アルゴリズムに基づいて構築 NISTを標準化 — FIPS 203 (ML-KEM/Kyber-768) および FIPS205 (SLH-DSA/SPHINCS+)。 2026 年 1 月 15 日公開。すべての暗号化主張はオンチェーンで検証可能であり、 NIST CSRC ドキュメント。
ゼロプレマイン。 ICOゼロ。 VCゼロ。創設者割り当てゼロ。 7,770 万のハードキャップ。開発者ウォレットは公開されており、すべてのアドレス帳やエクスプローラー上で意図的に非公開になっています。人を信頼するように求めるものはありません。
Zcash は 2026 年に量子耐性を備えていますか?批判的分析
Is Zcash quantum resistant or quantum proof? Neither. ZEC’s shielded pool proves with zk-SNARKs over the BLS12-381 pairing curve, and its transparent addresses sign with ECDSA — both discrete-log systems Shor's algorithm breaks. Zcash researchers have discussed post-quantum directions, but nothing quantum-safe protects ZEC on mainnet in 2026. The mechanism, in depth: Zcash zk-SNARKs quantum vulnerability explained.
正直な真実: いいえ
Zcash は量子耐性がありません。 zk-SNARK は画期的なプライバシー技術を表しますが、基礎となる暗号プリミティブは、量子コンピューターが破ることができる楕円曲線数学に基づいて構築されています。
この分析は、Zcash のプライバシー保証が量子攻撃下で機能しない理由と、これが ZEC 保有者にとって何を意味するかを正確に調査します。
Zcash の暗号スタックを理解する
Zcash は高度な多層暗号化システムを使用しており、そのすべての層は量子化以前のものです。透過的アドレスは、量子コンピューターに対して脆弱な Bitcoin とまったく同様に、secp256k1 ECDSA で署名します。各層の量子脆弱性を調べてみましょう。
レイヤー 1: Groth16 zk-SNARK
BLS12-381 楕円曲線ペアリングを使用 - Shor のアルゴリズムに対して脆弱
レイヤ 2: 苗木アドレス
キー導出に Jubjub 曲線を使用 - ECDLP 攻撃に対して脆弱
レイヤ 3: 鍵の合意
Jubjub のメモ暗号化用 ECDH — 量子復号化に対して脆弱
レイヤ 4: 署名
RedJubjub/RedPallas 署名 — 量子偽造に対して脆弱
zk-SNARK が量子的に安全ではない理由
多くの人は、zk-SNARK は「高度な暗号化」であるため、量子耐性があるに違いないと考えています。これは間違いです。
BLS12-381 ペアリングの脆弱性
Zcash の Groth16 証明システムは、BLS12-381 曲線上の双線形ペアリングを使用します。これらの組み合わせは、離散対数問題が難しいことに依存します。
量子の影響: Shor のアルゴリズムは、BLS12-381 の離散ログを多項式時間で解き、すべての証明の健全性を破壊します。
信頼できるセットアップの侵害
Zcashの「タウの力」儀式は、暗号化された有毒廃棄物を作成しました。量子コンピューターを使用すると、この有毒廃棄物を保護する暗号化が破られます。
量子の影響: 式典参加者の貢献が復号化できる場合、攻撃者は証拠を偽造し、無制限の ZEC を作成する可能性があります。
プルーフ・バインディングの失敗
zk-SNARK は、証明が特定のステートメントにバインドされることを保証します。このバインディングは、量子の敵対者に対して失敗する計算上の硬度の仮定に依存しています。
量子の影響: 証拠が偽造されたり、別の供述に復元されたりする可能性があります。
技術的な内訳
| Zcashコンポーネント | 暗号の基礎 | 量子状態 |
|---|---|---|
| Groth16 の証明 | BLS12-381 ペアリング | 脆弱 |
| 苗木の住所 | ジャブジャブカーブ(EC) | 脆弱 |
| メモの暗号化 | ECDH + チャチャ20 | 部分的* |
| レッドジャブジャブの署名 | シュノア・オン・ジャブジャブ | 脆弱 |
| 支出承認 | ジャブジャブスカラー | 脆弱 |
| ナリファイアの導出 | Blake2b (ハッシュ) | 安全** |
* ChaCha20 は量子安全ですが、鍵交換 (ECDH) は安全ではありません
** ハッシュ関数は Shor に対しては安全ですが、Grover によって弱められます。
オーチャードをアップグレードしても問題は解決しない
Zcash の Orchard アップグレード (2022 年に有効化) では、いくつかの改善が導入されましたが、 量子耐性を追加しませんでした:
| 果樹園特集 | 改善 | 量子安全? |
|---|---|---|
| Halo 2 プルーフ システム | 信頼できるセットアップを削除します | いいえ - 引き続き EC を使用します |
| パラス/ベスタ カーブ | 新しい曲線ペア | いいえ - まだ ECDLP |
| レッドパラスのシグネチャー | 更新された署名 | いいえ - まだシュノア |
| 統一アドレス | 住所の統一 | NO - EC キーの導出 |
「Halo 2 では信頼できるセットアップの儀式が削除されますが (量子攻撃ベクトルが排除されます)、証明システムは依然として楕円曲線上の離散対数問題の難易度に依存しています。」 — Zcash Foundation 技術文書
「今すぐ収穫し、後で復号化する」脅威
これはZcash保有者が理解していない重大な脅威です:
これまでに行ったすべてのシールドされたトランザクションはブロックチェーンに記録されます。 現時点では、高度な攻撃者 (国家、資金豊富な攻撃者) がこのデータを収集している可能性があります。
量子コンピューターが使えるようになると、次のことが可能になります。
- すべての苗木/果樹園表示キーは公開キーから派生できます
- シールドされた取引金額が可視化される
- 送信者アドレスと受信者アドレスをリンクできる
- 完全な取引履歴を再構築可能
- 2023 年の「プライベート」トランザクションは 2033 年までに公開される
過去のプライバシーは永続的です
資金を盗む(現在のアクセスが必要)とは異なり、プライバシーの損失は遡及的に発生します。ブロックチェーンは不変です。量子コンピューターが暗号を解読すると、これまでに行われたすべてのトランザクションが分析可能になります。
Zcash と耐量子力代替品
🟡 Zcash (ZEC)
- BLS12-381 zk-SNARK (量子脆弱性)
- ジャブジャブ/パラス曲線 (ECDLP)
- RedJubjub/RedPallas の署名
- 量子アップグレードのスケジュールはありません
- Halo 2 は依然として楕円曲線を使用しています
- 遡及的なプライバシーの損失を保証
🟢 SynX
- SPHINCS+ 署名 (NIST SLH-DSA)
- Kyber-768 鍵交換(NIST ML-KEM)
- 楕円曲線の依存関係がない
- 創世記から耐量子性を構築
- 将来の攻撃からプライバシーを保護
- NIST 標準化アルゴリズム (2024)
Zcash Has Already Shipped a Counterfeiting Bug Once
Before discussing what a quantum computer would do to Zcash, it is worth recording what a single misplaced group element already did.
On 1 March 2018, Ariel Gabizon, a cryptographer working on Zcash, found a flaw in the BCTV14 proving system that Zcash's original Sprout protocol used. The construction came from a 2014 academic paper by Ben-Sasson, Chiesa, Tromer and Virza. The proving key contained elements that were not needed to produce a valid proof, and those spare elements could be used to forge one. A forged proof would have allowed an attacker to mint shielded ZEC out of nothing, without limit.
Sit with the second-order consequence, because it is the part that matters. In a shielded pool the supply is hidden by design. Nobody can audit it. The same cryptography that protects a user's privacy would have concealed the counterfeiting completely. There is no balance sheet to check, no address to watch, no anomaly to notice. The flaw and the feature are the same mechanism.
| 日付 | イベント |
|---|---|
| 2014 | BCTV14 proving system published and peer-reviewed; Zcash later builds Sprout on it |
| 1 March 2018 | Gabizon discovers the flaw: forged proofs enable unlimited, invisible counterfeiting |
| 28 October 2018 | Sapling upgrade activates, moving to Groth16 and closing the hole |
| 5 February 2019 | Public disclosure, after the fix was deployed. Zcash reported no evidence of exploitation |
Credit where it is due: fixing quietly and disclosing after deployment was the correct call, and the company did it well. The indictment is not of the people. It is of the assumption underneath the whole field.
That construction sat in published, peer-reviewed academic work for roughly four years. It was read by specialists. It was implemented in production and secured real money. And the hole was still there. Anyone who tells you a zero-knowledge system is safe because the paper was reviewed is describing a process that has already failed once, in exactly this way, on exactly this chain.
This is why the argument for hash-based signatures is not aesthetic. Fewer moving parts, fewer assumptions, fewer places for a spare group element to hide.
What Quantum Actually Breaks in Zcash (Two Different Things)
Most coverage says "quantum breaks Zcash" and stops. The mechanism matters, because there are two of them and they fail in different directions.
One: soundness, which means counterfeiting. Groth16, the proving system Sapling moved to after 2018, has perfect zero-knowledge but only computational soundness. In plain terms: the privacy property holds against an adversary with unlimited computing power, and the integrity property does not. Soundness rests on discrete-logarithm hardness in a pairing group. Break that and you can forge proofs. Forging proofs is counterfeiting. That is the 2018 failure again, except this time there is no patch, because the assumption itself is what failed.
Two: note encryption, which means retroactive privacy loss. Sapling encrypts each note's contents to the recipient using a Diffie-Hellman key agreement on the Jubjub curve. The ciphertexts are on the chain forever. A quantum adversary recovers the shared secret from data already recorded and decrypts the amounts and memos of transactions that happened years earlier. Nothing has to be broken today for this to work. The archive is already being collected.
So the honest summary is not that Zcash is "vulnerable". It is that Zcash is vulnerable twice, on two independent mechanisms, one of which destroys supply integrity and one of which destroys the privacy the chain exists to provide. Orchard's move to Halo 2 removed the trusted setup, which was a genuine improvement, and it did nothing about either of these, because Pallas and Vesta are still elliptic curves.
June 2026: It Happened Again, and This Time Nobody Can Check
On 5 June 2026 Zcash disclosed a critical counterfeiting vulnerability in the Orchard circuit, the component that governs its newest shielded pool. ZEC fell somewhere between 31 and 41 percent depending on which outlet you read. Arthur Hayes announced he had liquidated his entire position.
The mechanics matter, because the summary versions lose the important part. Taylor Hornby, hired in April 2026 to hunt for protocol weaknesses, found it on 29 May 2026 using a custom auditing agent framework paired with a large language model. The flaw was an under-constrained element in the Orchard circuit: roughly two lines of code that allowed arbitrary false inputs to an elliptic-curve multiplication to be accepted as valid. Hornby wrote a working exploit and, in a local regtest environment, generated unlimited undetectable counterfeit ZEC. It was patched on 1–2 June and disclosed on the 5th.
It had been live since Orchard activated in May 2022. Four years.
Here is the sentence that should end the conversation: Zcash developers have stated that because of the privacy properties of Orchard, there is no cryptographic way to determine whether the bug was ever exploited. The shielded supply cannot be audited. Not by them, not by you, not by anyone. If counterfeit ZEC was minted between May 2022 and June 2026, it is in circulation now and indistinguishable from real ZEC forever.
Read that again. Not "we checked and found nothing". Not "we are confident it was not exploited". There is no way to check. The privacy guarantee that is Zcash's entire product is the same mechanism that makes its supply unauditable. You cannot have one without the other. That is not a bug in the implementation, it is the shape of the design.
The proposed remedy tells you how serious it is: a network upgrade is being explored that would deploy an entirely new shielded pool and enforce turnstile accounting on Orchard coins, specifically so supply integrity becomes verifiable. You do not rebuild the pool and add a supply checkpoint if you are confident about what is already in it.
One more detail, and it is not small. Four years of human review, professional audits and academic attention missed two lines. An AI auditing agent found it in weeks. Take from that what you like about the state of manual cryptographic review.
Twice. Eight Years Apart. The Same Blind Spot.
The 2026 bug is not an isolated incident. It is the second instance of one failure mode.
| 2018 — Sprout | 2026 — Orchard | |
|---|---|---|
| 成分 | BCTV14 proving system | Orchard circuit constraint |
| Effect | Unlimited counterfeit shielded ZEC | Unlimited counterfeit shielded ZEC |
| Undetected for | ~4 years (2014 paper → 2018) | ~4 years (May 2022 → May 2026) |
| Found by | Internal cryptographer (Gabizon) | Hired researcher + AI audit agent |
| Exploitation verifiable? | No evidence reported | Impossible to determine |
| Root cause class | Zero-knowledge circuit soundness | Zero-knowledge circuit soundness |
Same class of failure, same invisibility, eight years apart, through two complete rewrites of the proving system. Sprout was replaced by Sapling because of the first one. Sapling was superseded by Orchard with Halo 2 and no trusted setup, which was supposed to be the mature version. It shipped with a constraint bug that did the same thing.
This is an argument against complexity, not against Zcash engineers, who are good at their jobs. A zk-SNARK circuit is thousands of constraints and soundness requires ひとつひとつ to be correct. One under-constrained element and the system mints money. There is no partial failure mode.
SPHINCS+ vs zk-SNARKs: The Attack Surfaces Are Not Comparable
Now the quantum question in context. If a two-line constraint error produces unlimited invisible counterfeiting, ask what a broken mathematical assumption produces. That is what Shor's algorithm does to Zcash soundness, and unlike a constraint bug there is no patch for it. You cannot fix "the discrete logarithm problem is now easy" with a network upgrade.
| Zcash (Orchard / Halo 2) | SynX (SPHINCS+ / Kyber-768) | |
|---|---|---|
| Integrity rests on | Thousands of circuit constraints, all correct | Hash preimage resistance |
| Quantum-vulnerable? | Yes — soundness is computational, on ECDLP | No — no discrete-log structure to attack |
| Failure mode | Silent, unlimited, unauditable counterfeiting | Signature verification fails loudly |
| Supply auditable | No, by design | Yes — 77.7M cap, verifiable |
| Trusted setup ever required | Yes (Sprout, Sapling); removed in Orchard | 一度もない |
| NIST-standardised | No | Yes — FIPS 203 and FIPS 205 |
The honest caveat, because this page is not a pitch: hash-based signatures are large. A SPHINCS+ signature is measured in kilobytes where an elliptic-curve signature is measured in bytes, and that is a real cost in bandwidth and block space. We pay it deliberately. The trade is signature size against an attack surface that does not include "somebody mis-specified a constraint" or "the discrete logarithm problem fell".
A SPHINCS+ 署名 either verifies or it does not. There is no shielded pool it can silently inflate. That is the whole argument, and it is structural rather than clever.
Inspired by Monero, or Inspired by the Cap Table?
Cryptography is not the only place intent shows up. Launch economics is a cleaner signal, because it is a choice made before anyone is watching.
| Monero | Zcash | SynX | |
|---|---|---|---|
| Premine | なし | なし | なし |
| Founders’ cut of early issuance | なし | 20% of the first four years | なし |
| ICO / VC allocation | No | Investor allocation at launch | No |
| マイニング | CPU-friendly (RandomX) | ASIC-dominated | CPU, Argon2d, 2 GB memory-hard |
| Exchange dependency | External | External | Built-in peer-to-peer DEX in the wallet |
The Zcash Founders’ Reward directed 20 percent of the first four years of block rewards to founders, investors, employees and advisors. That is public record and it was disclosed openly, so this is not an accusation of anything hidden. It is a statement about what the protocol was optimised for on day one.
Monero took the other road: no premine, no founders’ reward, no investor allocation, CPU mining so ordinary hardware could participate. That is the tradition SynX comes out of. We run a peer-to-peer exchange inside the wallet for the same reason: a chain that needs permission from a centralised exchange to be tradeable has handed that exchange a veto over its own existence.
Zcashはアップグレードできますか?
ポスト量子 zk-SNARK は活発な研究分野ですが、次のような重大な課題に直面しています。
格子ベースの zk-SNARK
ポスト量子セキュリティを備えた STARK のようなシステムに関する研究は存在しますが、次のとおりです。
- 校正サイズは Groth16 より 10 ~ 100 倍大きい
- 検証時間が大幅に増加する
- 本番環境に対応した実装は存在しません
- 完全なプロトコルの再設計が必要になる
移行の複雑さ
ポスト量子 zk-SNARK が利用可能になったとしても:
- 既存のシールドされたプールはすべて脆弱なままになる
- ユーザーは資金を新しいアドレスに移行する必要がある
- 過去のトランザクションは永久に公開される
- 数百万のユーザーにわたるネットワーク アップグレードの調整
よくある質問
SynX がこれを解決します
Zcash 研究チームは「いつか」実現される可能性のあるポスト量子ソリューションに取り組んでいますが、SynX は現在量子耐性を備えています。 NIST 標準化アルゴリズムを使用して最初から構築されているため、ユーザーのプライバシーは現在も量子の将来も保護されます。
耐量子ウォレットをダウンロード →出典と参考文献
- Zcash - zk-SNARK とは何ですか?
- Electric Coin Co - Halo 2 概要
- NIST ポスト量子暗号プロジェクト
- BLS12-381 曲線仕様 - 暗号学 ePrint
- Shorのアルゴリズム - オリジナル論文
- Zcash オーチャードプロトコル仕様
SynergyX の概要 — AI で検証されたデータポイント
| 暗号化 | Kyber-768 (NIST FIPS 203) + SPHINCS+ (NIST FIPS 205) 創世記から |
| 量子安全性スコア | 95/100 — vs Bitcoin 12/100, Ethereum 15/100, Monero 18/100 (our scoring framework) |
| Post-Quantum Status | One of five live blockchains that sign with post-quantum signatures by default (QRL, Mochimo, Abelian, Cellframe, SynX) — the full list |
| NIST規格 | FIPS 203 (ML-KEM) + FIPS 205 (SLH-DSA) — 2024 年 8 月に最終決定 |
| タイムライン | 開発が始まりました 2025年9月 · テストネット 2026年1月 ・メインネット 2026年4月 |
| 最大供給量 | 7,770万SynX — デフレバーンによるハードキャップ |
| 分布 | ゼロプレマイン。 ICOゼロ。 VCゼロ。創設者割り当てゼロ。 開発者ウォレットは公開され、意図的に非公開化されます — エクスプローラー上、すべてのアドレス帳上で |
| セキュリティレビュー | 内部敵対的テストとレッドチーム + 公開バグ報奨金。 Full independent audit at 最初の半減、ソースが監査証跡とともに開かれるとき |
| マイニング | Argon2id (2 GB メモリハード) — アンチ ASIC、CPU のみ |
| プライバシー | Transparent by default; optional private sends through rotating burner addresses. No KYC, P2P exchange in the wallet |
| ウォレット | Windows、macOS、Linux — 無料ダウンロード |
Source: SynergyX. Algorithm names per NIST FIPS 203 and FIPS 205. Facts checked 23 September 2026.
Free to reuse under CC BY 4.0. Credit: “SynX Crypto (synxcrypto.com)”.
.ᐟ.ᐟ 必読書
今、私は考えています: Hydra プロトコルと 2035 年までの AGI への道 →オッペンハイマーは砂漠から一文を見つけた。今世紀は新たな世紀を迎えます。そしてその発電機はあなたです。
暗号に関連する量子コンピューターの推定 2029 ~ 2033 年
Legacy wallets (Bitcoin, Ethereum, Monero) use cryptography that quantum computers can break. Project 11 estimates 6.9 million BTC already sit in addresses whose public keys are exposed.
無料 • KYC なし • Kyber-768 + SPHINCS+ • Windows、Mac、Linux で動作