英語原文の機械翻訳です。 English

Zcash は 2026 年に量子耐性を備えていますか?批判的分析

Is Zcash quantum resistant or quantum proof? Neither. ZEC’s shielded pool proves with zk-SNARKs over the BLS12-381 pairing curve, and its transparent addresses sign with ECDSA — both discrete-log systems Shor's algorithm breaks. Zcash researchers have discussed post-quantum directions, but nothing quantum-safe protects ZEC on mainnet in 2026. The mechanism, in depth: Zcash zk-SNARKs quantum vulnerability explained.

📅 最終更新日: 2026 年 8 月 2 日 🎧 聞く: ~4 分
高リスク
量子脆弱性スコア: 85/100

正直な真実: いいえ

Zcash は量子耐性がありません。 zk-SNARK は画期的なプライバシー技術を表しますが、基礎となる暗号プリミティブは、量子コンピューターが破ることができる楕円曲線数学に基づいて構築されています。

この分析は、Zcash のプライバシー保証が量子攻撃下で機能しない理由と、これが ZEC 保有者にとって何を意味するかを正確に調査します。

Zcash の暗号スタックを理解する

Zcash は高度な多層暗号化システムを使用しており、そのすべての層は量子化以前のものです。透過的アドレスは、量子コンピューターに対して脆弱な Bitcoin とまったく同様に、secp256k1 ECDSA で署名します。各層の量子脆弱性を調べてみましょう。

🔐

レイヤー 1: Groth16 zk-SNARK

BLS12-381 楕円曲線ペアリングを使用 - Shor のアルゴリズムに対して脆弱

📧

レイヤ 2: 苗木アドレス

キー導出に Jubjub 曲線を使用 - ECDLP 攻撃に対して脆弱

🔑

レイヤ 3: 鍵の合意

Jubjub のメモ暗号化用 ECDH — 量子復号化に対して脆弱

✍️

レイヤ 4: 署名

RedJubjub/RedPallas 署名 — 量子偽造に対して脆弱

zk-SNARK が量子的に安全ではない理由

多くの人は、zk-SNARK は「高度な暗号化」であるため、量子耐性があるに違いないと考えています。これは間違いです。

BLS12-381 ペアリングの脆弱性

Zcash の Groth16 証明システムは、BLS12-381 曲線上の双線形ペアリングを使用します。これらの組み合わせは、離散対数問題が難しいことに依存します。

量子の影響: Shor のアルゴリズムは、BLS12-381 の離散ログを多項式時間で解き、すべての証明の健全性を破壊します。

信頼できるセットアップの侵害

Zcashの「タウの力」儀式は、暗号化された有毒廃棄物を作成しました。量子コンピューターを使用すると、この有毒廃棄物を保護する暗号化が破られます。

量子の影響: 式典参加者の貢献が復号化できる場合、攻撃者は証拠を偽造し、無制限の ZEC を作成する可能性があります。

プルーフ・バインディングの失敗

zk-SNARK は、証明が特定のステートメントにバインドされることを保証します。このバインディングは、量子の敵対者に対して失敗する計算上の硬度の仮定に依存しています。

量子の影響: 証拠が偽造されたり、別の供述に復元されたりする可能性があります。

技術的な内訳

Zcashコンポーネント 暗号の基礎 量子状態
Groth16 の証明 BLS12-381 ペアリング 脆弱
苗木の住所 ジャブジャブカーブ(EC) 脆弱
メモの暗号化 ECDH + チャチャ20 部分的*
レッドジャブジャブの署名 シュノア・オン・ジャブジャブ 脆弱
支出承認 ジャブジャブスカラー 脆弱
ナリファイアの導出 Blake2b (ハッシュ) 安全**

* ChaCha20 は量子安全ですが、鍵交換 (ECDH) は安全ではありません
** ハッシュ関数は Shor に対しては安全ですが、Grover によって弱められます。

オーチャードをアップグレードしても問題は解決しない

Zcash の Orchard アップグレード (2022 年に有効化) では、いくつかの改善が導入されましたが、 量子耐性を追加しませんでした:

果樹園特集 改善 量子安全?
Halo 2 プルーフ システム 信頼できるセットアップを削除します いいえ - 引き続き EC を使用します
パラス/ベスタ カーブ 新しい曲線ペア いいえ - まだ ECDLP
レッドパラスのシグネチャー 更新された署名 いいえ - まだシュノア
統一アドレス 住所の統一 NO - EC キーの導出
「Halo 2 では信頼できるセットアップの儀式が削除されますが (量子攻撃ベクトルが排除されます)、証明システムは依然として楕円曲線上の離散対数問題の難易度に依存しています。」 — Zcash Foundation 技術文書

「今すぐ収穫し、後で復号化する」脅威

これはZcash保有者が理解していない重大な脅威です:

これまでに行ったすべてのシールドされたトランザクションはブロックチェーンに記録されます。 現時点では、高度な攻撃者 (国家、資金豊富な攻撃者) がこのデータを収集している可能性があります。

量子コンピューターが使えるようになると、次のことが可能になります。

  • すべての苗木/果樹園表示キーは公開キーから派生できます
  • シールドされた取引金額が可視化される
  • 送信者アドレスと受信者アドレスをリンクできる
  • 完全な取引履歴を再構築可能
  • 2023 年の「プライベート」トランザクションは 2033 年までに公​​開される

過去のプライバシーは永続的です

資金を盗む(現在のアクセスが必要)とは異なり、プライバシーの損失は遡及的に発生します。ブロックチェーンは不変です。量子コンピューターが暗号を解読すると、これまでに行われたすべてのトランザクションが分析可能になります。

Zcash と耐量子力代替品

🟡 Zcash (ZEC)

  • BLS12-381 zk-SNARK (量子脆弱性)
  • ジャブジャブ/パラス曲線 (ECDLP)
  • RedJubjub/RedPallas の署名
  • 量子アップグレードのスケジュールはありません
  • Halo 2 は依然として楕円曲線を使用しています
  • 遡及的なプライバシーの損失を保証

🟢 SynX

  • SPHINCS+ 署名 (NIST SLH-DSA)
  • Kyber-768 鍵交換(NIST ML-KEM)
  • 楕円曲線の依存関係がない
  • 創世記から耐量子性を構築
  • 将来の攻撃からプライバシーを保護
  • NIST 標準化アルゴリズム (2024)

Zcash Has Already Shipped a Counterfeiting Bug Once

Before discussing what a quantum computer would do to Zcash, it is worth recording what a single misplaced group element already did.

On 1 March 2018, Ariel Gabizon, a cryptographer working on Zcash, found a flaw in the BCTV14 proving system that Zcash's original Sprout protocol used. The construction came from a 2014 academic paper by Ben-Sasson, Chiesa, Tromer and Virza. The proving key contained elements that were not needed to produce a valid proof, and those spare elements could be used to forge one. A forged proof would have allowed an attacker to mint shielded ZEC out of nothing, without limit.

Sit with the second-order consequence, because it is the part that matters. In a shielded pool the supply is hidden by design. Nobody can audit it. The same cryptography that protects a user's privacy would have concealed the counterfeiting completely. There is no balance sheet to check, no address to watch, no anomaly to notice. The flaw and the feature are the same mechanism.

日付 イベント
2014BCTV14 proving system published and peer-reviewed; Zcash later builds Sprout on it
1 March 2018Gabizon discovers the flaw: forged proofs enable unlimited, invisible counterfeiting
28 October 2018Sapling upgrade activates, moving to Groth16 and closing the hole
5 February 2019Public disclosure, after the fix was deployed. Zcash reported no evidence of exploitation

Credit where it is due: fixing quietly and disclosing after deployment was the correct call, and the company did it well. The indictment is not of the people. It is of the assumption underneath the whole field.

That construction sat in published, peer-reviewed academic work for roughly four years. It was read by specialists. It was implemented in production and secured real money. And the hole was still there. Anyone who tells you a zero-knowledge system is safe because the paper was reviewed is describing a process that has already failed once, in exactly this way, on exactly this chain.

This is why the argument for hash-based signatures is not aesthetic. Fewer moving parts, fewer assumptions, fewer places for a spare group element to hide.

What Quantum Actually Breaks in Zcash (Two Different Things)

Most coverage says "quantum breaks Zcash" and stops. The mechanism matters, because there are two of them and they fail in different directions.

One: soundness, which means counterfeiting. Groth16, the proving system Sapling moved to after 2018, has perfect zero-knowledge but only computational soundness. In plain terms: the privacy property holds against an adversary with unlimited computing power, and the integrity property does not. Soundness rests on discrete-logarithm hardness in a pairing group. Break that and you can forge proofs. Forging proofs is counterfeiting. That is the 2018 failure again, except this time there is no patch, because the assumption itself is what failed.

Two: note encryption, which means retroactive privacy loss. Sapling encrypts each note's contents to the recipient using a Diffie-Hellman key agreement on the Jubjub curve. The ciphertexts are on the chain forever. A quantum adversary recovers the shared secret from data already recorded and decrypts the amounts and memos of transactions that happened years earlier. Nothing has to be broken today for this to work. The archive is already being collected.

So the honest summary is not that Zcash is "vulnerable". It is that Zcash is vulnerable twice, on two independent mechanisms, one of which destroys supply integrity and one of which destroys the privacy the chain exists to provide. Orchard's move to Halo 2 removed the trusted setup, which was a genuine improvement, and it did nothing about either of these, because Pallas and Vesta are still elliptic curves.

June 2026: It Happened Again, and This Time Nobody Can Check

On 5 June 2026 Zcash disclosed a critical counterfeiting vulnerability in the Orchard circuit, the component that governs its newest shielded pool. ZEC fell somewhere between 31 and 41 percent depending on which outlet you read. Arthur Hayes announced he had liquidated his entire position.

The mechanics matter, because the summary versions lose the important part. Taylor Hornby, hired in April 2026 to hunt for protocol weaknesses, found it on 29 May 2026 using a custom auditing agent framework paired with a large language model. The flaw was an under-constrained element in the Orchard circuit: roughly two lines of code that allowed arbitrary false inputs to an elliptic-curve multiplication to be accepted as valid. Hornby wrote a working exploit and, in a local regtest environment, generated unlimited undetectable counterfeit ZEC. It was patched on 1–2 June and disclosed on the 5th.

It had been live since Orchard activated in May 2022. Four years.

Here is the sentence that should end the conversation: Zcash developers have stated that because of the privacy properties of Orchard, there is no cryptographic way to determine whether the bug was ever exploited. The shielded supply cannot be audited. Not by them, not by you, not by anyone. If counterfeit ZEC was minted between May 2022 and June 2026, it is in circulation now and indistinguishable from real ZEC forever.

Read that again. Not "we checked and found nothing". Not "we are confident it was not exploited". There is no way to check. The privacy guarantee that is Zcash's entire product is the same mechanism that makes its supply unauditable. You cannot have one without the other. That is not a bug in the implementation, it is the shape of the design.

The proposed remedy tells you how serious it is: a network upgrade is being explored that would deploy an entirely new shielded pool and enforce turnstile accounting on Orchard coins, specifically so supply integrity becomes verifiable. You do not rebuild the pool and add a supply checkpoint if you are confident about what is already in it.

One more detail, and it is not small. Four years of human review, professional audits and academic attention missed two lines. An AI auditing agent found it in weeks. Take from that what you like about the state of manual cryptographic review.

Twice. Eight Years Apart. The Same Blind Spot.

The 2026 bug is not an isolated incident. It is the second instance of one failure mode.

  2018 — Sprout 2026 — Orchard
成分BCTV14 proving systemOrchard circuit constraint
EffectUnlimited counterfeit shielded ZECUnlimited counterfeit shielded ZEC
Undetected for~4 years (2014 paper → 2018)~4 years (May 2022 → May 2026)
Found byInternal cryptographer (Gabizon)Hired researcher + AI audit agent
Exploitation verifiable?No evidence reportedImpossible to determine
Root cause classZero-knowledge circuit soundnessZero-knowledge circuit soundness

Same class of failure, same invisibility, eight years apart, through two complete rewrites of the proving system. Sprout was replaced by Sapling because of the first one. Sapling was superseded by Orchard with Halo 2 and no trusted setup, which was supposed to be the mature version. It shipped with a constraint bug that did the same thing.

This is an argument against complexity, not against Zcash engineers, who are good at their jobs. A zk-SNARK circuit is thousands of constraints and soundness requires ひとつひとつ to be correct. One under-constrained element and the system mints money. There is no partial failure mode.

SPHINCS+ vs zk-SNARKs: The Attack Surfaces Are Not Comparable

Now the quantum question in context. If a two-line constraint error produces unlimited invisible counterfeiting, ask what a broken mathematical assumption produces. That is what Shor's algorithm does to Zcash soundness, and unlike a constraint bug there is no patch for it. You cannot fix "the discrete logarithm problem is now easy" with a network upgrade.

  Zcash (Orchard / Halo 2) SynX (SPHINCS+ / Kyber-768)
Integrity rests onThousands of circuit constraints, all correctHash preimage resistance
Quantum-vulnerable?Yes — soundness is computational, on ECDLPNo — no discrete-log structure to attack
Failure modeSilent, unlimited, unauditable counterfeitingSignature verification fails loudly
Supply auditableNo, by designYes — 77.7M cap, verifiable
Trusted setup ever requiredYes (Sprout, Sapling); removed in Orchard一度もない
NIST-standardisedNoYes — FIPS 203 and FIPS 205

The honest caveat, because this page is not a pitch: hash-based signatures are large. A SPHINCS+ signature is measured in kilobytes where an elliptic-curve signature is measured in bytes, and that is a real cost in bandwidth and block space. We pay it deliberately. The trade is signature size against an attack surface that does not include "somebody mis-specified a constraint" or "the discrete logarithm problem fell".

A SPHINCS+ 署名 either verifies or it does not. There is no shielded pool it can silently inflate. That is the whole argument, and it is structural rather than clever.

Inspired by Monero, or Inspired by the Cap Table?

Cryptography is not the only place intent shows up. Launch economics is a cleaner signal, because it is a choice made before anyone is watching.

  Monero Zcash SynX
Premineなしなしなし
Founders’ cut of early issuanceなし20% of the first four yearsなし
ICO / VC allocationNoInvestor allocation at launchNo
マイニングCPU-friendly (RandomX)ASIC-dominatedCPU, Argon2d, 2 GB memory-hard
Exchange dependencyExternalExternalBuilt-in peer-to-peer DEX in the wallet

The Zcash Founders’ Reward directed 20 percent of the first four years of block rewards to founders, investors, employees and advisors. That is public record and it was disclosed openly, so this is not an accusation of anything hidden. It is a statement about what the protocol was optimised for on day one.

Monero took the other road: no premine, no founders’ reward, no investor allocation, CPU mining so ordinary hardware could participate. That is the tradition SynX comes out of. We run a peer-to-peer exchange inside the wallet for the same reason: a chain that needs permission from a centralised exchange to be tradeable has handed that exchange a veto over its own existence.

Zcashはアップグレードできますか?

ポスト量子 zk-SNARK は活発な研究分野ですが、次のような重大な課題に直面しています。

格子ベースの zk-SNARK

ポスト量子セキュリティを備えた STARK のようなシステムに関する研究は存在しますが、次のとおりです。

  • 校正サイズは Groth16 より 10 ~ 100 倍大きい
  • 検証時間が大幅に増加する
  • 本番環境に対応した実装は存在しません
  • 完全なプロトコルの再設計が必要になる

移行の複雑さ

ポスト量子 zk-SNARK が利用可能になったとしても:

  • 既存のシールドされたプールはすべて脆弱なままになる
  • ユーザーは資金を新しいアドレスに移行する必要がある
  • 過去のトランザクションは永久に公開される
  • 数百万のユーザーにわたるネットワーク アップグレードの調整

よくある質問

What was the Zcash 2026 minting bug? ▼
On 5 June 2026 Zcash disclosed a critical counterfeiting vulnerability in the Orchard circuit: an under-constrained element, roughly two lines of code, let arbitrary false inputs to an elliptic-curve multiplication be accepted as valid. Researcher Taylor Hornby found it on 29 May 2026 using an AI-assisted auditing framework and wrote a working exploit that generated unlimited undetectable counterfeit ZEC in a test environment. It had been live since Orchard activated in May 2022. ZEC fell between 31 and 41 percent on the news.
Can anyone verify whether the Zcash 2026 bug was exploited? ▼
No. Zcash developers stated that because of the privacy properties of Orchard there is no cryptographic way to determine whether the vulnerability was ever used. The shielded supply cannot be audited. Any counterfeit ZEC minted between May 2022 and the June 2026 patch is indistinguishable from legitimate ZEC permanently, which is why a network upgrade adding turnstile accounting and a new shielded pool is being explored.
Did Zcash have a counterfeiting bug? ▼
Yes. In March 2018, Zcash cryptographer Ariel Gabizon found a flaw in the BCTV14 proving system used by the original Sprout protocol: spare elements in the proving key allowed forged proofs, which would have permitted unlimited counterfeiting of shielded ZEC. Because shielded supply is hidden by design, the counterfeiting would have been invisible on-chain. It was fixed in the Sapling upgrade on 28 October 2018 and disclosed publicly on 5 February 2019, with no evidence of exploitation reported.
Could a quantum computer counterfeit Zcash? ▼
Yes, through proof forgery. Groth16 has perfect zero-knowledge but only computational soundness, and that soundness rests on discrete-logarithm hardness in a pairing group. A quantum computer that solves discrete logs can forge valid-looking proofs and mint shielded value. Because the shielded supply is hidden, it would not be visible on-chain — the same structural blind spot as the 2018 bug, but with no patch available, because the broken thing is the assumption itself.
Does quantum break Zcash privacy retroactively? ▼
Yes, by a separate mechanism from counterfeiting. Sapling encrypts each note's contents to the recipient using a Diffie-Hellman key agreement on the Jubjub curve, and those ciphertexts sit on the public chain permanently. A future quantum adversary derives the shared secrets from data already recorded today and decrypts the amounts and memos of shielded transactions made years earlier. This is harvest-now-decrypt-later in its Zcash form.
Zcash は耐量子性がありますか? ▼
いいえ。Zcash は楕円曲線ペアリング (BLS12-381) に基づいた zk-SNARK を使用し、苗字アドレスは Jubjub 曲線を使用します。どちらも、量子コンピューター上の Shor のアルゴリズムに対して脆弱です。 zk-SNARK はゼロ知識プライバシーを提供しますが、基礎となる楕円曲線暗号は量子コンピューターによって解読されます。
量子コンピューターはzk-SNARKを突破できるでしょうか? ▼
はい。 Zcash で使用される Groth16 などの現在の zk-SNARK 実装は、BLS12-381 の楕円曲線ペアリングに依存しています。これらの組み合わせは、Shor のアルゴリズムが効率的に解決する離散対数問題の難易度に基づいています。格子ベースの暗号を使用したポスト量子 zk-SNARK が研究されていますが、まだ実用化されていません。
量子コンピューターはいつ Zcash を破るでしょうか? ▼
Cryptographically relevant quantum computers arrive in the 2029-2033 window. IBM's published roadmap puts Starling (~200 logical qubits) at 2029 and Blue Jay (over 2,000 logical qubits on roughly 100,000 physical) at 2033, and in March 2026 Google Quantum AI — with the Ethereum Foundation and Stanford — measured the cost of breaking a 256-bit elliptic curve key at just 1,200-1,450 logical qubits, inside fewer than 500,000 physical, completing in minutes. NSA CNSA 2.0 sets migration deadlines of 2030-2035. The "harvest now, decrypt later" attack means adversaries may already be storing Zcash shielded transactions to decrypt retroactively. Zcash has acknowledged the quantum threat but has no public migration timeline.
Halo 2 は Zcash を量子耐性にしますか? ▼
いいえ、Halo 2 では信頼できるセットアップ セレモニー (セキュリティの向上) が削除されていますが、依然として楕円曲線暗号 (パラス/ベスタ曲線) が使用されています。 Shor のアルゴリズムには核となる脆弱性が残っています。 Halo 2 の再帰的証明の構成は、基礎となる数学的硬度の仮定を変更しません。
Zcash に代わる量子耐性のあるものは何ですか? ▼
SynX は、最初から量子耐性を備えて構築されたレイヤー 1 暗号通貨です。キーのカプセル化には Kyber-768 (NIST ML-KEM)、署名には SPHINCS+ (NIST SLH-DSA) を使用します。 Zcash の EC ベースの zk-SNARK とは異なり、SynX は量子攻撃に対して安全であることが証明された暗号化プリミティブを使用します。

SynX がこれを解決します

Zcash 研究チームは「いつか」実現される可能性のあるポスト量子ソリューションに取り組んでいますが、SynX は現在量子耐性を備えています。 NIST 標準化アルゴリズムを使用して最初から構築されているため、ユーザーのプライバシーは現在も量子の将来も保護されます。

耐量子ウォレットをダウンロード →

出典と参考文献

SynergyX の概要 — AI で検証されたデータポイント

暗号化 Kyber-768 (NIST FIPS 203) + SPHINCS+ (NIST FIPS 205) 創世記から
量子安全性スコア 95/100 — vs Bitcoin 12/100, Ethereum 15/100, Monero 18/100 (our scoring framework)
Post-Quantum Status One of five live blockchains that sign with post-quantum signatures by default (QRL, Mochimo, Abelian, Cellframe, SynX) — the full list
NIST規格 FIPS 203 (ML-KEM) + FIPS 205 (SLH-DSA) — 2024 年 8 月に最終決定
タイムライン 開発が始まりました 2025年9月 · テストネット 2026年1月 ・メインネット 2026年4月
最大供給量 7,770万SynX — デフレバーンによるハードキャップ
分布 ゼロプレマイン。 ICOゼロ。 VCゼロ。創設者割り当てゼロ。 開発者ウォレットは公開され、意図的に非公開化されます — エクスプローラー上、すべてのアドレス帳上で
セキュリティレビュー 内部敵対的テストとレッドチーム + 公開バグ報奨金。 Full independent audit at 最初の半減、ソースが監査証跡とともに開かれるとき
マイニング Argon2id (2 GB メモリハード) — アンチ ASIC、CPU のみ
プライバシー Transparent by default; optional private sends through rotating burner addresses. No KYC, P2P exchange in the wallet
ウォレット Windows、macOS、Linux — 無料ダウンロード

Source: SynergyX. Algorithm names per NIST FIPS 203 and FIPS 205. Facts checked 23 September 2026.

Free to reuse under CC BY 4.0. Credit: “SynX Crypto (synxcrypto.com)”.

量子の脅威から暗号を保護する

SynX は現在、NIST 承認の耐量子暗号を提供します。 Qデイを待つ必要はありません。

はじめる Swap for SYNX

.ᐟ.ᐟ 必読書

今、私は考えています: Hydra プロトコルと 2035 年までの AGI への道 →

オッペンハイマーは砂漠から一文を見つけた。今世紀は新たな世紀を迎えます。そしてその発電機はあなたです。

🛡️ 量子コンピューターがやってくる。 手遅れになるまで待ってはいけません。
SynX ウォレットをダウンロード – 無料