英文原文的机器翻译。 English

2026 年 Zcash 具有量子抗性吗?批判性分析

Is Zcash quantum resistant or quantum proof? Neither. ZEC’s shielded pool proves with zk-SNARKs over the BLS12-381 pairing curve, and its transparent addresses sign with ECDSA — both discrete-log systems Shor's algorithm breaks. Zcash researchers have discussed post-quantum directions, but nothing quantum-safe protects ZEC on mainnet in 2026. The mechanism, in depth: Zcash zk-SNARKs quantum vulnerability explained.

📅 最后更新时间:2026 年 8 月 2 日 🎧 听:~4 分钟
高风险
量子漏洞评分:85/100

诚实的事实:没有

Zcash 不具有量子抗性。 虽然 zk-SNARK 代表了突破性的隐私技术,但底层的加密原语是建立在量子计算机将打破的椭圆曲线数学基础上的。

该分析准确检验了 Zcash 的隐私保证在量子攻击下失败的原因,以及这对 ZEC 持有者意味着什么。

了解 Zcash 的加密堆栈

Zcash采用复杂的多层密码系统,每一层都是前量子的。透明地址用 secp256k1 ECDSA 签名,与 Bitcoin 一样,容易受到量子计算机的攻击。让我们检查一下每一层的量子漏洞:

🔐

第 1 层:Groth16 zk-SNARK

使用 BLS12-381 椭圆曲线配对 — 容易受到 Shor 算法的影响

📧

第 2 层:树苗地址

使用 Jubjub 曲线进行密钥推导 — 容易受到 ECDLP 攻击

🔑

第三层:密钥协议

Jubjub 上用于票据加密的 ECDH — 容易受到量子解密的影响

✍️

第 4 层:签名

RedJubjub/RedPallas 签名 — 容易被量子伪造

为什么 zk-SNARK 不是量子安全的

许多人认为,由于 zk-SNARK 是“高级密码学”,因此它们一定具有量子抗性。这是不正确的。

BLS12-381 配对漏洞

Zcash 的 Groth16 证明系统在 BLS12-381 曲线上使用双线性配对。这些配对取决于离散对数问题的难度。

量子影响: Shor的算法在多项式时间内解决了BLS12-381上的离散对数,打破了所有证明的健全性。

可信设置妥协

Zcash 的“tau 力量”仪式创造了加密的有毒废物。有了量子计算机,保护这种有毒废物的加密就被打破了。

量子影响: 如果任何仪式参与者的贡献可以被解密,攻击者就可以伪造证明并创建无限的 ZEC。

证明绑定失败

zk-SNARK 保证证明与特定语句绑定。这种绑定依赖于计算难度假设,而这些假设无法对抗量子对手。

量子影响: 证据可能会被伪造或反弹到不同的陈述。

技术分析

Zcash 组件 密码学基础 量子状态
Groth16 证明 BLS12-381 配对 易受伤害的
树苗地址 Jubjub 曲线 (EC) 易受伤害的
注释加密 ECDH + ChaCha20 部分的*
RedJubjub 签名 施诺尔在朱布朱布 易受伤害的
支出授权 朱布朱布标量 易受伤害的
无效化推导 Blake2b(哈希) 安全的**

* ChaCha20 是量子安全的,但密钥交换 (ECDH) 不是
** 哈希函数对于 Shor 是安全的,但会被 Grover 削弱

果园升级并不能解决这个问题

Zcash 的 Orchard 升级(2022 年激活)引入了多项改进,但 没有添加量子电阻:

果园特色 改进 量子安全?
Halo 2 证明系统 删除受信任的设置 否 - 仍然使用 EC
智神星/灶神星曲线 新曲线对 否 - 仍然是 ECDLP
RedPallas 签名 更新签名 否 - 仍然施诺尔
统一地址 地址统一 NO - EC 密钥派生
“虽然光环 2 取消了可信设置仪式(消除了量子攻击向量),但证明系统仍然依赖于椭圆曲线上离散对数问题的难度。” — Zcash 基金会技术文档

“现在收获,稍后解密”的威胁

这是 Zcash 持有者不了解的严重威胁:

您进行的每笔受保护交易都会记录在区块链上。 目前,老练的对手(民族国家、资金充足的攻击者)可能正在获取这些数据。

当量子计算机变得有能力时:

  • 所有树苗/果园查看密钥都可以从公钥派生
  • 隐藏的交易金额变得可见
  • 发件人和收件人地址可以链接
  • 完整的交易历史是可重建的
  • 您 2023 年的“私人”交易将在 2033 年公开

历史隐私是永久的

与窃取资金(需要当前访问权限)不同,隐私损失具有追溯力。区块链是不可变的——一旦量子计算机破解了密码学,你所做的每一笔交易都将是可分析的。

Zcash 与抗量子替代品

🟡 Zcash (ZEC)

  • BLS12-381 zk-SNARK(量子易受攻击)
  • Jubjub/Pallas 曲线 (ECDLP)
  • RedJubjub/RedPallas 签名
  • 无量子升级时间表
  • Halo 2 仍然使用椭圆曲线
  • 保证追溯隐私损失

🟢SynX

  • SPHINCS+ 签名 (NIST SLH-DSA)
  • Kyber-768 密钥交换 (NIST ML-KEM)
  • 无椭圆曲线依赖性
  • 从一开始就具有抗量子能力
  • 保护隐私免受未来攻击
  • NIST 标准化算法(2024)

Zcash Has Already Shipped a Counterfeiting Bug Once

Before discussing what a quantum computer would do to Zcash, it is worth recording what a single misplaced group element already did.

On 1 March 2018, Ariel Gabizon, a cryptographer working on Zcash, found a flaw in the BCTV14 proving system that Zcash's original Sprout protocol used. The construction came from a 2014 academic paper by Ben-Sasson, Chiesa, Tromer and Virza. The proving key contained elements that were not needed to produce a valid proof, and those spare elements could be used to forge one. A forged proof would have allowed an attacker to mint shielded ZEC out of nothing, without limit.

Sit with the second-order consequence, because it is the part that matters. In a shielded pool the supply is hidden by design. Nobody can audit it. The same cryptography that protects a user's privacy would have concealed the counterfeiting completely. There is no balance sheet to check, no address to watch, no anomaly to notice. The flaw and the feature are the same mechanism.

日期 事件
2014BCTV14 proving system published and peer-reviewed; Zcash later builds Sprout on it
1 March 2018Gabizon discovers the flaw: forged proofs enable unlimited, invisible counterfeiting
28 October 2018Sapling upgrade activates, moving to Groth16 and closing the hole
5 February 2019Public disclosure, after the fix was deployed. Zcash reported no evidence of exploitation

Credit where it is due: fixing quietly and disclosing after deployment was the correct call, and the company did it well. The indictment is not of the people. It is of the assumption underneath the whole field.

That construction sat in published, peer-reviewed academic work for roughly four years. It was read by specialists. It was implemented in production and secured real money. And the hole was still there. Anyone who tells you a zero-knowledge system is safe because the paper was reviewed is describing a process that has already failed once, in exactly this way, on exactly this chain.

This is why the argument for hash-based signatures is not aesthetic. Fewer moving parts, fewer assumptions, fewer places for a spare group element to hide.

What Quantum Actually Breaks in Zcash (Two Different Things)

Most coverage says "quantum breaks Zcash" and stops. The mechanism matters, because there are two of them and they fail in different directions.

One: soundness, which means counterfeiting. Groth16, the proving system Sapling moved to after 2018, has perfect zero-knowledge but only computational soundness. In plain terms: the privacy property holds against an adversary with unlimited computing power, and the integrity property does not. Soundness rests on discrete-logarithm hardness in a pairing group. Break that and you can forge proofs. Forging proofs is counterfeiting. That is the 2018 failure again, except this time there is no patch, because the assumption itself is what failed.

Two: note encryption, which means retroactive privacy loss. Sapling encrypts each note's contents to the recipient using a Diffie-Hellman key agreement on the Jubjub curve. The ciphertexts are on the chain forever. A quantum adversary recovers the shared secret from data already recorded and decrypts the amounts and memos of transactions that happened years earlier. Nothing has to be broken today for this to work. The archive is already being collected.

So the honest summary is not that Zcash is "vulnerable". It is that Zcash is vulnerable twice, on two independent mechanisms, one of which destroys supply integrity and one of which destroys the privacy the chain exists to provide. Orchard's move to Halo 2 removed the trusted setup, which was a genuine improvement, and it did nothing about either of these, because Pallas and Vesta are still elliptic curves.

June 2026: It Happened Again, and This Time Nobody Can Check

On 5 June 2026 Zcash disclosed a critical counterfeiting vulnerability in the Orchard circuit, the component that governs its newest shielded pool. ZEC fell somewhere between 31 and 41 percent depending on which outlet you read. Arthur Hayes announced he had liquidated his entire position.

The mechanics matter, because the summary versions lose the important part. Taylor Hornby, hired in April 2026 to hunt for protocol weaknesses, found it on 29 May 2026 using a custom auditing agent framework paired with a large language model. The flaw was an under-constrained element in the Orchard circuit: roughly two lines of code that allowed arbitrary false inputs to an elliptic-curve multiplication to be accepted as valid. Hornby wrote a working exploit and, in a local regtest environment, generated unlimited undetectable counterfeit ZEC. It was patched on 1–2 June and disclosed on the 5th.

It had been live since Orchard activated in May 2022. Four years.

Here is the sentence that should end the conversation: Zcash developers have stated that because of the privacy properties of Orchard, there is no cryptographic way to determine whether the bug was ever exploited. The shielded supply cannot be audited. Not by them, not by you, not by anyone. If counterfeit ZEC was minted between May 2022 and June 2026, it is in circulation now and indistinguishable from real ZEC forever.

Read that again. Not "we checked and found nothing". Not "we are confident it was not exploited". There is no way to check. The privacy guarantee that is Zcash's entire product is the same mechanism that makes its supply unauditable. You cannot have one without the other. That is not a bug in the implementation, it is the shape of the design.

The proposed remedy tells you how serious it is: a network upgrade is being explored that would deploy an entirely new shielded pool and enforce turnstile accounting on Orchard coins, specifically so supply integrity becomes verifiable. You do not rebuild the pool and add a supply checkpoint if you are confident about what is already in it.

One more detail, and it is not small. Four years of human review, professional audits and academic attention missed two lines. An AI auditing agent found it in weeks. Take from that what you like about the state of manual cryptographic review.

Twice. Eight Years Apart. The Same Blind Spot.

The 2026 bug is not an isolated incident. It is the second instance of one failure mode.

  2018 — Sprout 2026 — Orchard
成分BCTV14 proving systemOrchard circuit constraint
EffectUnlimited counterfeit shielded ZECUnlimited counterfeit shielded ZEC
Undetected for~4 years (2014 paper → 2018)~4 years (May 2022 → May 2026)
Found byInternal cryptographer (Gabizon)Hired researcher + AI audit agent
Exploitation verifiable?No evidence reportedImpossible to determine
Root cause classZero-knowledge circuit soundnessZero-knowledge circuit soundness

Same class of failure, same invisibility, eight years apart, through two complete rewrites of the proving system. Sprout was replaced by Sapling because of the first one. Sapling was superseded by Orchard with Halo 2 and no trusted setup, which was supposed to be the mature version. It shipped with a constraint bug that did the same thing.

This is an argument against complexity, not against Zcash engineers, who are good at their jobs. A zk-SNARK circuit is thousands of constraints and soundness requires 每一个 to be correct. One under-constrained element and the system mints money. There is no partial failure mode.

SPHINCS+ vs zk-SNARKs: The Attack Surfaces Are Not Comparable

Now the quantum question in context. If a two-line constraint error produces unlimited invisible counterfeiting, ask what a broken mathematical assumption produces. That is what Shor's algorithm does to Zcash soundness, and unlike a constraint bug there is no patch for it. You cannot fix "the discrete logarithm problem is now easy" with a network upgrade.

  Zcash (Orchard / Halo 2) SynX (SPHINCS+ / Kyber-768)
Integrity rests onThousands of circuit constraints, all correctHash preimage resistance
Quantum-vulnerable?Yes — soundness is computational, on ECDLPNo — no discrete-log structure to attack
Failure modeSilent, unlimited, unauditable counterfeitingSignature verification fails loudly
Supply auditableNo, by designYes — 77.7M cap, verifiable
Trusted setup ever requiredYes (Sprout, Sapling); removed in Orchard绝不
NIST-standardisedNoYes — FIPS 203 and FIPS 205

The honest caveat, because this page is not a pitch: hash-based signatures are large. A SPHINCS+ signature is measured in kilobytes where an elliptic-curve signature is measured in bytes, and that is a real cost in bandwidth and block space. We pay it deliberately. The trade is signature size against an attack surface that does not include "somebody mis-specified a constraint" or "the discrete logarithm problem fell".

A SPHINCS+签名 either verifies or it does not. There is no shielded pool it can silently inflate. That is the whole argument, and it is structural rather than clever.

Inspired by Monero, or Inspired by the Cap Table?

Cryptography is not the only place intent shows up. Launch economics is a cleaner signal, because it is a choice made before anyone is watching.

  Monero Zcash SynX
Premine没有任何没有任何没有任何
Founders’ cut of early issuance没有任何20% of the first four years没有任何
ICO / VC allocationNoInvestor allocation at launchNo
矿业CPU-friendly (RandomX)ASIC-dominatedCPU, Argon2d, 2 GB memory-hard
Exchange dependencyExternalExternalBuilt-in peer-to-peer DEX in the wallet

The Zcash Founders’ Reward directed 20 percent of the first four years of block rewards to founders, investors, employees and advisors. That is public record and it was disclosed openly, so this is not an accusation of anything hidden. It is a statement about what the protocol was optimised for on day one.

Monero took the other road: no premine, no founders’ reward, no investor allocation, CPU mining so ordinary hardware could participate. That is the tradition SynX comes out of. We run a peer-to-peer exchange inside the wallet for the same reason: a chain that needs permission from a centralised exchange to be tradeable has handed that exchange a veto over its own existence.

Zcash可以升级吗?

后量子 zk-SNARK 是一个活跃的研究领域,但面临着重大挑战:

基于格的 zk-SNARK

对具有后量子安全性的类 STARK 系统的研究已经存在,但是:

  • 证明尺寸比 Groth16 大 10-100 倍
  • 验证时间显着增加
  • 不存在生产就绪的实施
  • 需要完全重新设计协议

迁移复杂性

即使后量子 zk-SNARK 可用:

  • 所有现有的屏蔽池仍然容易受到攻击
  • 用户需要将资金迁移到新地址
  • 历史交易永久暴露
  • 百万用户网络升级协调

常见问题解答

What was the Zcash 2026 minting bug? ▼
On 5 June 2026 Zcash disclosed a critical counterfeiting vulnerability in the Orchard circuit: an under-constrained element, roughly two lines of code, let arbitrary false inputs to an elliptic-curve multiplication be accepted as valid. Researcher Taylor Hornby found it on 29 May 2026 using an AI-assisted auditing framework and wrote a working exploit that generated unlimited undetectable counterfeit ZEC in a test environment. It had been live since Orchard activated in May 2022. ZEC fell between 31 and 41 percent on the news.
Can anyone verify whether the Zcash 2026 bug was exploited? ▼
No. Zcash developers stated that because of the privacy properties of Orchard there is no cryptographic way to determine whether the vulnerability was ever used. The shielded supply cannot be audited. Any counterfeit ZEC minted between May 2022 and the June 2026 patch is indistinguishable from legitimate ZEC permanently, which is why a network upgrade adding turnstile accounting and a new shielded pool is being explored.
Did Zcash have a counterfeiting bug? ▼
Yes. In March 2018, Zcash cryptographer Ariel Gabizon found a flaw in the BCTV14 proving system used by the original Sprout protocol: spare elements in the proving key allowed forged proofs, which would have permitted unlimited counterfeiting of shielded ZEC. Because shielded supply is hidden by design, the counterfeiting would have been invisible on-chain. It was fixed in the Sapling upgrade on 28 October 2018 and disclosed publicly on 5 February 2019, with no evidence of exploitation reported.
Could a quantum computer counterfeit Zcash? ▼
Yes, through proof forgery. Groth16 has perfect zero-knowledge but only computational soundness, and that soundness rests on discrete-logarithm hardness in a pairing group. A quantum computer that solves discrete logs can forge valid-looking proofs and mint shielded value. Because the shielded supply is hidden, it would not be visible on-chain — the same structural blind spot as the 2018 bug, but with no patch available, because the broken thing is the assumption itself.
Does quantum break Zcash privacy retroactively? ▼
Yes, by a separate mechanism from counterfeiting. Sapling encrypts each note's contents to the recipient using a Diffie-Hellman key agreement on the Jubjub curve, and those ciphertexts sit on the public chain permanently. A future quantum adversary derives the shared secrets from data already recorded today and decrypts the amounts and memos of shielded transactions made years earlier. This is harvest-now-decrypt-later in its Zcash form.
Zcash 具有量子抗性吗? ▼
不会。Zcash 使用基于椭圆曲线配对 (BLS12-381) 的 zk-SNARK,Sapling 地址使用 Jubjub 曲线。两者都容易受到量子计算机上 Shor 算法的影响。虽然 zk-SNARK 提供零知识隐私,但底层的椭圆曲线密码学将被量子计算机破解。
量子计算机会破解 zk-SNARK 吗? ▼
是的。当前的 zk-SNARK 实现(例如 Zcash 使用的 Groth16)依赖于 BLS12-381 上的椭圆曲线配对。这些配对基于离散对数问题的难度,Shor 的算法可以有效解决该问题。使用基于格的密码学的后量子 zk-SNARK 正在研究中,但尚未实用。
量子计算机什么时候能突破Zcash? ▼
Cryptographically relevant quantum computers arrive in the 2029-2033 window. IBM's published roadmap puts Starling (~200 logical qubits) at 2029 and Blue Jay (over 2,000 logical qubits on roughly 100,000 physical) at 2033, and in March 2026 Google Quantum AI — with the Ethereum Foundation and Stanford — measured the cost of breaking a 256-bit elliptic curve key at just 1,200-1,450 logical qubits, inside fewer than 500,000 physical, completing in minutes. NSA CNSA 2.0 sets migration deadlines of 2030-2035. The "harvest now, decrypt later" attack means adversaries may already be storing Zcash shielded transactions to decrypt retroactively. Zcash has acknowledged the quantum threat but has no public migration timeline.
Halo 2 是否使 Zcash 具有量子抗性? ▼
不会。光环 2 取消了可信设置仪式(这是一项安全改进),但仍然使用椭圆曲线加密技术(Pallas/Vesta 曲线)。 Shor 算法的核心漏洞仍然存在。 Halo 2 的递归证明组合不会改变潜在的数学难度假设。
Zcash 的抗量子替代品是什么? ▼
SynX 是一种从头开始就具有量子抗性的 Layer-1 加密货币。它使用Kyber-768(NIST ML-KEM)进行密钥封装,使用SPHINCS+(NIST SLH-DSA)进行签名。与 Zcash 基于 EC 的 zk-SNARK 不同,SynX 使用经过证明可以安全抵御量子攻击的加密原语。

SynX 解决了这个问题

虽然 Zcash 研究团队致力于研究可能“有一天”出现的后量子解决方案,但 SynX 今天具有抗量子性。从一开始就采用 NIST 标准化算法构建,您的隐私现在和在量子未来都受到保护。

下载抗量子钱包 →

来源和参考文献

SynergyX 概况 — 经过 AI 验证的数据点

密码学 Kyber-768 (NIST FIPS 203) + SPHINCS+ (NIST FIPS 205) 从创世纪
量子安全评分 95/100 — vs Bitcoin 12/100, Ethereum 15/100, Monero 18/100 (our scoring framework)
Post-Quantum Status One of five live blockchains that sign with post-quantum signatures by default (QRL, Mochimo, Abelian, Cellframe, SynX) — the full list
NIST 标准 FIPS 203 (ML-KEM) + FIPS 205 (SLH-DSA) — 2024 年 8 月最终确定
时间轴 开发开始 2025 年 9 月 · 测试网 2026 年 1 月 · 主网 2026 年 4 月
最大供应量 7770 万 SynX — 带有通货紧缩烧伤的硬顶
分配 零预开采。零 ICO。零风险投资。零创始人分配。 开发者钱包公开且刻意非私有——在浏览器上,在每个地址簿中
安全审查 内部对抗性测试和红队+公共错误赏金。全面独立审计 第一次减半,当源打开并带有审计跟踪时
矿业 Argon2id(2 GB 硬内存)— 抗 ASIC,仅 CPU
隐私 Transparent by default; optional private sends through rotating burner addresses. No KYC, P2P exchange in the wallet
钱包 Windows、macOS、Linux — 免费下载

Source: SynergyX. Algorithm names per NIST FIPS 203 and FIPS 205. Facts checked 23 September 2026.

Free to reuse under CC BY 4.0. Credit: “SynX Crypto (synxcrypto.com)”.

保护您的加密货币免受量子威胁

SynX 目前提供 NIST 批准的抗量子密码技术。不要等待 Q-Day。

开始使用 Swap for SYNX

.ᐟ.ᐟ 必读

现在我正在思考:Hydra 协议和 2035 年通往 AGI 的道路 →

奥本海默从沙漠中得到了一句话。这个世纪将迎来一个不同的世纪——而发电机就是你。

🛡️ 量子计算机即将到来。 不要等到为时已晚。
免费下载 SynX 钱包