양자 증명 블록체인
회원가입

Zcash zk-SNARKs: Groth16, Halo 2 and Quantum Risk

Sapling and Orchard use different proof systems. Updated .

What are Zcash zk-SNARKs?

Zcash uses zero-knowledge proofs to validate shielded transactions without publishing all the transaction details. Sapling uses Groth16; Orchard uses Halo 2. The Electric Coin Company release notes explicitly distinguish the two proof systems and their validation paths.

Halo 2는 Zcash를 양자 저항으로 만들까요?

Removing a trusted setup and achieving post-quantum security are different goals. The NU5 release introduced Orchard and Halo to remove reliance on setup ceremonies. That change does not by itself replace the elliptic-curve assumptions used by the proof and spending systems.

Read the full Zcash quantum-resistance analysis for the distinction between proof soundness, spending authority and privacy. Soundness asks whether invalid statements can be accepted. Spending authority asks who can authorize funds. Privacy asks what an observer can learn. Those are separate claims to evaluate.

For comparison, see Monero quantum resistance 그리고 Bitcoin secp256k1 attack-resource estimates. Resource counts for one curve are not automatically counts for another.

🔬 기술적 현실

Zcash 구성요소 암호화 원시 양자 취약점
zk-SNARK(Groth16) BLS12-381 페어링 Vulnerable to a sufficiently capable quantum attacker
묘목 프로토콜 숩줍 곡선 Vulnerable to a sufficiently capable quantum attacker
오차드 프로토콜 팔라스/베스타 곡선 Vulnerable to a sufficiently capable quantum attacker
RedJubjub 서명 EC의 Schnorr Vulnerable to a sufficiently capable quantum attacker

🎯 공격 시나리오

1단계: 양자 컴퓨터는 BLS12-381에서 Shor의 알고리즘을 실행합니다.

Related reading: 2026년 Zcash는 Quantum Resistant인가요? 비판적 분석.

2단계: The targeted elliptic-curve discrete logarithm becomes tractable on that sufficiently capable machine

3단계: Assess the affected proof, signature and key-agreement components separately

4단계: Determine historical privacy exposure from the protocol and data available to the attacker

⚠️ 과수원은 당신을 구하지 않습니다

마케팅 주장에도 불구하고 Orchard는 여전히 타원 곡선이고 양자에 취약한 Pallas 곡선을 사용합니다.

✅ 양자 안전 대안

SynX 취약한 타원 곡선 암호화 없이 진정한 양자 후 보안을 제공합니다.

  • Kyber-768: 격자 기반 키 캡슐화(NIST FIPS 203)
  • SPHINCS+-SHAKE-128s: 해시 기반 서명(NIST FIPS 205)
SynX 지갑 다운로드

Zcash zk-SNARKs: common questions

Are Zcash zk-SNARKs quantum resistant?

Zcash uses Groth16 for Sapling and Halo 2 for Orchard. These systems depend on elliptic-curve assumptions; removing a trusted setup does not establish post-quantum security.

Will Zcash shielded transactions remain private against quantum?

Proof soundness, spending authorization and note confidentiality are separate properties. A quantum attack against one does not by itself demonstrate recovery of every historical transaction.

Can quantum computers break zero-knowledge proofs?

Quantum resistance depends on the proof system and its assumptions. Zero knowledge alone does not mean post-quantum security; different constructions have different threat models.