Zcash's Proposed Plan to Protect Transparent Payments From Quantum and AI Threats
Table of Contents
You might want to know
- How could Zcash make transparent payments more resistant to potential AI-driven or quantum-computing attacks?
- Can rotating addresses protect users’ privacy if servers can still connect those addresses to the same wallet?
Main Topic
Zakura, a team that builds a Zcash full node, says it is preparing a proposal to strengthen the network’s transparent payments against future cryptographic threats. In an engineering post, Zakura developer Roman Akhtariev described a goal of creating “full post-quantum safe transparent pools with hash based signatures.” The team expects post-quantum signature opcodes to land in Zcash in January. These opcodes are low-level instructions that would enable the network to verify a different type of digital signature.
The announcement comes amid a wider discussion in cryptocurrency about how users and networks should respond to the possibility that advances in artificial intelligence or quantum computing could weaken existing cryptography. Ethereum Foundation researcher Justin Drake recently urged holders to move funds to fresh addresses as a precaution, an approach described in the source as “bunker mode.” The public response to his warning was notably unsettled. Zakura’s proposal presents one possible technical response, but it addresses a specific part of Zcash rather than offering a complete solution for the broader crypto ecosystem.
To understand the proposal, it helps to distinguish between Zcash’s two payment types. Shielded payments are designed to conceal the sender, recipient, and transaction amount. Transparent payments, by contrast, are publicly visible, much like transactions on Bitcoin. A transparent address contains a hash of a public key. The key itself remains hidden until its owner spends from that address and reveals it onchain.
Zakura’s approach combines address rotation with a hash-based backup signature. Under the proposed approach, a wallet would use a fresh transparent address after each transaction. Rotating addresses can reduce the amount of public information associated with any one address and help keep public keys hidden until they are needed. The backup signature, known as WOTS, relies on hash-based cryptography.
Hash-based signature schemes are designed differently from the elliptic-curve methods used in many existing digital-signature systems. Researchers are concerned that sufficiently powerful quantum computers, or breakthroughs in AI-assisted mathematics, could eventually undermine some elliptic-curve cryptography. Hash-based signatures avoid that particular mathematical foundation. This does not mean they are automatically immune to every future attack, but it explains why they are being considered as a potential post-quantum alternative.
The proposal’s key distinction is that address rotation and signature protection solve different problems: one aims to limit key exposure, while the other aims to make signatures rely on a different cryptographic approach. Using both could strengthen transparent payments against certain risks, but it does not eliminate all security or privacy concerns.
Address rotation creates a separate privacy challenge. A wallet may need to ask a server to check balances across multiple addresses. If it sends those requests in a way that identifies each address, the server may be able to infer that the addresses belong to the same user. In that case, rotating addresses would not necessarily prevent the server from linking a person’s activity across them.
Zakura says it intends to address this linkability problem with private information retrieval, commonly abbreviated as PIR. This cryptographic technique is designed to let a wallet retrieve records from a server without revealing which records it is requesting. If applied as intended, PIR could allow a wallet to check information related to multiple addresses while disclosing less about which addresses it controls.
The source says the feature is rolling out this week in the Vizor wallet. Users can test it by switching on “private queries” in the wallet’s settings. This wallet feature is separate from the proposed network opcodes: private queries address how wallet requests may reveal user information, whereas the opcodes would allow Zcash to verify hash-based signatures.
In a post on X, Zakura summarized its position by writing: “While others are worrying about the viability of rotating transparent addresses, we’re already solving linkability.” The comment responds to concerns raised alongside Drake’s call for holders to move funds to new addresses. It also highlights that address rotation alone is not enough if supporting wallet infrastructure can associate the new addresses with one another.
Drake warned that AI-driven mathematical advances could potentially break the ECDSA signatures that secure Bitcoin and Ethereum before quantum computers do. In the worst case, he said, this could happen “in the worst case in months not years.” Ethereum co-founder Vitalik Buterin later called it “plausible” that AI-driven advances in mathematics could break encryption within the next two years. These statements describe risks and forecasts, not confirmed capabilities or a guaranteed timeline.
The scope of Zakura’s plan is limited. It concerns Zcash’s transparent payment side, not the network’s shielded payments as a whole. The engineering post did not state how or when the signature opcodes would be activated across the network. The expectation that they may arrive in January should therefore not be mistaken for a confirmed activation date. Their implementation, review, and deployment would still matter to any assessment of the proposal’s practical security.
The proposal arrives as Zcash attracts increased institutional attention. The source mentions another proposed U.S. ETF tied to the Winklevoss twins, as well as Europe’s first Zcash ETP. It also notes a recent upgrade intended to make private payments three times faster. These developments provide context for the network’s activity, but they are distinct from the technical plan for transparent addresses and post-quantum signatures.
Overall, Zakura’s approach brings together three related but separate ideas: rotate transparent addresses, use PIR to make address lookups less revealing, and add hash-based signatures as a potential defense against threats to current signature systems. Each addresses a different part of the problem. The approach’s effectiveness will depend on implementation details, security review, wallet behavior, and whether the proposed opcodes are ultimately adopted and activated.
Key Insights Table
| Aspect | Description |
|---|---|
| Proposed signature support | Zakura expects post-quantum signature opcodes to land in Zcash in January, enabling verification of hash-based signatures. No network activation date has been confirmed. |
| Address rotation | Wallets would move to a fresh transparent address after every transaction, helping keep public keys out of view until they are revealed through spending. |
| Hash-based backup | The proposed WOTS backup signature uses a hash-based approach rather than elliptic-curve mathematics. |
| Private information retrieval | PIR aims to let a wallet retrieve records without revealing which records it is requesting. The feature is rolling out this week in the Vizor wallet. |
| Scope and uncertainty | The plan concerns Zcash’s transparent payments. The source does not explain how or when the opcodes would be activated across the network. |
| Wider context | The discussion follows warnings from Justin Drake and Vitalik Buterin about possible AI-driven risks to encryption and occurs alongside growing institutional interest in Zcash. |
Afterwards...
Zakura’s proposal illustrates why preparing for future cryptographic threats involves more than selecting a new signature scheme. Wallets, network rules, and the way users query servers all influence whether funds and transaction histories remain secure and private. Further work should examine how hash-based signatures perform in real-world deployments, how their verification can be reviewed and standardized, and how private information retrieval behaves under practical operating conditions.
Researchers and developers should also continue to test assumptions about both AI-driven mathematical advances and quantum computing. Forecasts about when existing cryptography might become vulnerable remain uncertain, so planning should distinguish demonstrated capabilities from plausible scenarios. Open security reviews, clear migration procedures, and careful communication about what a proposal does—and does not—protect will be important for users and institutions alike.
The next meaningful step is to evaluate the full system, not just its cryptographic components: how addresses are generated and rotated, what information servers can observe, how software handles failures, and how network upgrades are adopted. If these pieces are examined together, Zcash’s proposal may help inform broader efforts to build cryptocurrency systems that can adapt to changing security risks without overstating what current defenses can guarantee.
Last edited at:2026/10/11
