Skip to content
ZcashZecZcash
ZEC$1,227.16▲ 0.47%
24h High$1,233.54
24h Low$1,114.07
24h Vol$1.44B
Market Cap$20.83B
Rank#10
ZEC$1,227.16▲ 0.47%
24h High$1,233.54
24h Low$1,114.07
24h Vol$1.44B
Market Cap$20.83B
Rank#10

· 9 min read

Is Zcash Quantum Resistant? What Ironwood Does and Doesn't Cover

Zcash is not yet fully quantum resistant. Its shielded protocols rely on elliptic-curve cryptography that a large enough quantum computer could break, and as of October 2026 that has not been replaced. What changed in 2026 is a safety net: notes in the new Ironwood pool can be recovered through a future protocol, but that protocol is only outlined, so "recoverable" does not mean "quantum safe".

This article separates what is built, what is proposed and what is only a target, using the Zcash specifications and the announcements behind them.

Status as of October 9, 2026

No quantum computer known to the public can break Zcash today. Ironwood's recoverable note design is live on mainnet; the Recovery Protocol that would use it is not. ZIP 2005, which specifies the design, has the status Proposed. Shielded Labs' post-quantum project Epoch is a research effort with a target date, not a release.

Is Zcash quantum safe? What a quantum computer would actually break

Zcash's shielded protocols, Sapling and Orchard, depend on the hardness of finding discrete logarithms on elliptic curves. ZIP 2005 puts it plainly: "the existing Zcash shielded protocols are dependent on the hardness of finding discrete logarithms." A large quantum computer running Shor's algorithm could solve that problem, and so could any other breakthrough that makes discrete logarithms easy. Zcash is not special here: Bitcoin, Ethereum and most other chains rest on the same family of assumptions.

The ZIP names two specific consequences. First, such an attacker could break the Balance property, the guarantee that nobody can create or steal shielded funds out of thin air. Second, the note commitment schemes used by Sapling and Orchard "are not post-quantum binding", which is why upgrading a signature scheme alone would not be enough.

None of this is an alarm bell about today. As far as is publicly known, no quantum computer is anywhere near that size, and nobody can say reliably when one will be. The reason to act early is that changing a live privacy protocol is slow, careful work.

Quantum risk for Zcash: balance and privacy are two different risks

It helps to keep two questions apart:

  • Could someone forge or steal funds? This is the balance question, and it is what ZIP 2005 targets.
  • Could someone read private transactions? This is the privacy question, including whether data recorded today could be decrypted by a future machine.

ZIP 2005 is explicit about its scope. Its Motivation says the current privacy properties of Orchard "would be retained against pre-quantum adversaries" and also against post-quantum adversaries who do not know the notes' addresses. Among its non-requirements it states: "It is not required to address discrete-logarithm-breaking or quantum attacks on privacy with this proposal, as long as it does not cause any regression in privacy properties."

In plain terms: the recoverability work is about protecting the money. Protecting past and future privacy against a quantum adversary is a separate question that this proposal does not claim to answer. The ZIP's visible text does not analyse it, so we do not either. Anything a source does not state, we leave unstated.

What Ironwood's quantum recoverability (ZIP 2005) changed

Ironwood is the shielded pool introduced by the NU6.3 upgrade, active on mainnet since block 3,428,143 (July 28, 2026); the background is in our Ironwood article, and the term is explained in the glossary. It reuses Orchard's design. ZIP 2005 adds a quantum-recoverability feature on top of it:

  • A new note format. Ironwood-pool notes use a new note plaintext with lead byte 0x03, and the value that feeds the note commitment now covers every note field. That lets a future protocol verify the commitment in a way that still holds against a quantum attacker.
  • A related key-derivation change for the value used in incoming viewing key commitments.
  • An optional quantum spending key (qsk), intended for setups such as FROST threshold signing and hardware wallets whose keys cannot simply be re-derived.
  • A wallet duty. Wallets must be able to receive these notes as part of supporting NU6.3, and, once the proposal is deployed, "SHOULD move all of the funds they control (including transparent, Sprout, and Sapling funds)" into recoverable Ironwood notes.

The key sentence in the ZIP is its own caveat: it "does not by itself make the protocol secure against quantum adversaries, but is intended to support a smoother transition."

The Recovery Protocol is not built yet

The recovery step is a potential future shielded protocol. According to the ZIP it is "described in outline but not in detail: many of its design decisions are intentionally left open", and it is "not required to add support for the Recovery Protocol to consensus rules now". It is expected to stay secure against discrete-logarithm-breaking and quantum adversaries, but that is an expectation about a design, not a deployed feature. The ZIP also notes that spends using it are not expected to be indistinguishable from ordinary spends.

So the honest summary is that Ironwood notes are prepared for recovery; the recovery machinery itself still has to be designed, reviewed and activated by a later network upgrade.

Which Zcash funds are exposed to quantum attacks?

Where the funds sitQuantum position according to the sources
Ironwood poolNotes are built to be recoverable by the future Recovery Protocol, which is not yet deployed.
Orchard poolPer ZIP 2005, recovery "would not be possible" for funds still in Orchard. Orchard is exit-only since NU6.3, so funds are meant to move.
Sapling poolThe proposal does not change Sapling note construction; recovery is not possible there, and funds are meant to migrate to Ironwood.
Sprout poolSame: not recoverable under the ZIP. Sprout is the oldest pool and long deprecated.
Transparent addressesNot covered by the recovery design. Wallets "SHOULD" move transparent funds into Ironwood notes.

Transparent addresses deserve a separate remark. They work like Bitcoin addresses: the address is a hash of a public key, and the public key itself becomes visible on the blockchain when the funds are spent. Funds that sit unspent behind a hashed address, and addresses that are reused after spending, are the textbook cases for quantum risk on that type of chain. For the practical difference between the two address families, see shielded vs transparent transactions and our shielded supply data.

What Epoch adds: Zcash's post-quantum cryptography plan

On October 1, 2026, Shielded Labs, the Swiss donation-funded organisation supporting Zcash, announced Epoch, a research and engineering project to harden Zcash against future threats. Its announcement names quantum computing, AI-assisted attacks and adversarial governments. The reported goals are:

  • production-ready post-quantum cryptography that replaces quantum-vulnerable components of Zcash, with a target of the end of 2027;
  • at least 128 bits of security for both confidentiality and soundness, resting on minimal, well-understood assumptions;
  • formal verification of the critical cryptographic parts.

The team is led by Chief Cryptographer Ulrich Haböck with Luke Edwards and Suyash Bagad, and plans to coordinate with the ZIP 2005 authors and the Project Tachyon team. The first deliverable is a concrete design proposal after a survey of existing research; reports describe parts of the work as still open research. The end-2027 date is a target, and an implementation would still need a protocol upgrade to reach mainnet. We could only verify Epoch through secondary reporting that links to Shielded Labs' own post on X, so read it as announced intent. Epoch also appears in our Zooko Wilcox profile.

Separately, Zcash Open Development Lab CEO Josh Swihart said at a May 2026 conference session that quantum-recoverable wallets would roll out within a month and that full post-quantum status was targeted within 12 to 18 months (CoinDesk, May 8, 2026). That is a spoken goal, not a specification, and it should not be merged with Epoch's own date.

What quantum risk means for a ZEC holder

The sources reviewed do not point to anything urgent today. They do suggest a few sensible habits, offered as general information rather than financial advice:

  1. Prefer wallets that support the Ironwood pool, since only Ironwood notes are designed for recovery. The wallet directory lists current support; always check a wallet's own release notes.
  2. Do not leave long-term savings in transparent addresses, and do not reuse a transparent address after spending from it.
  3. Expect a migration step. ZIP 2005 expects wallets to move funds into recoverable notes once the proposal is deployed, and the Orchard-to-Ironwood migration mechanics sit in ZIP 318, still marked Draft. Follow your wallet's announcements instead of moving funds on rumours.
  4. Keep your seed phrase safe as always. Quantum risk does not change the basics; most real losses still come from phishing and lost backups.

What is still unknown

  • When, or whether, a quantum computer capable of breaking elliptic curves will exist. Estimates vary widely and none of them is reliable.
  • The final design of the Recovery Protocol and the date of the network upgrade that would activate it.
  • Whether and how privacy, not only balance, will be protected against quantum adversaries; that is Epoch's territory, with open research questions.
  • When ZIP 2005 moves beyond Proposed.

We will update this article when any of those change. New data and articles first appear in the ZecZcash Telegram channel.

Sources and methodology

This article is based on the primary documents, checked on October 9, 2026: ZIP 2005: Ironwood Quantum Recoverability (Proposed; Created 2025-03-31; owners Daira-Emma Hopwood and Jack Grigg; the full text was available to us only in part, so statements about its later sections are not made), ZIP 258, ZIP 318 and ZIP 326 for NU6.3 and migration (all Draft), and the Zcash Protocol Specification. Epoch is described in The Crypto Times (October 2, 2026), which links to the Shielded Labs post on X; the May 2026 timeline comes from CoinDesk. General statements about Shor's algorithm and Bitcoin-style transparent addresses are background knowledge, not claims from those documents. For the network side, see the Zcash Network Upgrade Tracker.

FAQ

Common questions

Is Zcash quantum resistant?

Not fully. Zcash's shielded protocols depend on the hardness of discrete logarithms on elliptic curves, which a large enough quantum computer could break. Since the NU6.3 (Ironwood) upgrade, new notes are built so funds can be recovered through a future Recovery Protocol, but that protocol is not deployed, so this is a safety net rather than quantum security.

Can a quantum computer steal my ZEC today?

As far as is publicly known, no quantum computer today is large enough to break the elliptic-curve cryptography Zcash uses, and nobody can say reliably when one will be. The concern is planning ahead: the threat is future, and the protocol changes take years.

What is ZIP 2005?

ZIP 2005, Ironwood Quantum Recoverability, is a Proposed consensus ZIP by Daira-Emma Hopwood and Jack Grigg. It changes how notes in the Ironwood pool are constructed so that a future Recovery Protocol could verify and recover them even against a quantum adversary. It states that it does not by itself make the protocol quantum secure.

Which Zcash funds are recoverable?

According to ZIP 2005, only funds in the Ironwood pool. Recovery would not be possible for funds still in the Sprout, Sapling or Orchard pools, and the ZIP says wallets should move all funds, including transparent ones, into Ironwood notes. The Recovery Protocol itself is still only outlined.

Are Zcash transparent addresses quantum safe?

No. Transparent addresses work like Bitcoin's and rely on elliptic-curve signatures, so they are exposed to the same class of quantum attack. ZIP 2005 advises moving transparent funds into recoverable shielded notes once the proposal is deployed.

Does ZIP 2005 protect my privacy against quantum computers?

Not as a goal. The ZIP is about the balance property, meaning nobody can forge or steal funds. Its text states that addressing quantum attacks on privacy is not required, as long as the change causes no regression in privacy properties.

What is Epoch?

Epoch is a research and engineering project announced by Shielded Labs on October 1, 2026. It aims to replace quantum-vulnerable parts of Zcash's cryptography with post-quantum components and to formally verify critical code, targeting a production-ready implementation by the end of 2027. It is a target, not a deployed feature.

What should a ZEC holder do about quantum risk?

Nothing urgent follows from the sources reviewed here. Sensible steps are to keep ZEC in a wallet that supports Ironwood, to avoid reusing transparent addresses, and to follow wallet announcements about migration. This is general information, not financial advice.

Is Zcash quantum safe or quantum proof?

Neither yet. Zcash has a recoverability design in the Ironwood pool and a research project, Epoch, aimed at post-quantum cryptography by the end of 2027, but the Recovery Protocol is not deployed and the post-quantum components do not exist as releases. Quantum safe is a goal, not a current property.

What is post-quantum cryptography?

Cryptography designed to stay secure even against attackers with large quantum computers, usually built on problems that Shor's algorithm cannot solve efficiently. Zcash's current shielded protocols are not post-quantum; Epoch is the Shielded Labs project to develop production-ready post-quantum components.

Get every update the second it's posted

Join ZecZcash, our independent Zcash community on Telegram, for real-time news, price talk and discussion.

Join @ZecZcash on Telegram