Report Summary
Bitcoin succeeded as “digital gold,” but failed as private money
It achieved permissionless value transfer, but full ledger transparency, institutional capture, and regulatory friendliness mean Bitcoin no longer fulfills the cypherpunk goal of financial privacy or sovereignty.The macro environment increasingly rewards privacy, not just scarcity
Rising surveillance, AI-driven financial monitoring, capital controls, and asset seizures make non-debasable and non-surveillable assets more relevant than ever. Scarcity alone is no longer enough.Bitcoin is effectively locked out of meaningful privacy upgrades
Cultural ossification, technical inertia, and reliance on auditability for institutional adoption make protocol-level privacy on Bitcoin politically and practically impossible.Zcash solves the privacy–integrity tradeoff with cryptography, not trust
Using zero-knowledge proofs, Zcash preserves monetary integrity without transparency. Supply correctness is enforced mathematically, not by public inspection, offering true encryption rather than obfuscation.Zcash’s long-standing thesis is finally becoming practical and visible
With trusted setup eliminated, mobile-first private UX, and easy non-custodial access, Zcash has crossed from “theoretically superior” to “actually usable,” positioning it as a private, quantum-aware complement to Bitcoin rather than a replacement.Zcash now has a credible path to scale without sacrificing privacy
Tachyon fundamentally breaks the assumed privacy–scalability tradeoff by shrinking shielded transactions to Bitcoin-like sizes, eliminating unbounded state growth, and preserving ledger indistinguishability. If delivered, Zcash can support real-world usage while staying fully private.Zcash is proactively future-proofing itself while competitors aren’t
The protocol is actively addressing quantum threats in the correct order: protecting historical privacy first, adding emergency recoverability, and then upgrading soundness. Bitcoin has no comparable roadmap, and Monero’s privacy is structurally vulnerable to quantum de-anonymization.Zcash is emerging as the only privacy asset with regulatory and institutional durability
The SEC investigation closed with no action, ZEC remains listed on major regulated exchanges, Grayscale is pursuing a spot ETF, and high-signal allocators (Winklevoss twins, VanEck, Naval) are publicly backing the thesis. Mandatory-privacy competitors have largely been pushed out of regulated markets.The shielded pool is the product—and it’s accelerating
Shielded supply grew from ~11% to ~30% in one year, creating a privacy flywheel and acting as a supply sink. This metric reflects real adoption, not narrative momentum, and its continued growth would materially strengthen Zcash’s store-of-value case.Zcash represents an asymmetric bet on private, sovereign money
Downside: it remains a niche privacy tool. Upside: it becomes the encrypted store of value that Bitcoin never became, capturing a meaningful share of sovereignty-driven demand currently split between BTC, gold, and Monero. The risk/reward is skewed, not symmetric.
Bitcoin has three problems no one wants to talk about.
First, it’s been co-opted. What started as a cypherpunk experiment in financial sovereignty has become a line item in Blackrock’s portfolio, a strategic reserve asset for the US government, and a political talking point for the Trump administration. Nearly 9% of all BTC now sits in ETFs or government treasuries. The asset that was supposed to exist outside the system has been absorbed by it.
Second, it was never private. Every transaction, every balance, every send and receive, permanently etched on a public ledger for anyone to analyze. Pseudonymity was always a weak substitute for privacy, and the chain analysis industry has spent a decade proving it. If your threat model includes anyone with resources and motivation, Bitcoin’s transparency is a feature for them, not for you.
Third, and this one’s newer: it may not survive the quantum era intact. Google’s Willow chip put quantum computing back in the headlines, but the underlying concern has been building for years. Bitcoin’s cryptographic foundations were state of the art in 2009. They’re increasingly uncertain for 2039. And Bitcoin Core’s track record on proactive upgrades is, to put it generously, glacial. For an asset positioning itself as a multi-generational store of value, “the developers will figure it out when they need to” is a significant asterisk.
To be clear, I’m still long Bitcoin. It remains the Schelling point for digital scarcity, the most liquid crypto asset, and the one with genuine institutional rails. Those advantages compound over time. Nothing I’m about to say changes that.
But step back for a second. Something doesn’t add up.
We’re living through the most favorable macro backdrop for a sovereign store of value in a generation. Currency debasement is accelerating. Trust in institutions is collapsing. Governments are getting more aggressive with financial surveillance, from CBDC pilots to California-style asset seizure regimes. AI is about to supercharge the state’s ability to monitor and control capital flows. The case for an asset that can’t be debased, surveilled, or confiscated has never been stronger.
Gold understood the assignment. It’s ripped, and continues to rip, to all-time highs.
Bitcoin? Underperforming the Nasdaq. Underperforming gold. Struggling to hold momentum despite ETF inflows and a friendly administration.
Maybe the market is telling us something. Maybe an asset that’s been absorbed into the traditional financial system, that offers no real privacy, and that carries unresolved quantum risk doesn’t fully scratch the itch that this macro moment demands. Maybe “digital gold” isn’t enough when the original thesis was “digital freedom.”
Ray Dalio about Bitcoin:
“I have a small percentage of Bitcoin I’ve had forever, like 1% of my portfolio. I’ve said the same thing over and over again about Bitcoin. I think the problem of Bitcoin is it’s not going to be a reserve currency for major countries because it can be… pic.twitter.com/UWgtxa06fR
— *Walter Bloomberg (@DeItaone) November 20, 2025
This is where Zcash enters the conversation.
If you believe the demand for a truly private, sovereign store of value is only going to increase from here, and you look at the options available, Zcash is the only asset that was purpose-built for this from day one. Not privacy bolted on as an afterthought. Not obfuscation that sophisticated analysis can pierce. Actual encryption. Mathematical guarantees. With a credible path to quantum resistance already in development.

Two things are colliding: a world that’s becoming less private by the day, and an asset specifically engineered for that world finally becoming usable. The outperformance isn’t random but a consequence of the times.
The thesis: Zcash as the private, quantum-resistant complement to Bitcoin. Not a replacement, but a hedge against its blind spots. An insurance policy for the possibility that the cypherpunk vision still matters.
The Cypherpunk Vision That Bitcoin Abandoned
To understand why Zcash matters, you have to understand what Bitcoin was supposed to be and where it has fallen short.
The idea of private digital money is far from new. It dates back to 1982, when David Chaum, then a PhD candidate in computer science, published “Blind Signatures for Untraceable Payments.”

The core insight was elegant: a bank could sign a digital token without seeing its content, and when spent, the bank could verify validity through its own signature but couldn’t link the spending to the withdrawal.
Chaum later founded DigiCash in 1989 to commercialize this, and several banks piloted the technology. DigiCash failed (the timing was wrong, before widespread internet commerce), but Chaum had proven that private digital money was possible.
The cypherpunks then picked up the thread. In 1992, a group of cryptographers, hackers, and libertarians started meeting in the San Francisco Bay Area and communicating via an electronic mailing list. Their founding premise was that in the digital age, privacy would not be granted by governments or corporations. It would have to be built, deployed, and defended by individuals using cryptographic tools.

As Eric Hughes wrote in A Cypherpunk’s Manifesto in 1993: “Privacy is necessary for an open society in the electronic age… We must defend our own privacy if we expect to have any… Cypherpunks write code.”
The mailing list became a crucible for the ideas that would shape the next three decades. Members included Julian Assange (before WikiLeaks), Hal Finney (who would later receive the first Bitcoin transaction), Nick Szabo (who proposed bit gold), and Wei Dai (whose b-money proposal was cited by Satoshi). Zooko Wilcox, who would later co-found Zcash, was also on the list.
Bitcoin: Permissionless, But Not Private
When Satoshi published the Bitcoin whitepaper in 2008, it emerged directly from the cypherpunk tradition. Bitcoin solved the double-spend problem without a central authority. For the first time, people could transfer value over the internet without banks, intermediaries, or permission.
But there was a glaring problem: Bitcoin wasn’t private.
The blockchain is entirely public. Every transaction, every address, every balance is visible to anyone who cares to look. Satoshi acknowledged this limitation, suggesting users could preserve some privacy by generating new addresses for each transaction. That was a weak mitigation then. It’s nonexistent now, given the sophistication of chain analysis.

Satoshi also acknowledged something more telling. In a 2010 Bitcointalk post, he wrote: “If a solution was found, a much better, easier, more convenient implementation of Bitcoin would be possible.” He was talking specifically about privacy. The cryptography to solve it simply didn’t exist yet. Zero-knowledge proofs were still academic, impractical for real-world use.
So the early Bitcoiners made a bet: privacy would come later, as the math matured. In the meantime, permissionless was enough.
If you go back through the Bitcointalk archives, it’s clear that many early Bitcoiners believed that if stronger cryptographic tools had existed at the time, Bitcoin would have implemented them from day one. That sentiment never fully went away. And as ZK proving systems have matured over the past decade, it’s resurfaced in a very real way.
But Bitcoin never added privacy. And it probably never will.
Two forces killed the possibility.
The Ossification Problem
Bitcoin ossified. The community coalesced around “don’t change Bitcoin” as a core value, treating any protocol modification as an existential threat to the network’s credibility. This conservatism is both Bitcoin’s greatest strength (stability, predictability, Schelling point for “digital gold”) and its greatest weakness (inability to adapt to new threats or opportunities).
When the Zerocoin proposal came to Bitcoin Core in 2013, it offered a cryptographically sound privacy layer designed specifically for Bitcoin. It could have become Bitcoin’s native shielded transaction system, or at least a sidechain that preserved the asset’s cypherpunk roots. Bitcoin Core rejected it. Not because it didn’t work, but because the culture had already shifted toward risk-aversion and ossification.

The team behind Zerocoin eventually left and created Zcash, implementing the privacy that Bitcoin refused to adopt.
To be fair Bitcoin’s ossification isn’t all bad. The resistance to change is also what gives it credibility as a stable, predictable monetary base. And on quantum specifically, I do think Bitcoin will eventually adapt. When the threat becomes undeniable, the community will mobilize. It’ll be messy and slow, but it’ll happen. Survival instincts tend to win out.
Privacy is different. There’s no future scenario where Bitcoin becomes private at the protocol level. The transparency is too deeply embedded, both technically and culturally. The institutional adoption, the regulatory acceptance, the ETF approvals, all of it was built on the premise that Bitcoin is auditable. That’s not changing.
Which, in my view, opens the door for another store of value within crypto. One that offers what Bitcoin can’t: genuine privacy, built from the ground up. Not as a replacement for BTC, but as a complement to it. A sovereign asset for a world where sovereignty increasingly requires invisibility.
But this raises an obvious question: if privacy is so valuable, why didn’t Bitcoin just build it in from the start? The answer isn’t just cultural resistance. There’s a genuine technical tradeoff at the heart of it, one that involves what cryptographers call “monetary base integrity.”
The Privacy-Integrity Tradeoff
In a transparent system like Bitcoin, anyone can audit the entire ledger. Every transaction, every balance, every block is visible. If someone exploits a bug to create coins out of thin air, the network can see the violation and respond.
This actually happened in 2010 with an integer overflow bug that created 184 billion BTC.
10 years ago a bug was exploited to create 184 billion BTC. Due to the ability to easily audit the supply it was noticed quickly; bug was patched in 5 hours.
Several protocols have since suffered inflation bugs that went unnoticed for months.
Independent auditability has value.
— Jameson Lopp (@lopp) August 14, 2020
Because Bitcoin is transparent, the community could see exactly what happened and coordinate a rollback.
In a truly private system, this kind of audit isn’t possible through transparency. You can’t see the transactions. You can’t check the balances. So how do you verify no one is counterfeiting?
The answer, it turns out, is zero-knowledge proofs. What most people get wrong though is that ZK proofs don’t necessarily trade integrity for privacy. They’re actually an integrity mechanism. Each Zcash transaction that changes the shielded pool comes with a cryptographic proof that the change is valid, that it doesn’t counterfeit ZEC. Verifying all the zero-knowledge proofs is auditing the ledger. It’s a new technology for proving the integrity of the monetary base without revealing private details of the transactions.
Most ZK work happening outside of Zcash, in Ethereum, Starkware, and other communities, is actually focused on provable integrity. The cryptographic proof techniques they use don’t even come with full-strength privacy. Privacy is one application of ZK. Integrity is the foundation.
But in the early 2010s, this was new cryptography. Untested at scale. Bitcoin was unwilling to switch to a newfangled cryptographic auditing mechanism, one which would preserve user privacy but could have undiscovered flaws. That was a reasonable decision given the tradeoffs at the time. Transparency wasn’t just a limitation; it was a feature that protected the integrity of the monetary base.
But it meant abandoning the cypherpunk vision that animated Bitcoin’s creation: money that couldn’t be surveilled, couldn’t be censored, couldn’t be controlled.
That vision didn’t die. It just moved to a different project.
The Cypherpunk Continuation
In 2014, a paper titled “Zerocash: Decentralized Anonymous Payments from Bitcoin” showed how to make it work. The author list included cryptographers who had been working on a new generation of zero-knowledge proofs: Eli Ben-Sasson, Alessandro Chiesa, and others who would later become foundational figures in the ZK space.
The key innovation was zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge). These were zero-knowledge proofs that were small (a few hundred bytes), fast to verify (milliseconds), and expressive enough to prove complex statements about hidden data. With zk-SNARKs you could prove not just that you own a valid coin, but that an entire transaction is valid, without revealing the sender, recipient, or amount. Privacy and integrity, together.

Zooko Wilcox had been in the privacy and cryptography space for decades. He had worked at DigiCash in the 1990s and been involved with decentralized storage projects. When the Zerocash paper was released, it was an immediate fit. In 2016, Wilcox founded the Zcash Company (later renamed Electric Coin Company) and assembled a team to turn Zerocash into a production cryptocurrency.
On October 28, 2016, the Zcash genesis block was mined. Thirty-four years after David Chaum’s first paper, the dream of untraceable digital money was running on a live network.
Zcash: The Market Finally Needs What It Always Had
Zcash isn’t new, it’s been live for almost nine years. So what’s different about this moment that could explain both the recent outperformance and justify continued strength from here?
Part of the answer is what I described above: the macro environment has shifted in ways that make privacy more salient. Institutional capture of Bitcoin. Governments getting more aggressive with financial controls. AI supercharging the state’s ability to monitor every transaction. The sense that the original cypherpunk promise went unfulfilled.
But there’s also a more specific catalyst, and it has to do with Zcash finally becoming usable.
A few things have changed in Zcash since Jan 2024:
– @zashi_app, launched world-class UX for ZEC
– @ShieldedLabs, new team of core contributors
– integration with @FlexaHQ for retail payments
– 2nd Zcash halving
– fundamental gov change (no ECC/ZF control)
– no direct dev fund…— Josh Swihart 🛡 (@jswihart) October 23, 2025
For years, Zcash’s technical superiority was undermined by practical problems. The cryptography was too slow. You couldn’t run shielded transactions on a mobile phone. And the protocol required a “trusted setup,” a ceremony where cryptographic parameters were generated by multiple participants. The design was safe as long as even one participant destroyed their secret input. But if every participant colluded and retained their secrets, they could theoretically counterfeit coins undetectably.

The trusted setup was a legitimate concern. Even though the ceremony was designed with multiple independent participants (the setup would be secure as long as any single participant destroyed their secrets), it created uncertainty. Some users weren’t willing to trust that the ceremony was conducted correctly. The theoretical risk of undetectable inflation, however small, was enough to keep them away.
Three things changed that made Zcash actually usable for normal people.
- First, the trusted setup was eliminated. The Halo proving system, deployed in the Orchard upgrade in 2022, uses recursive zero-knowledge proofs that don’t require any ceremony-generated parameters. There’s no ceremony, no toxic waste, no trust assumptions about events that happened years ago. The security is mathematical, not dependent on trusting that strangers destroyed their secrets.
- Second, mobile-friendly wallets arrived. Zashi, along with hardware wallet support and the Near Intents integration, made Zcash functional on phones. This sounds trivial but it wasn’t. Shielded transactions require significant computation, and getting that to run smoothly on mobile hardware took years of cryptographic optimization.

- Third, and most importantly, the ZK layer became invisible to users. You don’t need to understand zero-knowledge proofs to use Zashi. You don’t need to care about the cryptography. You just use it like any other wallet, and your transactions are private by default. Zashi automatically shields any transparent funds before spending. The complexity is hidden.
This last point is crucial. The ZK proving system is what creates Zcash’s moat (more on this below), but it was never going to drive adoption as long as users had to understand it. The moat had to be hidden behind good UX. Once it was, Zcash became something you could actually recommend to normal people.
The market noticed quickly. The Near Intents integration in October was the unlock, giving users a frictionless way to rotate into ZEC from any chain without touching a centralized exchange.

Since the integration went live, ZEC has consistently ranked in the top 5 assets by volume on Near Intents, often trailing only BTC, ETH, and major stablecoins. At times it’s actually outpaced them all.

In the last 30 days alone, ZEC has done $285M in volume on Near Intents, over 80% of BTC’s $348M. All-time, it’s $1.3B vs $1.5B. A top-30 asset running neck-and-neck with the largest asset in crypto.
Before October 2025, ZEC volume on Near Intents was negligible. After the integration, it exploded. When it became trivial for users to move into ZEC in a fully non-custodial, private way, they started doing it.
First Principles: Zcash’s Cryptographic Design
For Zcash, the cryptographic design is the moat. It determines whether the privacy guarantees are real or theater, whether the asset can credibly serve as a sovereign store of value, and whether the protocol can scale without compromising its core properties. The following sections break down how this actually works.
For anyone evaluating Zcash as a long-term holding, this is where the diligence happens, beyond narrative, beyond price action, at the level of the underlying technology itself.
Encryption vs. Obfuscation
There are basically two approaches to privacy in cryptocurrency.
The first is obfuscation. You identify sources of information leakage (sender addresses, receiver addresses, amounts) and you add features to obscure them. Stealth addresses hide recipients. Ring signatures mix your transaction with decoys. Confidential transactions encrypt amounts. The more fancy-sounding features you stack, the more private it’s supposed to be.
This is fundamentally the Monero approach. The problem is that you’re playing whack-a-mole with attack vectors. Each new feature adds complexity, and complexity creates new attack surfaces. You can never be certain you’ve plugged all the leaks because the security model isn’t designed to be comprehensive.

The deeper issue is that obfuscation degrades over time. It’s hiding a needle in a haystack. It works until someone builds a better magnet. The needle is still there, still findable with sufficient effort. The security is economic, not mathematical. You’re betting that finding the needle costs more than it’s worth.
But costs decline. Compute gets cheaper. Algorithms get smarter. Adversaries get more motivated. What’s hidden today may be trivially exposed tomorrow.
The second approach is encryption. Instead of trying to obscure specific pieces of information, you prove that a transaction is valid without revealing anything about it. The sender, receiver, and amount are all hidden. The data isn’t obscured or mixed with decoys. It’s encrypted. What the network sees is mathematically indistinguishable from random noise.

This is what Zcash does, using zero-knowledge proofs to achieve something cryptographers call “ledger indistinguishability.” The result is a formal security guarantee: transactions cannot be distinguished from one another, robust against every possible attack strategy.
This distinction matters more than most people realize. In cryptography circles, the difference between obfuscation and encryption isn’t a matter of degree, it’s a difference in kind. One offers plausible deniability that erodes with time and compute. The other offers mathematical guarantees that hold regardless of how much resources an adversary throws at it.
How It Actually Works: Commitments, Nullifiers, and Merkle Trees
When you receive shielded ZEC, a “note” is created. Think of notes as encrypted UTXOs. A note contains your address, the value, and some random values that make it unique. But the note itself never touches the blockchain. Instead, a cryptographic commitment to the note is added to a global Merkle tree containing every note commitment ever created.
The commitment is computed by hashing the note’s fields together. It has two critical properties: it’s one-way (you can’t recover the note from the commitment) and collision-resistant (you can’t find two different notes that produce the same commitment). The blockchain stores the commitment, not the note.

When you spend a note, you need to prove two things: that the note exists (its commitment is in the tree) and that you haven’t spent it before.
- For existence, you prove a Merkle path from your commitment to the root, without revealing which commitment is yours.
- For double-spend prevention, you reveal a “nullifier,” a value derived from the note that only you can compute.
The nullifier is the clever part. Every note maps to exactly one nullifier. When you spend, you publish the nullifier, and the network adds it to a nullifier set. If someone tries to spend the same note again, they’d have to publish the same nullifier, which the network would reject because it’s already in the set. But crucially, no one can link a nullifier to its corresponding commitment without knowing your secret key. Observers see a nullifier appear and know some note was spent, but can’t tell which of the millions of commitments it came from.
The zk-SNARK then ties everything together.
When you construct a transaction, you generate a proof (about 1.5 kilobytes) that demonstrates: you know a note with a commitment in the tree, you know the secret key needed to compute its nullifier, the nullifier you’re publishing corresponds to that note, and the transaction amounts balance.
The network verifies the proof and checks the nullifier against the set. It never learns which commitment was spent, who the recipient is, or how much was transferred.
The Shielded Pool: Privacy as a Network Effect
The shielded pool is all the ZEC that exists in private (shielded) addresses. It’s simultaneously a measure of adoption, a measure of privacy quality, and Zcash’s most durable moat.
Think of the shielded pool like a black hole. In physics, the no-hair theorem says black holes can only be characterized by a few external properties: mass, charge, angular momentum. You can’t see what’s happening inside. You can only observe what crosses the event horizon.

The shielded pool works the same way. You can see what enters and exits (amounts and timing), but when money is inside the pool, the on-chain data is indistinguishable from random noise without the relevant keys. You can’t see who owns it, who they transact with, or how much any individual holds.
The size of the pool is critical because you’re only as anonymous as the crowd you’re hiding in. If there’s only one person in the pool, their privacy is zero. Everyone knows any shielded transaction must involve them. If there are millions of users and billions of dollars in the pool, the anonymity set is massive, and individual transactions become mathematically indistinguishable from one another.

This creates a flywheel. More capital in the pool means better privacy for everyone. Better privacy attracts more users. More users attract more capital. The pool grows, and its gravity increases.
The Orchard pool now contains millions of notes. That’s the anonymity set for every shielded transaction; the total number of notes that have ever been created, not just what’s currently in the pool. It grows with every transaction and never shrinks.
When you spend a shielded note, you prove that it exists somewhere in that tree of millions, without revealing which one. There’s no probabilistic attack that works against an anonymity set of millions of notes. You can’t narrow the candidates through elimination because nothing is eliminated.

The amount of ZEC currently held in shielded addresses is a different metric; it tells you about usage levels and market confidence. Since October 2025, nearly 1 million additional ZEC has moved into shielded pools.

The shielded supply has grown from roughly 11% of circulating supply at the start of 2025 to approximately 30% today (4.9 million ZEC).
This is the metric to watch. A growing shielded pool is a strengthening moat.
Turnstiles: A Second Line of Defense
If zero-knowledge proofs are the primary mechanism for ensuring monetary integrity, turnstiles are the redundant backup, an extra layer of defense in case the primary layer ever fails.
Each shielded pool has a turnstile, a running tally of ZEC that has entered and exited. When coins move from the transparent pool into a shielded pool, the turnstile records the deposit. When coins move back out, it records the withdrawal.
If the turnstile shows 1 million ZEC have entered a pool and 800,000 have exited, then at most 200,000 remain shielded. If someone tries to withdraw 300,000, something is wrong. Either the cryptography failed, or someone is attempting fraud.
Turnstiles don’t prevent counterfeiting, that’s what the ZK proofs do. Turnstiles detect any attempt to cash out counterfeit coins if the proofs somehow fail. You could theoretically forge ZEC inside a shielded pool (if you broke the cryptography), but you couldn’t spend those coins in the transparent pool without the discrepancy being noted.
This was tested in 2018 when a vulnerability was discovered in the Sprout cryptography. A flaw in the proof system could have allowed an attacker to create coins without detection inside the shielded pool. The bug was found by the Zcash team during a security audit and patched before any exploitation occurred.
But the episode demonstrated the importance of turnstiles: even a catastrophic cryptographic failure would not produce undetectable inflation. The damage would be bounded, and any attempt to realize the counterfeit value would raise alarms.
Protocol Evolution: From Trusted to Trustless
Zcash has upgraded its core cryptography twice since launch, with each generation bringing better performance, stronger security, and fewer trust assumptions.

Sprout (2016) proved that private cryptocurrency was possible. But it was barely usable. Creating a shielded transaction required about 40 seconds of computation and several gigabytes of RAM. Not usable on phones, barely usable on laptops. Most transactions stayed transparent simply because shielding was too costly. And it required the trusted setup ceremony.
Sapling (2018) made privacy practical. Proof generation dropped from 40 seconds to a few seconds. Memory requirements fell to a few dozen megabytes. Shielded transactions became feasible on mobile devices for the first time. But the trusted setup remained, just with a larger ceremony involving hundreds of participants.
Orchard (2022) replaced the entire proof system. Built on Halo 2, it eliminated the trusted setup entirely. No ceremony, no toxic waste, no trust assumptions. The parameters come from public, verifiable data. Orchard is the pool Zcash was always meant to have. The earlier generations were the best technology available at the time; Orchard is what became possible once the research caught up with the vision.
Today, Orchard is the default for new shielded transactions. Sapling remains supported but is being phased out. Sprout is deprecated.
The Next Chapter: Scaling, Economics, and Future-Proofing
The core product works. What comes next determines if Zcash can actually compete with Bitcoin as a store of value. Three developments matter most: scaling without breaking privacy, funding the network beyond block rewards, and quantum-proofing before it’s forced to.

Tachyon: The Path to Scale
Private transactions are expensive. The cryptographic machinery required to prove transaction validity without revealing contents results in proofs that are roughly 10 kilobytes per transaction. Verification is computationally intensive. Zcash’s current shielded transaction throughput is approximately 3 TPS, nowhere near what mainstream adoption would require.
But the deeper problem is state growth. Every shielded transaction creates something called a nullifier. These nullifiers must be stored by every full node, permanently, to validate future transactions. The nullifier set grows linearly with the total number of transactions ever made. At even 100 TPS (still far from Visa scale), this would mean roughly 1 gigabyte of state growth per day. Not blockchain history that can be pruned, but an active state that must be retained by validators.
Tachyon, led by cryptographer Sean Bowe (the architect behind Halo 2 and much of Zcash’s core cryptography), addresses both problems.

The key innovation is “oblivious synchronization.” The idea is that a service can help you prove you haven’t double-spent, while remaining blind to what you’re actually spending. The service processes the computation on your behalf without learning which nullifiers you’re using. You get the computational help without trusting the helper.
This means validators don’t need to store the full nullifier history. Users aren’t exposed to costs that scale with total network activity. And ledger indistinguishability, Zcash’s core privacy property, remains intact.
Tachyon also introduces proof aggregation (similar to signature aggregation), allowing multiple shielded transactions to be batched with a single proof. This reduces marginal transaction size to approximately 200-500 bytes, comparable to Bitcoin. A fully private Zcash transaction ends up being about the same size and speed as a transparent Bitcoin transaction.
The tradeoff between privacy and scale, long assumed to be fundamental, turns out to be an engineering problem with a cryptographic solution.
Tachyon’s shielded pool is expected to be live at the protocol level by the end of 2026. Wallet integration takes longer since the entire ecosystem needs to add support, but this should be smoother than previous upgrades because Tachyon’s cryptography is compatible with the existing Orchard pool. Hardware wallets, for example, will be able to piggyback on existing code and library support rather than building from scratch.
Network Sustainability Mechanism (NSM)
Bitcoin faces a looming problem: as block rewards halve toward zero, transaction fees must compensate miners for securing the network. Whether fees will suffice remains an open question.
Zcash inherits this problem. The NSM, being developed by Shielded Labs, solves it without breaking the 21 million cap.
The mechanism allows ZEC to be burned from circulating supply and reintroduced as future block rewards. Burning 1 ZEC now causes additional ZEC to be issued over subsequent halving periods following an exponential decay. Short-term: reduced circulating supply, increased scarcity. Long-term: sustained miner incentives without exceeding the cap.
Three ZIPs define the mechanism: ZIP 233 (voluntary burning), ZIP 234 (smoothed issuance curve), and ZIP 235 (60% of transaction fees burned). The infrastructure is being established now while fees are low and miners have no economic incentive to oppose it.
Quantum Resistance
Quantum computing represents a long-term threat to all cryptographic systems. For privacy coins, there are two distinct risks: theft/counterfeiting (breaking the cryptography that secures funds) and de-anonymization (retroactively revealing who transacted with whom).
This is where the encryption vs. obfuscation distinction becomes critical.
Zcash’s anonymity is protected by what cryptographers call “information-theoretic hiding.” The relevant parts of a shielded transaction (sender, receiver, amount) aren’t just encrypted; they’re hidden in a way that no amount of computational power can reveal.
A quantum computer cannot de-anonymize Zcash’s historical transactions because there is no information in the transaction data that would allow it.
Monero is fundamentally different. Its anonymity relies on computational hardness assumptions (the discrete logarithm problem). A quantum computer could, in principle, solve these problems and fully de-anonymize Monero’s entire transaction graph, retroactively. Every transaction ever made on Monero could potentially be traced.
This isn’t a theoretical concern for the distant future. It’s a property of transactions being made today. If you transact on Monero now and quantum computers become practical in 5-10 years, your transactions from today can be de-anonymized then. If you transact on Zcash now, they cannot be.
The Zcash team is addressing quantum risks in a prioritized order:
- Post-quantum privacy (via Tachyon): Making Zcash fully safe from quantum adversaries by addressing the one remaining component that isn’t currently protected. This is bundled into the Tachyon upgrade, meaning the scaling improvements and quantum privacy improvements ship together. Expected at the protocol level by the end of 2026.
- Quantum recoverability (2026): An escape hatch that protects funds if quantum computers appear suddenly. Already designed and implemented; integration is underway.
- Post-quantum soundness (longer-term): Ensuring the cryptographic assumptions underlying transaction validity are quantum-resistant. This is the most complex piece and is on a longer timeline.
The sequencing matters. Privacy protection comes first because that’s what protects users retroactively. Recoverability provides a safety net. Soundness is the final piece that makes the system fully quantum-proof.
For an asset positioning itself as a multi-generational store of value, this kind of forward-looking roadmap matters. Bitcoin has no comparable plan. Monero is structurally vulnerable. Zcash is the only major cryptocurrency actively building for a post-quantum world.
Zcash Shielded Assets: Expansion or Distraction?
Zcash Shielded Assets (ZSAs) are a proposed extension that would allow arbitrary tokens to be issued on Zcash, sharing the same shielded pool as ZEC. The idea is that if you’re sending stablecoins through the pool, observers can’t tell whether a transaction involves ZEC or some other token. All ZSA activity would be shielded, with transaction fees paid in ZEC.
The feature has its supporters. The argument is that ZSAs could expand Zcash’s utility, attract new users, and increase demand for ZEC as the fee token. Bridging assets like Bitcoin or stablecoins into a truly private environment is a use case that doesn’t exist elsewhere.
My reasons for disagreeing:
Refusing to build out functionality that supports future chain revenue and keeps the protocol competitive is the same hole Bitcoin fell into, and is why they never added zkps. “attack surface” is an engineering problem that gets turned into an…— path.eth 🛡️ (@Cryptopathic) January 20, 2026
There’s also a more pointed version of the bull case: that refusing to build out functionality is the same hole Bitcoin fell into. Bitcoin never added ZKPs. It never added privacy. The “attack surface” concern became an ideological one, driven by fear, and ended up ossifying the protocol. If Zcash takes the same approach, rejecting features that could drive adoption and revenue because of theoretical risk, it risks the same fate. “Store of value” can become an intellectually lazy framing that justifies stagnation.
It’s a fair critique, and worth taking seriously.
But there’s meaningful skepticism within the community, and I share some of it.
ZSAs are a bad idea
Focus should be singular — competing against other networks for other asset types will never work
private SoV has PMF
— mert (@mert) November 10, 2025
The core concern is strategic focus. Zcash hasn’t solved private money at scale yet. The bottlenecks that Tachyon addresses are real constraints. Adding more forms of money before solving the fundamental scaling problem risks diluting engineering attention at a critical moment.
There’s also complexity risk. Every feature added to the shielded pool increases the attack surface. For a project positioning itself as a secure store of value, this matters. The comparison to Bitcoin’s Ordinals comes up often: a distraction that consumed developer energy without meaningfully advancing the core value proposition.
From a competitive standpoint, Zcash won’t be able to compete with Ethereum or Solana by trying to be like them. Those chains have developer ecosystems, DeFi infrastructure, and network effects that Zcash can’t easily replicate. The winning strategy, in this view, is to be the encrypted store of value and make ZEC as valuable as possible. Once that happens, the asset will be extended to other ecosystems in a trust-minimized way for DeFi usage regardless.
The counterargument is that ZSAs could actually strengthen ZEC’s position by making the shielded pool more useful and increasing overall activity. More usage means a larger anonymity set, which benefits everyone. It’s a reasonable debate, and the community hasn’t fully resolved it.
The ZSA implementation is being developed by QEDIT under a grant from the Zcash Foundation. But the feature currently faces blockers: the Foundation can’t merge it into the Zebra node until shared cryptography libraries are updated, and the timeline is uncertain given recent organizational changes. Whether that’s a problem or a blessing depends on where you stand.
Regardless of where ZSAs land, the core thesis remains: Zcash is positioning itself as a private store of value. But Zcash isn’t the only project working on privacy. If the demand for private money is real and growing, why should Zcash capture it?
The Competition: Why Not All Privacy Is Equal
Privacy is becoming a crowded narrative. Monero has been around for years. Tornado Cash brought privacy to Ethereum before it was (temporarily) sanctioned. Privacy Pools are being developed as a “compliant” alternative. Aztec and other L2s are building encrypted execution environments. Almost every major chain is exploring some form of confidential transactions or shielded transfers.
But there’s a difference between privacy as a feature and privacy as a foundation. And there’s a difference between privacy that holds up under serious adversarial pressure and privacy that works until someone tries hard enough to break it.
For an asset to credibly serve as a long-term store of value, the privacy guarantees need to be durable. Not just today, but decades from now, against adversaries with resources we can’t fully anticipate. That’s a high bar and most approaches don’t clear it.
Monero
Monero is the obvious comparison and deserves serious treatment. It has a dedicated community, genuine usage in contexts where privacy matters, and cultural staying power. These aren’t trivial advantages.
But the technical architecture has fundamental limitations.
Monero’s privacy model, as previously mentioned, is based on obfuscation. When you spend, your transaction is mixed with 16 decoys sampled from the blockchain. An observer sees 16 possible senders and can’t immediately tell which is real. This sounds robust until you examine it more closely.
Sixteen is a small number. It’s small enough that probabilistic analysis, especially when combined with timing data, amount patterns, and behavioral heuristics, can narrow the candidates. It’s small enough that sufficient compute and sophisticated techniques can, in some cases, identify the real spend. This has already happened in practice. Law enforcement has successfully traced Monero transactions. The documented case of Japanese police analyzing Monero to identify and arrest eighteen suspected fraudsters demonstrates that decoy-based privacy has a ceiling.
Zcash works differently. When you spend a shielded note, you’re proving it exists somewhere in a Merkle tree containing millions of notes, without revealing which one. There’s no set of decoys to analyze. There’s no probabilistic elimination. The anonymity set is every shielded note ever created, and it grows with every transaction.
This is the difference between obfuscation and encryption. Obfuscation hides information by adding noise. Encryption makes information mathematically inaccessible. One degrades as analysis techniques improve. The other doesn’t.
Then there’s quantum. Zcash’s anonymity is information-theoretically hidden. Even a quantum computer can’t de-anonymize historical transactions because the information simply isn’t there to extract. Monero’s privacy relies on computational hardness assumptions, specifically the discrete logarithm problem, that quantum computers could solve. A sufficiently powerful quantum computer could potentially de-anonymize Monero’s entire transaction history, retroactively exposing every transaction ever made.
This isn’t a concern for next year. But if you’re evaluating an asset as a multi-decade store of value, it matters. Transactions made today on Monero could theoretically be exposed in 2030. Transactions made today on Zcash cannot.
Scalability is another divergence. Zcash has Tachyon, a concrete roadmap to address state growth and throughput constraints. Monero faces the same fundamental bottleneck, they call their equivalent objects “key images,” with no comparable plan. The cryptographic techniques required to solve these problems are years ahead of anything Monero has deployed.
Finally, there’s market access. Monero has been delisted from virtually every major exchange: Coinbase, Bybit, Binance, and others. Zcash remains available on Coinbase, Gemini, Kraken, and more. For an asset to function as a store of value, liquidity and accessibility matter. Monero’s regulatory positioning has made that increasingly difficult, and the situation is unlikely to improve.
None of this means Monero is worthless or that its community isn’t building something real. And it’s worth saying: this isn’t necessarily zero-sum. There’s room for multiple projects that take privacy seriously, and Monero’s cultural energy has done real work in keeping the privacy narrative alive during years when most of crypto didn’t care.
But from a technical standpoint, evaluating on privacy guarantees, quantum resistance, scaling roadmap, and market access, Zcash is stronger on every dimension. Culture matters, but culture doesn’t create cryptographic security guarantees.
Mixers and Tornado Cash
Mixers approach privacy differently. The idea is simple: deposit funds into a pool, wait, then withdraw to a fresh address. The goal is to break the link between your input and output.
The problem is that mixers add privacy to value in motion, not value at rest. Both the deposit and withdrawal are visible onchain. If they correlate, through timing, amounts, or patterns, the privacy breaks. Sophisticated analysis can often link inputs to outputs, especially when user behavior is predictable.
More fundamentally, you can’t actually use funds while they’re in a mixer. You can’t send arbitrary amounts. You can’t transact within the pool. You can’t receive payments or make purchases. To do anything with your money, you have to withdraw to a transparent address, which re-exposes you to the surveillance layer you were trying to escape.
Zcash’s shielded pool is architecturally different. You can receive funds, hold them indefinitely, spend arbitrary amounts, receive change, and transact with others, all without ever leaving the shielded environment. It’s not a temporary privacy layer you pass through. It’s a fully functional monetary system where privacy is the default state.
For a store of value use case, this distinction is critical. You want an asset you can hold for years, transact with when needed, and never have to expose to maintain usability. Mixers don’t offer that. Zcash does.
Privacy Pools
Privacy Pools represent an attempt to create “compliant privacy,” a system where users can prove they’re not associated with known bad actors while still maintaining some degree of anonymity.
The cryptography is clever. You can withdraw from a pool while demonstrating your funds didn’t originate from sanctioned addresses. Regulators get assurance that funds aren’t tainted. Users get privacy within the bounds of what’s permissible.
The problem is philosophical as much as technical. Privacy Pools invert due process. The assumption is that you’re suspicious until you prove otherwise by opting into approved association sets and providing cryptographic evidence of your cleanliness. In functioning legal systems, the burden is on the prosecution to prove guilt. Privacy Pools normalize the opposite.
There’s also a practical limitation. Your privacy depends on what others in your association set choose to disclose. As members prove exclusion from various activities to clear their names, the remaining members become more suspicious by default. The system creates constant pressure to prove more, disclose more, narrow your set further.
This might satisfy regulators. It doesn’t satisfy the demand for genuine financial sovereignty. It’s permissioned privacy, which is almost a contradiction in terms.
Aztec and Private L2s
Encrypted rollups like Aztec are doing serious engineering work. They’re building infrastructure for private programmability: encrypted DeFi, confidential computation, private smart contracts. This is valuable technology for specific use cases.
But it’s solving a different problem than Zcash.
If you want to interact with complex financial protocols without exposing your positions, an encrypted execution environment makes sense. If you want a place for wealth to rest securely for years or decades, you need something with a longer track record.
Aztec is new. The cryptography may be sound, but the system hasn’t been tested over time, through market cycles, regulatory pressure, and sustained adversarial conditions. For experimental DeFi applications, that’s an acceptable tradeoff. For a store of value, it’s not.
Store of value assets need to be Lindy. They need history. Zcash has nearly a decade of continuous operation. That’s not a guarantee of future security, but it’s more evidence than any new system can offer.
There’s also a question of focus. Aztec is building a platform for private applications. Zcash is building private money. These are different missions with different design priorities. Zcash’s entire architecture is optimized for a single use case: holding and transferring value privately. That focus is a feature, not a limitation.
The Bigger Picture
The point of this comparison isn’t to dismiss everything else in the privacy space. Different projects serve different purposes, and some will find meaningful adoption in their respective niches. Monero has a community that’s kept the privacy conversation alive for years. Tornado Cash proved there was demand for privacy on Ethereum. Aztec is doing genuinely innovative work on encrypted computation. These projects matter, and the space is better for having them.
But if you’re specifically evaluating the store of value use case, the requirements narrow. The privacy needs to be mathematically durable, not probabilistically hopeful. The asset needs to be usable as actual money, not just a temporary obfuscation layer. The system needs a track record of operating under adversarial conditions. And it needs enough market access to provide liquidity when you need it.
Most privacy approaches fail on at least one of these dimensions. Monero’s obfuscation degrades over time and faces quantum risk. Mixers can’t be used as money. Privacy Pools require you to prove innocence. New L2s lack the track record.
Zcash clears every bar. That doesn’t guarantee success, and it doesn’t mean other projects won’t thrive in their own lanes. But if you believe a private store of value is going to be important, and the macro environment increasingly suggests it will be, then Zcash is the strongest candidate to capture that specific demand. Store of value dynamics tend toward concentration. The asset with the strongest technical foundation, the longest track record, and the clearest path to continued adoption has a meaningful edge.
The Current Moment: Catalysts, Context, and Clearing the Air
Zcash is getting renewed attention from crypto-native capital. Privacy narratives are resurfacing. Macro conditions favoring financial sovereignty are aligning. But the conversation around Zcash remains anchored to criticisms and governance controversies from 2017-2020 that no longer reflect the protocol’s current state.
The gap between perception and reality is wide.
Most investors are still operating on outdated mental models: trusted setup concerns that haven’t been relevant since multiple ceremony upgrades, founder’s reward debates that concluded years ago, governance conflicts that have since been restructured. Meanwhile, the actual protocol has evolved significantly: regular network upgrades, meaningful adoption in specific use cases, and a technical architecture that’s increasingly differentiated as privacy and quantum resistance move from theoretical to practical concerns.
This section establishes where Zcash actually stands today: the catalysts driving current momentum, the context that makes this moment distinct from previous cycles, and a clear-eyed assessment of which criticisms still matter versus which ones are legacy noise
Regulatory Clarity
On January 14, 2026, the SEC closed its investigation into the Zcash Foundation without recommending enforcement action. The probe had been open for more than two years, beginning in August 2023, and focused on potential securities issues tied to Zcash’s funding and governance structure.
We are pleased to announce that the SEC has concluded its review and informed us that it does not intend to recommend any enforcement action or other changes against Zcash Foundation regarding this matter. https://t.co/zjxfh3mmst
— Zcash Foundation 🛡️ (@ZcashFoundation) January 14, 2026
For over two years, institutional capital had a reason to stay away; regulatory uncertainty is the fastest way to kill liquidity and exchange listings in crypto. The investigation’s closure, part of the broader unwinding of Gensler-era enforcement, doesn’t just remove an overhang. It validates that a privacy-focused cryptocurrency can survive sustained SEC scrutiny and emerge with no action. In an environment where privacy coins are presumed guilty until proven otherwise, that’s significant.
The timing helps too. If there’s any administration under which financial privacy could get a legitimate run, it’s this one. Trump’s crypto policy is being shaped, in part, by people with direct skin in the game: the Winklevoss twins (longtime Zcash supporters), Coinbase (which still lists ZEC), and David Sacks, who’s been publicly vocal about CBDC overreach and asset seizure risks in states like California.
.@davidsacks47 blasts California’s so-called “Billionaire Tax Act”
“This is this is not a tax, this is an asset seizure… Never been anything like this before in American history.
People are trying to minimize it by saying it’s a one-time. It’s not a one-time. It’s a… pic.twitter.com/1sfqAvVfP0
— Breitbart News (@BreitbartNews) January 21, 2026
This isn’t an administration that’s going to champion CBDCs or expand financial surveillance infrastructure. The macro-political environment for privacy-preserving technology is as favorable as it’s been in years.
The competitive positioning amplifies this. Monero, Zcash’s closest comparable, has been systematically delisted from every major regulated exchange. Coinbase, Gemini, Binance (in most jurisdictions): all gone. Meanwhile, Zcash remains available on Coinbase, Gemini, and Kraken. The distinction isn’t arbitrary. Zcash’s optional transparency model, its willingness to engage with regulators rather than position itself as adversarial, and its compliance infrastructure give it regulatory durability that mandatory-privacy protocols can’t achieve.
This creates a structural moat. If global privacy regulation tightens, and all signs point to continued pressure on financial surveillance tools, Zcash is the only credible privacy asset positioned to survive in regulated markets. Monero may have the hardline cypherpunk credibility, but Zcash has the exchange listings, the institutional on-ramps, and now, explicit regulatory clearance. For capital that wants privacy exposure without career risk, there’s increasingly no alternative.
The SEC closure validates Zcash’s strategic positioning: you can build privacy tools without becoming untouchable. That determines everything; whether exchanges list you, whether liquidity exists, whether anyone with compliance concerns can allocate.
Institutional Interest
The institutional signals have been building quietly but consistently.
In November 2025, Grayscale filed to convert its Zcash Trust into a spot ETF on NYSE Arca. The trust holds approximately $137 million in ZEC, representing roughly 5% of circulating supply. A decision is expected in Q1 2026. If approved, it would be the first privacy coin ETF, a landmark not just for Zcash but for the broader acceptance of privacy-preserving assets within traditional financial infrastructure.
Winklevoss-backed Cypherpunk targets 5% of Zcash supply with $58 million treasury seed https://t.co/gZkO9xAhtC
— The Block (@TheBlock__) November 12, 2025
Around the same time, a more unusual development emerged. Cypherpunk Technologies, a NASDAQ-listed company formerly known as Leap Therapeutics, pivoted to a Zcash treasury strategy following a $58.88 million private placement led by Winklevoss Capital. The company now holds 290,063 ZEC, approximately 1.76% of total circulating supply. Both Zooko Wilcox and Josh Swihart joined as Strategic Advisors in December 2025.
The Winklevoss involvement carries weight beyond the capital itself. These are some of Bitcoin’s earliest and most consequential backers; they once held roughly 1% of Bitcoin’s supply and were instrumental in building early liquidity and institutional legitimacy for the asset. Their public conviction on Zcash isn’t noise.
In January 2026, they made their second donation to Shielded Labs: 3,221 ZEC (roughly $1.2 million). For crypto-native capital watching for signal, especially the early Bitcoiners who’ve grown disillusioned with BTC’s institutional capture, the Winklevoss positioning matters.
The backing also extends beyond crypto natives. Prominent Silicon Valley voices have been making the case for encrypted, private stores of value, and for Zcash specifically. Naval Ravikant, an early Bitcoin advocate with a network spanning both crypto allocators and mainstream tech, has publicly framed Zcash as a necessary hedge to Bitcoin.
Literally the most well articulated zcash / private crypto money thesis i have ever seen
fungible, quantum resistant (soon), private — all zcash properties mentioned
highly recommend you take a few seconds, reiterates all of our points well pic.twitter.com/9ZWVz7V1kK
— mert (@mert) January 10, 2026
Chamath Palihapitiya has similarly called out the importance of private financial infrastructure as a counterweight to surveillance systems. These aren’t crypto-first investors selling a narrative to retail. They’re Silicon Valley figures with real reputations, putting their names behind the idea that privacy at the financial layer actually matters.
The institutional conversation is also shifting at the executive level. Earlier this year, VanEck’s CEO, Jan van Eck went on CNBC and said the quiet part out loud: “What the Bitcoin community has been asking itself is: Is there enough encryption in Bitcoin, because quantum computing is coming? And secondly: Is there enough privacy in Bitcoin? And so a lot of Bitcoin OGs or maxis have been looking at Zcash.”
VanEck CEO Jan van Eck on CNBC:
“There’s something else going on within the Bitcoin community that non-crypto people need to know about.
And that is: ultimately, VanEck has been around before Bitcoin. We will walk away from Bitcoin if we think the thesis is fundamentally… pic.twitter.com/pCUtuqBVHD
— Arjun Khemani (@arjunkhemani) November 22, 2025
He continued: “A lot of people are looking for more privacy”, framing Zcash explicitly as the answer to Bitcoin’s limitations, not as a competitor to dismiss.
This is VanEck, a firm that filed for the first Bitcoin ETF back in 2017. When their CEO is publicly discussing Zcash as the solution to Bitcoin’s gaps on CNBC, the institutional conversation has clearly shifted.
Governance: The ECC-Bootstrap Split
On January 7, 2026, the entire staff of the Electric Coin Company resigned following a dispute with Bootstrap, ECC’s parent nonprofit board. CEO Josh Swihart announced the departure publicly, citing fundamental misalignment on Zcash’s direction and naming specific board members he disagreed with.
Over the past few weeks, it’s become clear that the majority of Bootstrap board members (a 501(c)(3) nonprofit created to support Zcash by governing the Electric Coin Company), specifically Zaki Manian, Christina Garman, Alan Fairless, and Michelle Lai (ZCAM), have moved into…
— Josh Swihart 🛡 (@jswihart) January 7, 2026
Bootstrap framed the conflict as a governance and legal issue. As a 501(c)(3) nonprofit, the board argued it had fiduciary obligations that constrained certain proposed transactions involving Zashi and outside investment. The specifics remain somewhat opaque, but the core tension appears to have been about Zcash’s funding model; though that question was largely resolved in November 2024 when the original Dev Fund sunset and was replaced by a decentralized, grant-based structure.
The former ECC team has since launched cashZ, a new startup building a wallet derived from Zashi’s codebase. The framing is explicitly for-profit: “scale Zcash to billions.” Balaji Srinivasan publicly endorsed the team. Dragonfly’s Haseeb Qureshi called them “true believers and cypherpunks.”
Meanwhile, Shielded Labs, a Swiss-based nonprofit led by Zooko Wilcox as Head of Product, continues work on Crosslink (a hybrid PoW/PoS consensus mechanism) and the Network Sustainability Mechanism. The Zcash Foundation maintains the Zebra node implementation and deployed new DNS seed nodes shortly after ECC’s departure to ensure network stability.
The headlines were dramatic. The reality is more nuanced.
Zcash’s development was never dependent on a single organization. Multiple independent teams, in different jurisdictions, with different funding sources, have been contributing to the protocol for years. The ECC split doesn’t change the underlying technology or the network’s operation. If anything, it accelerates a transition that was already underway: from a more centralized development model toward genuine decentralization across multiple competing and collaborating entities.
This is messy. It’s also arguably healthy. Protocols that depend on a single team have a single point of failure. Zcash, post-split, has multiple teams with different approaches all building toward the same core mission.
Clearing Up Common Misconceptions
Zcash has been around long enough to accumulate a layer of FUD that no longer reflects reality. Some of it was legitimate concern at one point. Most of it is now outdated or was never accurate to begin with. Worth addressing directly.
“There was a premine.”
There wasn’t. Zero coins existed before the genesis block. The confusion stems from the Founder’s Reward: during Zcash’s first four years, 20% of block rewards were allocated to founders, investors, employees, and the Zcash Foundation.
zcash was as fairly launched as it could have been at the time of its launch c.2016 (at that time it was not possible to recreate bitcoin’s launch entirely because was already a mining ecosystem in existence that would have just scooped up all the initial zec)
investors…
— sacha (@sacha) October 21, 2025
This wasn’t a hidden allocation created before launch. It was a portion of ongoing issuance, created through mining, distributed transparently according to terms that were fully disclosed before the network went live. Anyone who mined or purchased ZEC in 2016 knew exactly how this worked. The Founder’s Reward ended completely in November 2020.
“Developers get 20% of mining rewards.”
This conflates two separate programs. The Founder’s Reward (2016-2020) included founders and early investors. It ended. The original Dev Fund (2020-2024) allocated 20% of block rewards differently: 7% to ECC for protocol development, 5% to the Zcash Foundation for infrastructure and grants, and 8% to community grants administered independently. That structure sunset in November 2024 and was replaced by a new model where funding is decentralized and grant-based. Founders haven’t received protocol rewards since 2020.
“Zcash requires a trusted setup.”
This was true until 2022. Sprout and Sapling, the earlier shielded pool implementations, required trusted setup ceremonies where cryptographic parameters were generated by participants who had to destroy their secret inputs. If anyone retained those secrets, they could theoretically counterfeit ZEC undetectably.
Orchard, deployed in 2022, eliminated this entirely. Built on Halo 2, Orchard uses a proving system that requires no ceremony, no trusted participants, no “toxic waste.” The security is purely mathematical. The trusted setup critique, while valid for years, no longer applies to how Zcash works today.
“The anonymity set is small.”
This criticism fundamentally misunderstands Zcash’s architecture by conflating it with Monero’s approach. In Monero, each transaction hides among 16 decoys. The anonymity set is literally 16. In Zcash, when you spend a shielded note, you prove it exists somewhere in a Merkle tree containing millions of notes without revealing which one. The anonymity set is every shielded note ever created. It grows with every transaction and never shrinks. These are categorically different privacy models.
“Optional transparency weakens privacy.”
It doesn’t. The transparent pool and shielded pool are mathematically independent systems. What happens in transparent addresses reveals nothing about shielded addresses. Even if 99% of ZEC sat in transparent addresses, the privacy guarantees for the shielded 1% would be determined entirely by the shielded pool itself. Optional transparency exists for use cases that require it (exchange compliance, for example) without compromising privacy for users who don’t.
“Zcash isn’t private by default.”
This was a fair criticism of early wallet implementations, which often defaulted to transparent addresses for performance and compatibility reasons. It’s no longer accurate. Modern wallets like Zashi shield by default, automatically moving any transparent funds into the shielded pool before spending. The default path through Zcash today is fully private.
Valuation: Framing the Opportunity
Valuing Zcash is hard. Not because the fundamentals are unclear, but because there’s no clean comp.
It’s not a smart contract platform with fee revenue to discount. It’s not a DeFi protocol with TVL to benchmark. It’s not even a straightforward “digital gold” narrative where you can point to Bitcoin and apply a percentage.
Zcash is something different: an encrypted store of value. A sovereign asset for a world where sovereignty increasingly requires privacy. The closest analog might be Bitcoin circa 2012, before institutions arrived, when the thesis was still about financial freedom rather than portfolio diversification. But even that comparison breaks down because Zcash is explicitly building what Bitcoin chose not to.
So rather than pretend precision where none exists, I’ll lay out a few frameworks for thinking about what ZEC could be worth under different assumptions. The goal isn’t to give you a price target. It’s to help you think through the asymmetry.
Framework 1: ZEC as a Percentage of Bitcoin
The simplest lens is to think of Zcash as capturing some share of the “store of value” demand that currently flows to Bitcoin.
Bitcoin is insurance against fiat.
ZCash is insurance against Bitcoin. https://t.co/rqMrR3bW7O
— Naval (@naval) October 1, 2025
Bitcoin’s market cap is roughly $1.4 trillion. Zcash is around $3.5 billion. That means ZEC currently trades at approximately 0.25% of BTC’s market cap.
The thesis of this report is that Zcash offers something Bitcoin doesn’t: genuine privacy, with a credible path to quantum resistance. If that thesis has merit, if there’s real demand for a private store of value alongside a transparent one, then ZEC capturing a larger share of BTC’s market cap is the natural expression of that demand.

Here’s what different scenarios would imply: At 1% of Bitcoin, ZEC roughly quadruples from here. At 5%, it’s ~19.8x. I don’t think these are wild assumptions either. They simply ask: what if a small but meaningful portion of store-of-value demand decides that privacy matters?
For context, Monero currently sits around $6.3 billion, or roughly 0.45% of Bitcoin’s market cap. Zcash, despite being technically superior on privacy, quantum resistance, scaling roadmap, and exchange access, trades at a discount to Monero. If you believe the technical merits eventually matter, that discount alone is likely mispriced.
Framework 2: The Monero Comp
Speaking of Monero: ZEC currently trades below XMR in market cap. Around 0.56x.
This is striking given the analysis laid out in this report. Zcash has stronger privacy guarantees (encryption vs. obfuscation). Zcash has quantum resistance for historical transactions (Monero doesn’t). Zcash has a concrete scaling roadmap (Monero doesn’t). Zcash has major exchange listings (Monero has been delisted from most). Zcash has institutional infrastructure being built around it (Grayscale ETF, Cypherpunk treasury, Winklevoss backing etc).
On what dimension does Monero deserve a premium?
The answer is probably cultural, and criminal. Monero has a grassroots, cypherpunk-coded community that’s been evangelizing for years. It has mindshare in certain circles. That’s worth something. It’s also become the de facto currency of the dark web; when ETH hacks get laundered, they flow straight into XMR. There’s genuine demand there.
But that demand comes with baggage. Monero’s association with illicit activity makes it radioactive to institutional capital. No fund manager wants to explain an XMR position to their compliance team.
Zcash has positioned itself differently, around freedom, not crime. The branding is intentional: financial privacy as a human right, not a tool for evasion. That framing matters when you’re trying to attract capital allocators who need a story they can tell out loud.
And the privacy demand that currently flows to Monero isn’t locked in. As Zcash’s UX improves and its technical advantages become harder to ignore ( faster transactions, lower fees, a credible quantum-resistance roadmap) that demand could easily migrate. Users follow the best product eventually.
Culture doesn’t compound the way technology does. And culture doesn’t protect you from quantum de-anonymization of your entire transaction history.
If Zcash simply traded at parity with Monero, that’s roughly a 1.8x from current levels. If the market eventually prices in technical superiority and Zcash trades at a premium, say 2x Monero’s market cap, that’s a 3.6x. If Zcash absorbs a meaningful portion of Monero’s user base as the technical differences become more apparent, the upside extends further.
The ZEC/XMR ratio is one of the cleaner ways to track whether the market is starting to recognize what this report argues.
Framework 3: The Sovereign Store of Value TAM
This one is harder to pin down, but worth thinking through.
Some portion of gold demand, estimated anywhere from 10-30% depending on who you ask, is driven by sovereignty concerns rather than pure investment allocation. People buy gold because governments can’t print it, can’t easily confiscate it, and can’t track it. It’s the original private store of value.
Gold’s market cap is approximately $17 trillion (above-ground gold; broader estimates including reserves push toward $37 trillion, but let’s use the more conservative figure).
You could argue Bitcoin has already captured a chunk of the “digital sovereignty” demand. But Bitcoin’s transparency limits how much of that demand it can actually satisfy. You can hold Bitcoin outside the banking system, but anyone can see your balance, your transactions, your entire financial history onchain.
Zcash is an asset that actually delivers what the sovereignty-motivated gold buyer wants: scarcity plus privacy. An asset that can’t be inflated, can’t be surveilled, and is increasingly difficult to confiscate in any practical sense.
What if Zcash captures just 1% of the “sovereignty premium” embedded in gold? That’s $17 billion, roughly a ~4.9x from current levels.
What if it captures 5%? That’s $85 billion, roughly a ~24.3x.
These are rough numbers, obviously. The “sovereignty premium” in gold isn’t precisely measurable, and the overlap between gold buyers and crypto adopters is imperfect. But the framework is useful for thinking about the scale of demand that could flow into a genuinely private store of value if the narrative takes hold.
Framework 4: Shielded Pool Trajectory
The shielded pool is Zcash’s core product. Its growth is the single most important metric for tracking adoption.
At the start of 2025, roughly 11% of ZEC supply was shielded. Today, it’s approximately 30%, a 3x increase in one year.
For context on how far this has come: in December 2017, only ~4% of ZEC was shielded. The tech worked but the UX didn’t. By early 2025, that had crept to ~11%, modest progress over 8 years. Then 2025 happened, and we went from 11% to 30% in twelve months. More growth in one year than the previous eight combined.

If the shielded pool continues growing at anything close to its 2025 rate, we could see 50%+ shielded within the next 12-18 months. That would represent a major shift in how ZEC is actually used, from a speculative asset with optional privacy to genuine private money.
The shielded pool growth also has a reflexive quality. More capital in the pool means better privacy (larger anonymity set). Better privacy attracts more users. More users attract more capital. The flywheel compounds.
There is also a supply dynamic worth noting.
ZEC in the shielded pool tends to be stickier. These aren’t coins sitting on exchanges waiting to be sold. They’re held by users who’ve actively chosen privacy, which usually signals longer time horizons and higher conviction. As the shielded pool grows, it acts as a supply sink, removing coins from active circulation. More ZEC shielded means less ZEC available on the open market. If demand increases while liquid supply shrinks, the math gets interesting.
Watching the shielded pool trajectory tells you whether the thesis is playing out in real time. If it stalls, the thesis could be in trouble. If it continues accelerating, the market will eventually have to price in what’s happening.
The historical parallel is worth considering too.
Zcash launched in October 2016 and has now had nearly a decade of continuous proof-of-work distribution, longer than Bitcoin had before its first major institutional wave. The Founders’ Reward sunset in 2020. Since then, 80% of block rewards have gone directly to miners, with the rest flowing to community grants and a protocol-controlled lockbox. The coins are scattered across a global miner base, not concentrated in VC hands.

The emission schedule mirrors Bitcoin’s: 21 million cap, halvings every four years. The November 2024 halving dropped annual inflation to ~4%. By 2028, it falls to ~1%. Bitcoin’s second halving (2016) preceded its 2017 explosion. Zcash’s second halving preceded… this.
The Asymmetry
I’m not going to give you a specific price target. Anyone who tells you exactly what ZEC will be worth is either lying or deluded.
But the setup is asymmetric.
The downside case is that Zcash remains a niche privacy tool. The shielded pool grows slowly. Institutions stay away. The macro environment shifts. Privacy becomes less salient. In that scenario, you lose money on a position that was never going to be portfolio-defining anyway. ZEC drifts. The bet didn’t work.
The upside case is that the thesis plays out.
Demand for a private store of value accelerates as surveillance intensifies and quantum concerns mount. The shielded pool keeps growing. Institutional infrastructure matures. Grayscale ETF gets approved. More Bitcoin holders rotate into ZEC as a hedge. The market starts pricing Zcash not as a “privacy coin” but as an encrypted store of value, the thing Bitcoin was supposed to be.
In that scenario, ZEC reprices. Not 50%. Multiples.
The expected value depends on the probabilities you assign. But the shape of the distribution is favorable. Limited downside relative to potential upside. That’s a setup that makes sense in a portfolio context.
There’s also something less quantifiable but worth naming. People want to believe in something again.

Crypto has spent the last few years drowning in memecoins, rug pulls, and increasingly hollow narratives. The early Bitcoin energy, the sense that you were part of something that mattered, has faded. For a lot of people, buying BTC now feels like buying a financial product. Safe. Institutional. Boring.
Zcash has some of that old energy. It’s a bit rebellious. It’s building something that actually matters in a world that’s getting more surveilled by the day. That kind of conviction tends to attract a different type of capital, not just speculators chasing price action, but people who want to own something they believe in. Early Bitcoin had that. Zcash might be one of the few assets in crypto right now that still does.
If the thesis is even partially right, ZEC is mispriced. And if the vibes matter, and sometimes they do, there’s something here that most of crypto has lost.
Conclusion: The Cypherpunk Hedge
Forty years ago, David Chaum published a paper proving that private digital money was possible. Thirty years ago, the cypherpunks started building the tools to make it real. Fifteen years ago, Bitcoin launched and proved that decentralized money could work. But Bitcoin made a choice, transparency over privacy, and that choice has shaped everything since.
For a long time, it didn’t matter. Bitcoin won anyway. It became the Schelling point, the institutional asset, the thing that Blackrock puts in your retirement account. That’s a kind of success.
But it’s not the cypherpunk vision.
The cypherpunk vision was money that couldn’t be surveilled. Couldn’t be frozen. Couldn’t be tracked. Money that existed outside the system entirely. That vision has been waiting for the right technology and the right moment to converge.
Zcash is the technology. This might be the moment.
The macro setup is hard to ignore. Surveillance infrastructure is expanding, not contracting. Governments are getting more aggressive with capital controls, not less. AI will make financial monitoring cheaper and more comprehensive than ever before. The demand for an asset that offers genuine privacy, not pseudonymity, not obfuscation, but actual mathematical guarantees, is not going to shrink. It’s going to grow.
Meanwhile, Bitcoin has drifted from its roots. Nearly 10% of supply sits in ETFs and government hands. It’s become politicized, institutionalized, captured. Gold and silver have outperformed it during exactly the macro environment where Bitcoin was supposed to shine. Maybe the market is telling us something.
Zcash has been building quietly through all of this. The trusted setup problem that plagued its early years is solved. The UX is finally good enough for normal people. The shielded pool has nearly tripled in a year, pulling supply out of circulation and into private hands. The SEC investigation is closed. Institutional capital is starting to pay attention.
There’s an irony here. This report points to institutional interest as a positive signal for Zcash while critiquing Bitcoin’s institutional capture. The difference is what kind of institutions and what kind of interest. The Winklevoss twins donating to Shielded Labs is not the same as Blackrock adding BTC to a passive index fund. One is conviction from people who understand what they’re backing. The other is allocation from people who need exposure to an asset class. Zcash is attracting believers. Bitcoin has become a product.
The honest answer is that nobody knows if Zcash succeeds from here. Execution risk is real. Adoption is still early. The narrative could fail to take hold. Privacy could remain a niche concern rather than a mainstream demand.
But the asymmetry is compelling.
If the thesis is wrong, ZEC remains a small position that didn’t work out. You move on.
If the thesis is right, you own the asset that captures the demand for private, sovereign money as that demand goes from niche to essential. You own what Bitcoin was supposed to be before it became what it is.
0 Comments