Zakura, a Zcash engineering team, says it plans to add post-quantum signature opcodes to Zcash in January, according to its engineering post published in the past few days. The goal is to give transparent addresses a hash-based way to authorise spending that does not depend on elliptic-curve cryptography. TokenPost also reported the plan.
What the post says
Zcash has two kinds of address. A transparent address, the t1… kind, works much like bitcoin’s: it contains a hash of a public key, and spending from it publishes that key. Once the key is public, funds sitting at that address stay controlled by it, which is why address reuse is the weak point. I made the same argument about bitcoin in my 7 Oct note on the Europol quantum report, and the basics are in what a quantum attack on bitcoin means.
Zakura’s advice for anyone worried about advances in cryptography is to publish only the address, rotate to a fresh one on every transaction, and add a hash-based escape hatch such as WOTS, a Winternitz one-time signature, beside the usual key. It says this is usable today. A new wallet feature for private lookups, using a technique called private information retrieval, is due in the Vizor wallet this week and can be tested by toggling “Private queries”, the post says.
The January item is separate: opcodes that would let transparent coins be spent with such signatures, which the post says would make the transparent pool post-quantum safe.
Where it holds, and where it is open
The steelman is straightforward. Rotation plus a hash-based fallback is a real defence, because a hash is much harder for a quantum computer to undo than an elliptic-curve key. The post also treats the key-exposure problem honestly, noting that sharing an extended public key reveals more keys than an ordinary spend does.
The test is what the post does not say. It gives no activation date beyond “January”, it does not say who must approve the change or how it would be switched on, and it does not describe any change for Zcash’s shielded pools, which use different cryptography and would need separate work. A plan is also not a deployed upgrade.
My base case I will call the long fuse: more likely than not, chains with active engineering teams get a post-quantum option into the protocol well before quantum hardware can threaten it, and the harder work is persuading holders to move.
What would change my mind. A slipped January date with no new one; evidence that wallets cannot make rotation usable for ordinary people; or a verified jump in quantum hardware well ahead of current roadmaps.
The bottom line
Zcash is a useful test case for the migration problem that bitcoin also faces. The code is the easier half; getting exposed coins moved is the harder one.
The bottom line: a promised signature upgrade is welcome, but until it ships and holders use it, the exposure is where it was before the announcement.
— Alasdair
This article is for information only and is not investment advice.
