耐量子ブロックチェーン
登録

Zcash zk-SNARKs: Groth16, Halo 2 and Quantum Risk

Sapling and Orchard use different proof systems. Updated .

What are Zcash zk-SNARKs?

Zcash uses zero-knowledge proofs to validate shielded transactions without publishing all the transaction details. Sapling uses Groth16; Orchard uses Halo 2. The Electric Coin Company release notes explicitly distinguish the two proof systems and their validation paths.

Halo 2 は Zcash を量子耐性にしますか?

Removing a trusted setup and achieving post-quantum security are different goals. The NU5 release introduced Orchard and Halo to remove reliance on setup ceremonies. That change does not by itself replace the elliptic-curve assumptions used by the proof and spending systems.

Read the full Zcash quantum-resistance analysis for the distinction between proof soundness, spending authority and privacy. Soundness asks whether invalid statements can be accepted. Spending authority asks who can authorize funds. Privacy asks what an observer can learn. Those are separate claims to evaluate.

For comparison, see Monero quantum resistance そして Bitcoin secp256k1 attack-resource estimates. Resource counts for one curve are not automatically counts for another.

🔬 技術的な現実

Zcashコンポーネント 暗号プリミティブ 量子の脆弱性
zk-SNARKs (Groth16) BLS12-381 ペアリング Vulnerable to a sufficiently capable quantum attacker
苗木プロトコル ジャブジャブカーブ Vulnerable to a sufficiently capable quantum attacker
オーチャードプロトコル パラス/ベスタ カーブ Vulnerable to a sufficiently capable quantum attacker
レッドジャブジャブの署名 EC のシュノア Vulnerable to a sufficiently capable quantum attacker

🎯 攻撃シナリオ

ステップ 1: 量子コンピューターはBLS12-381でShorのアルゴリズムを実行します

Related reading: Zcash は 2026 年に量子耐性を備えていますか?批判的分析.

ステップ 2: The targeted elliptic-curve discrete logarithm becomes tractable on that sufficiently capable machine

ステップ 3: Assess the affected proof, signature and key-agreement components separately

ステップ 4: Determine historical privacy exposure from the protocol and data available to the attacker

⚠️ オーチャードはあなたを救わない

マーケティング上の主張にもかかわらず、オーチャードはパラス曲線を使用していますが、依然として楕円曲線であり、依然として量子的に脆弱です。

✅ 量子安全な代替手段

SynX 脆弱な楕円曲線暗号を使用せずに真のポスト量子セキュリティを提供します。

  • Kyber-768: ラティスベースのキーのカプセル化 (NIST FIPS 203)
  • SPHINCS+-SHAKE-128s: ハッシュベースの署名 (NIST FIPS 205)
SynXウォレットをダウンロード

Zcash zk-SNARKs: common questions

Are Zcash zk-SNARKs quantum resistant?

Zcash uses Groth16 for Sapling and Halo 2 for Orchard. These systems depend on elliptic-curve assumptions; removing a trusted setup does not establish post-quantum security.

Will Zcash shielded transactions remain private against quantum?

Proof soundness, spending authorization and note confidentiality are separate properties. A quantum attack against one does not by itself demonstrate recovery of every historical transaction.

Can quantum computers break zero-knowledge proofs?

Quantum resistance depends on the proof system and its assumptions. Zero knowledge alone does not mean post-quantum security; different constructions have different threat models.