separate safeguards because attackers could potentially save encrypted records and try to decrypt them later.
How much of the Zcash supply is currently held in transparent payments that the initial upgrade would protect?
About 70% of issued ZEC was held in the transparent pool when the figures were calculated. That equals 11.96 million coins out of 16.98 million issued ZEC. These payments are public, much like Bitcoin transactions, so they are the first target for the proposed quantum-resistant upgrade.
The January plan would add signature checks for this transparent side of Zcash. A transparent address initially hides its public key behind a hash, but spending reveals that key. A future attacker with a powerful enough breakthrough could then try to derive the secret key and forge the owner’s approval. Hash-based signatures are intended to replace that vulnerable approval method when the payment is spent.
This does not mean every Zcash payment will be protected immediately. Shielded payments conceal the sender, recipient, and amount, and the article says they require separate work. The scale of the transparent pool explains why developers are addressing it first.
What could happen to a wallet if a future quantum computer—or another breakthrough—could derive its secret key from its public key?
If a future quantum computer or another breakthrough could work backward from a public key to its secret key, an attacker could impersonate the wallet owner. They could create a valid-looking approval for a transaction and spend coins without the owner’s permission. The article says no practical attack on wallet keys has been demonstrated so far.
Zcash transparent addresses initially protect public keys behind hashes. When a user spends, the public key is revealed so the network can check the signature. If the underlying key system were broken, an attacker could use that revealed information to forge approvals. Moving leftover funds to a fresh address hides them behind a new, undisclosed key, but spending later exposes that key too.
The proposed hash-based signatures aim to change this risk. Their security depends on defeating hashes, so a breakthrough against current wallet keys would not automatically defeat them. Shielded payments face a separate concern involving saved encrypted records.
Why does the January target not yet mean that quantum-resistant payments will be active on the Zcash network?
The January target refers to post-quantum signature opcodes landing in Zcash software. An opcode is an instruction that lets the network perform a new check. Adding that capability is different from activating it across the live network, where users and validators must run compatible software and follow an agreed schedule.
Roman Akhtariev wrote that the team plans for the opcodes to land in Zcash in January. The proposed instructions would allow the network to check hash-based signatures for spending approvals. However, the article specifically notes that no confirmed network activation date was mentioned. That leaves the operational launch unresolved.
The distinction matters because a software target does not guarantee that protected payments are immediately available or mandatory. The article reports the developers’ aim, but gives no later date for network-wide activation. Until that schedule is confirmed and implemented, the plan remains preparation rather than active protection.
How do transparent and shielded Zcash payments differ, and why does the proposed upgrade initially focus only on transparent payments?
Transparent Zcash payments work much like Bitcoin transactions: their payment activity is public. Shielded payments conceal the sender, recipient, and amount. The two designs expose different information, so protecting them against future cryptographic attacks requires different solutions rather than one universal upgrade.
The January plan targets transparent payments, where about 11.96 million of 16.98 million issued ZEC sat on Thursday. Transparent addresses initially hide a public key behind a hash, but spending reveals that key. The proposed hash-based signatures are intended to protect the approval once it becomes public during spending.
Shielded payments are not covered by this initial plan. Zcash’s quantum recovery design warns that an attacker could obtain a recipient’s address, save encrypted payment records today, and try to decrypt them after a future mathematical breakthrough. That separate risk explains why shielded payments need additional safeguards.
How can Zcash’s private lookup tool let a wallet check balances without revealing to a server which addresses belong to the same user?
Zcash’s private lookup tool addresses a privacy problem created by using fresh addresses. Fresh addresses can keep public keys hidden until spending, but a wallet still needs to check every balance. A normal server request could reveal which addresses belong to one user by showing the set being checked.
The tool uses private information retrieval. This method lets a database return the requested record without learning which record was requested. A wallet can therefore check balances while withholding a readable list of its addresses from the server. The payments themselves remain public; the privacy applies to the balance lookup.
The feature is separate from the proposed quantum-resistant signatures. Zakura developed the lookup tool, and an experimental version is available through Vizor’s “Private queries” setting. It could make address separation more useful, but the article does not describe it as hiding transactions or protecting shielded payments.
How do public keys, secret keys, digital signatures, and cryptographic hashes normally work together to prove that someone is allowed to spend cryptocurrency?
A cryptocurrency wallet uses a secret key to approve spending. The corresponding public key is shared with the network so it can check whether an approval is valid. The public key should not reveal the secret key, because working backward is supposed to require an impractical amount of computing.
When a payment is authorized, the wallet produces a digital signature using secret data. The network checks that signature with the public key. In transparent Zcash, the address initially hides the public key behind a hash, described in the article as a digital fingerprint designed to be difficult to reverse. Spending reveals the public key and lets the network verify the approval.
The proposed replacement uses hash-based signatures. Their purpose is to make a future forgery require defeating the hashes, rather than merely breaking today’s wallet-key system. Fresh addresses can hide undisclosed keys until they are spent, but they do not remove the need for secure approval checks.
Key Facts:
📌 Post-quantum signature opcodes are targeted for January.
📌 The proposed signatures use hashes to verify spending approvals.
📌 No network activation date has been confirmed.
📌 About seven in 10 issued ZEC sat in the transparent pool.
📌 The transparent pool held 11.96 million ZEC.
📌 Total issued supply was 16.98 million ZEC.
📌 An attacker could forge an owner’s approval.