Coiniversity

Free crypto content for clarity, not hype.

← All articles

September 1, 2026Crypto Drood18 min read

What is ZCash (ZEC)?

  • ZCash (ZEC)
  • Privacy Coins

What is ZCash (ZEC)?


The Proof Without the Story: Why Zcash Exists, and Why ZEC Might Matter

Imagine you need to prove you paid a bill.

One way is to hand over your entire bank statement. The landlord sees the rent. The landlord also sees the clinic, the donation, the relative you helped, and every other line you never meant to share. The statement is honest. It is also a biography.

Another way is cash. Cash proves nothing later. The landlord cannot follow it backward, and you cannot prove, years from now, that the envelope was yours.

Zcash was built for a third option: a receipt that can stay sealed for the world and still open for the one person you choose. The mathematics can prove that a payment was real, that no coins were forged, and that the books still balance - without publishing who paid whom, or how much moved. If you later need to show an accountant, a court, or your future self what happened, you can hand over a viewing key. Everyone else still sees a wall of ciphertext.

That is a strange kind of money. It is also a serious answer to a problem Bitcoin never tried to solve.


A paper, a company, and a ceremony

The story starts in a university, not a forum.

In 2013, Johns Hopkins cryptographer Matthew Green and graduate students Ian Miers and Christina Garman published Zerocoin: a way to take Bitcoin’s public coins, drop them into a cryptographic mixing pool, and pull out coins that no longer carried a history. Bitcoin developers were not about to graft that machinery onto the base chain. The idea kept growing. With Alessandro Chiesa and Madars Virza at MIT, Eli Ben-Sasson at the Technion, and Eran Tromer at Tel Aviv University, the design became Zerocash - a full private payment system built on a then-exotic tool called a zk-SNARK.

A zero-knowledge proof is a way to convince someone a statement is true without saying anything else. You can prove you know a password without revealing the password. You can prove a hidden number is positive without revealing the number. Applied to money, you can prove a transaction is legal - the sender had the coins, the amounts add up, nothing was printed from thin air - while leaving sender, receiver, and amount in the dark.

Someone still had to turn the papers into a living network. Zooko Wilcox, a longtime cypherpunk who had already built encrypted file storage, took the job. The vehicle was a for-profit company, first called the Zerocoin Electric Coin Company and later the Electric Coin Company. Venture money arrived. A nonprofit, the Zcash Foundation, was created to hold the protocol at arm’s length from the firm that wrote most of the code. The project was never a volunteer fork of a volunteer fork. It was a scientific prototype with a payroll.

Launch required a ritual that still haunts the project’s reputation. Early zk-SNARKs needed a trusted setup: a ceremony that produced public parameters and, as a byproduct, a secret that could be used to counterfeit coins. If every participant destroyed their shard of that secret, the trapdoor vanished. If even one honest participant shredded their piece, the others could not reconstruct it. In October 2016 a small group of cryptographers ran the ceremony in separate rooms on separate continents. Years later Edward Snowden confirmed he had been one of them, under a pseudonym. The network went live on October 28, 2016.

The design choice that followed was as consequential as the math. Zcash copied Bitcoin’s monetary skeleton - 21 million coins, halvings about every four years, proof of work - and then added a second, quieter layer. You could use Zcash the way you use Bitcoin, with a transparent address anyone can watch. Or you could send coins into a shielded pool, where the interesting facts disappear. Privacy was a mode, not a law.

That option is the whole personality of the coin. It is why exchanges kept listing it after they dropped other privacy assets. It is also why critics have spent a decade saying Zcash is private only for people who remember to close the curtain.


What “shielded” actually means

A Zcash payment can look like Bitcoin, or it can look like fog.

Transparent addresses work the way Bitcoin addresses work. The chain shows the amount, the destination, and the history attached to those coins. If you never leave this layer, Zcash has not given you privacy. It has given you a Bitcoin replica with a famous name.

Shielded addresses are the point of the project. A fully shielded payment hides the sender, the receiver, and the amount. The network still checks a proof that the payment is legal. Nodes do not learn the story inside the proof.

The cryptography has been rebuilt more than once, because the first versions were too heavy and too trusting.

The original pool, Sprout, was the 2016 prototype. Creating a private payment on a laptop could take minutes. The trusted setup sat underneath it like a buried charge. Sapling, activated in October 2018, made shielded payments fast enough for a phone. Orchard, switched on with Network Upgrade 5 in May 2022, used a proving system called Halo 2 and dropped the trusted setup for new shielded money. That was the scientific victory the founders had wanted since the ceremony: privacy without a room full of people promising they had burned a key.

Then, in late May 2026, an independent researcher named Taylor Hornby found a soundness bug in the Orchard circuit - a flaw that could, in theory, have let someone create coins that were never mined. The network paused new Orchard activity, patched the circuit in an emergency upgrade on June 3, and, on July 28, opened a new shielded pool called Ironwood. Funds leaving the old Orchard pool now pass through a public turnstile: an accounting gate that will not let more value out than was verifiably put in. If counterfeit coins were ever minted in the dark, they stay trapped on the far side of that gate. Anyone running a node can add up the active pools and check that the circulating supply still matches the issuance schedule.

That episode is not a footnote. It is what hidden money costs. When amounts are public, a counterfeit announces itself. When amounts are private, the defense has to live in the proof system, and the proof system can be wrong.

Around the pools sit the features that make Zcash a different argument from Monero.

Viewing keys split seeing from spending. You can give an accountant, an auditor, or a regulator a key that decrypts your shielded history and still keep the key that moves the coins. The disclosure is selective. The rest of the world still sees noise. The key, once shared, cannot be taken back - a fact wallets should say out loud.

Unified addresses, introduced with Orchard, hide some of the plumbing. A recipient can publish one string that accepts transparent or shielded payments, instead of asking every sender to understand which generation of pool is current.

The design choice that still defines the coin is the one made in 2016. Shielding is optional. A user who deposits on an exchange, withdraws to a transparent address, and never touches a shielded wallet has used Zcash as a ticker. A user who keeps coins in Ironwood, pays from that pool, and only discloses with a viewing key has used Zcash as a protocol. Both behaviors are valid under the rules. Only one of them is the reason the protocol exists.

As of early September 2026, roughly 29 percent of all issued ZEC sits in shielded pools - about 4.9 million coins, most of them now in Ironwood, with smaller remnants still migrating out of Sapling and the sealed Orchard pool. On a typical recent day, about half of transactions are shielded. Five years earlier the shielded share of supply was in the single digits. The curtain is being used more than it used to be. Most of the money is still standing in the open.


The token, in plain English

ZEC is the money on that chain. It is not a work token, a fee coupon for a company’s API, or a vote that can fire the lab. It is the unit miners earn, users send, and wallets hold.

The supply schedule is Bitcoin’s on purpose. There will only ever be 21 million ZEC. New coins arrive in each block, and the block subsidy halves about every four years. After the Blossom upgrade, blocks arrive every seventy-five seconds or so - faster than Bitcoin - and the halving interval was stretched so the calendar still matches. The second halving landed in November 2024 and cut the subsidy to 1.5625 ZEC per block. The third is due in late 2028. As of early September 2026, a little under 17 million ZEC have been issued, a bit more than four fifths of the cap. The last coins will dribble out for decades.

Who received the early coins is the part of the story Bitcoin maximalists never forgive.

There was no premine dumped on day one, and no ICO. There was a Founders’ Reward. For the first four years, 20 percent of each block subsidy went to the company, the foundation, early employees, and investors. Over that window the slice amounted to 2.1 million ZEC - 10 percent of the eventual 21 million. Miners received the other 80 percent. After the first halving, the founders’ cut ended and a development fund took its place: still 20 percent of the subsidy, now split among the Electric Coin Company, the Zcash Foundation, and a grants program. In November 2024 the named-company streams were stripped out of the protocol. Since Network Upgrade 6.1 in November 2025, the split has been 80 percent to miners, 8 percent to Zcash Community Grants, and 12 percent to a coinholder-controlled fund seeded by coins that had accumulated in an on-chain lockbox. That arrangement runs until the third halving, when the community will have to decide again.

The honest reading of that history is mixed. The founders’ slice paid for world-class cryptography at a moment when volunteer privacy projects were underfunded. It also created a class of early recipients whose wealth arrived by rule rather than by mining. Later upgrades pushed allocation toward grants and coinholder direction. The protocol is less of a company treasury than it was in 2016. It is not, and has never been, a commons with empty pockets.

Mining uses Equihash, a memory-hard proof of work chosen to make specialized chips less of a runaway advantage than they became on Bitcoin. Specialized hardware arrived anyway. Large miners exist. The security model is the familiar one: computers burn electricity to make rewriting history expensive, and they are paid in the coin they defend.

What is ZEC for, besides existing?

You pay fees in it. You receive it when you sell something or when a machine finds a block. You can hold it as a scarce bearer asset with an optional privacy mode and a viewing key if you ever need to open the envelope. There is no staking program. There is no on-chain parliament that lets holders fire a foundation. Use is the utility - use as money that can go dark, and use as money that can, when asked, produce a receipt.


Why this token, among thousands?

Crypto is crowded with coins that added a mixing button to a transparent ledger and called the result privacy. A smaller set made privacy mandatory and accepted exile from polite exchanges as the price. Zcash sits on a third path, and the path is the argument.

Zero-knowledge proofs, used well, are a stronger kind of hiding than a crowd of decoys. A ring signature says “it was one of these sixteen.” A SNARK says “this payment is valid, and that is all you get.” When both parties stay inside the current shielded pool, the mathematical assurance is closer to a sealed vault than to a disguise in a hallway. That is the technical claim, and it is real.

The social claim is different, and it is why the token keeps being listed in places that have dropped Monero.

If private digital cash is only useful to people who will never talk to a bank, an exchange, or a tax office, it will remain a tool for a subculture. Zcash’s wager is that privacy becomes durable when it can selectively stop being private. A freelancer can receive shielded pay and still hand a viewing key to an accountant. A company can keep customer payments off the public graph and still satisfy an auditor. A regulated venue can list the asset, confine itself to transparent deposits, and tell a compliance officer there is a path through the system that looks like Bitcoin. Whether that compromise is wisdom or a dilution depends on what you wanted privacy for.

There is a second, quieter reason ZEC is not interchangeable with the next privacy ticker. The 21 million cap and the halving clock give it a monetary story institutions already know how to recite. Scarcity is not a privacy feature. It is a translation feature. It lets someone who does not care about SNARKs still recognize the asset as a cousin of Bitcoin rather than as an uncapped experiment.

The question the token exists to keep asking is not “can money hide?” Plenty of designs can hide. The question is whether electronic cash can hide and still produce a proof when a legitimate demand arrives - and whether a coin that offers that combination can stay honest when the hiding is optional and the proofs are complicated enough to break.


What can go wrong

It would be dishonest to stop at the wow.

Optional privacy splits the money. Coins that have only ever lived on transparent addresses carry a history. Coins that have passed through the shielded pool and come back out can pick up a different kind of attention at the exit. If most holders never shield, the anonymity set stays smaller than the market cap implies, and “taint” has somewhere to stick. Monero’s mandatory design refuses that split by force. Zcash accepts it as the cost of remaining speakable to institutions. Recent usage is the best it has been in years. Most supply is still transparent. Until the shielded pool is where ordinary wallets send by default, the cryptography is stronger than the crowd standing behind it.

Hidden money can hide a bug. The 2026 Orchard flaw did not steal anyone’s viewing key. It threatened something worse: coins that should not exist. The response was fast by the standards of a global network - a soft fork, a circuit fix, a new pool, a turnstile. Speed is not the same as comfort. Users had to migrate. Exchanges had to keep up. For a few weeks the market had to trust that the counterfeit, if it existed, could be sealed in. Ironwood restores the ability to add up the supply from the active pools. It does not make the next proof system immortal. Formal verification and extra audits reduce the odds. They do not reduce them to zero.

The trusted setup is retired for new pools, not erased from history. Sprout and Sapling still rest on ceremonies. Orchard’s successor no longer does. Coins that never leave the old pools still carry the old assumption: that every participant who could have kept a shard actually destroyed it. Most users will never think about this. The people who think about it professionally will not stop until those pools are empty.

Governance is a company story wearing a protocol’s clothes. In January 2026 the entire engineering and product team at the Electric Coin Company resigned after a fight with Bootstrap, the nonprofit board that governed the firm. They formed a new lab and kept building wallets and protocol work. The chain did not halt. The episode still said something true: Zcash’s most important software has often lived inside organizations with boards, employment contracts, and disagreements about whether a wallet should be a public good or a product. Grants and coinholder votes are an attempt to fund the work without recreating a single official company. Attempts of that kind can mature. They can also turn into a permanent argument about who is allowed to steer.

Regulators have not granted a permanent exemption. Optional transparency has kept ZEC on major exchanges that removed mandatory-privacy coins. That is an established fact. It is not a treaty. The European Union’s anti-money-laundering rulebook still points at anonymity-enhancing crypto, with the sharpest restrictions on licensed firms arriving in 2027. Some venues already confine Zcash to transparent rails. A future rule that treats any shielded pool as disqualifying would not need to understand viewing keys. It would only need to decide that the option to hide is the problem. In January 2026 the U.S. Securities and Exchange Commission closed a long inquiry into the Zcash Foundation without an enforcement action. That removed one cloud. It did not rewrite European law.

Quantum computers are a special nightmare for a privacy coin. Zcash’s current proofs and addresses rest on elliptic curves. A machine that can break those curves could forge and, in some designs, look backward. Ironwood added quantum-resistant records for future recovery work. That is a plan, not a finished shield. Copying a shielded chain today and opening it later is the attack privacy researchers lose sleep over. Knowledge of the problem is not the same as a migrated user base.

You cannot audit hidden amounts by eye. Issuance follows a public formula. Independent dashboards reconstruct supply pool by pool. What you cannot do is open every shielded note and add the numbers, because the numbers are the secret. The proofs are supposed to make hidden inflation impossible. If a proof system is wrong in a subtle way, the failure may not advertise itself until someone builds a turnstile. That is the tax on confidential amounts. Most users will never think about it. After 2026, the people who run the network will never stop.

None of these are secret. They are the price of trying to build an envelope that can stay closed and still be opened on purpose.


What would have to go right

Zcash is easy to misunderstand because the best version of it looks like ordinary payment.

A merchant gets paid. The public chain records that a valid transfer occurred. A stranger with a copy of the ledger cannot write the rest of the story. Years later, if a tax office asks, the merchant can produce a key that opens only their own envelope. That is a small miracle by the standards of consumer finance, and it is supposed to feel boring.

For ZEC itself to remain more than a listed souvenir of a famous paper, a few things have to keep lining up.

Shielding has to become the default path in the wallets people actually open, not an advanced toggle. The Ironwood pool has to finish absorbing the older pools so that “the current anonymity set” and “the money” are roughly the same object. The proof systems have to keep surviving contact with auditors who are now using the same class of tools that found the last bug. Development has to stay funded after the company-shaped era without turning every upgrade into a referendum. Peer-to-peer and self-custodial routes have to work if regulated firms are told they may list the ticker but not the shielded pool. And enough ordinary users - not only traders rotating a narrative - have to want a payment that can keep a secret and still produce a receipt.

That is a narrow road. It is also a more interesting one than most of the tokens that will be launched this year.

The distinctive claim is not that Zcash invented privacy, or that ZEC is scarce in a way no other asset is scarce. The distinctive claim is that a public ledger can carry a proof instead of a story, and that the person who owns the story should be the one who decides when it is told. Zcash took that job when zero-knowledge proofs were still an academic instrument. It is still doing that job, after a ceremony, a founders’ tax, a company schism, and a summer spent building a turnstile so that hidden money could be counted again.

Whether the coin becomes the way ordinary software hides a payment, or remains a specialist tool that most holders never shield, is the open question. The proof is real. The curtain is optional. The world that wants to look behind every curtain is not optional at all.

That is not a prophecy. It is a design, under load, in public.

Continue learning

Related articles you may find useful.

  • Sep 11, 2026

    Privacy Coins - The Right to Pay Without an Audience

    Privacy coins are not trying to make crime easier, they are trying to restore a property money already had for centuries - the ability to spend without inviting the neighborhood to watch.

  • Sep 3, 2026

    What is Monero (XMR)?

    Every transaction hides three things - who sent it, who received it, and how much moved.

  • Sep 5, 2026

    What is Hyperliquid (HYPE)?

    Imagine an exchange whose rules run in the open, and whose history is a chain that anyone can inspect.

Coiniversity

Free crypto content for clarity, not hype.

© 2026 Coiniversity