Privacy is not quantum safety: Zcash spends are authorised by elliptic-curve signatures, though ZIP 2005 adds a quantum recovery path for shielded notes ahead of a full transition.
Is Zcash quantum-safe?
No, and the distinction matters more here than almost anywhere else in this index. Zcash is a privacy chain, and privacy is routinely confused with quantum safety. They are different properties. Zcash spends are authorised by RedDSA and RedPallas signatures, which are elliptic-curve schemes, and the Halo 2 proof system they underpin rests on the same mathematics. A large fault-tolerant quantum computer running Shor's algorithm is expected to break them. What Zcash does have is an unusually thoughtful sequencing of the problem. ZIP 2005 introduces Orchard quantum recoverability, an emergency path that changes how recoverable Orchard notes are constructed so that if a quantum adversary forced the network to disable the vulnerable shielded protocols, holders could still recover funds into a future post-quantum protocol. Full post-quantum migration is targeted on a twelve to eighteen month horizon from mid-2026.
Where we are making a judgement call Zcash is the clearest case in the index of two different security properties being conflated. Zero-knowledge privacy hides who paid whom. Quantum safety concerns whether the signature authorising a payment can be forged. Zcash currently has the first and not the second, and a reader who takes shielded transactions as evidence of quantum resistance has drawn the wrong conclusion.
At a glance
On mainnet today
RedDSA and RedPallas elliptic-curve signatures, with Halo 2 proofs
Post-quantum scheme
Not yet selected. ZIP 2005 adds Orchard quantum recoverability ahead of a full transition.
NIST standard
None confirmed for the full migration at the time of writing
Readiness tier
Tier 3: Committed. A funded roadmap with public dates and active research exists, but no post-quantum signature is live on mainnet.
Score breakdown
Each dimension scored 0 to 10. The weight beside it is its share of the
total score.
Zcash spend authorisation uses RedDSA and RedPallas, both elliptic-curve signature schemes, and the Halo 2 proving system rests on the same curve mathematics. Nothing post-quantum authorises spends on mainnet today.
source
2 Deployment stage 5/10, weighted 25%
Tier 3: Committed. A named ZIP is deploying a quantum recovery path and a full post-quantum transition is on a published horizon, but no post-quantum signature authorises spends on mainnet.
source
3 NIST alignment 5/10, weighted 15%
Zcash has committed to a direction and to a recovery mechanism, but we could not confirm a specific NIST-standardised signature scheme selected for the full transition. The recoverability work in ZIP 2005 is a bespoke construction rather than an adoption of FIPS 204 or FIPS 205.
source
4 Migration path 8/10, weighted 15%
The strongest sequencing logic in the committed group. Rather than waiting for a full migration, Zcash is shipping a recovery path first, so that funds remain recoverable into a future post-quantum protocol even if the shielded protocols had to be disabled in an emergency. Solving the rescue case before the upgrade case is the right order.
source
5 Exposure 5/10, weighted 10%
Shielded Zcash is a genuine exception in this index. Funds held in shielded pools do not publish a spending public key on-chain in the way a transparent account does, which materially limits what an attacker can harvest today. Transparent addresses behave like Bitcoin's and are exposed on spend.
source
6 Verification 8/10, weighted 5%
Zcash's protocol is specified in a public document, changes go through numbered public ZIPs, the cryptography is peer-reviewed and the implementation is open source. The quantum recoverability work is identified by a specific ZIP number rather than described in a blog post.
source
The deployment dimension is not a separate judgement. It is Tier 3
expressed as a number. See the tier mapping.
How it compares
All 23 rated chains on the 0 to 100 scale.
Zcash is marked. Select any point to open that profile.
Zcash sets out a plan for quantum-recoverable wallets within a month and full post-quantum protection on a twelve to eighteen month horizon.
source
2026in-progress
ZIP 2005 deploys Orchard quantum recoverability, changing how recoverable notes are constructed so funds can later be moved into a post-quantum recovery protocol.
source
Exposure measures how much of the chain's value already sits behind a public key that an
attacker can record today and break later. This is the part of the threat that a future
upgrade cannot undo.
Zcash is the one chain in this index where the privacy design genuinely reduces quantum exposure, though not for the reason people usually assume. Funds held in shielded pools do not publish a spending public key on-chain the way a transparent account does, so there is materially less for an attacker to harvest today. That is a real advantage and it is why Zcash scores at the midpoint rather than near the bottom. It is not the same as quantum safety: the signatures authorising shielded spends are still elliptic-curve, so a quantum adversary that could break them could still forge spends. Transparent Zcash addresses behave like Bitcoin's and reveal their key on spend.
What this rating means for you
If you hold Zcash
Zcash has a funded roadmap but no post-quantum signature protecting funds on mainnet yet. Until it ships, your exposure is the ordinary one, and the steps that reduce it cost nothing.
Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it
is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating.
How we make money.
Questions
Is Zcash quantum-safe?
No. Zcash spends are authorised by RedDSA and RedPallas, elliptic-curve signature schemes that a sufficiently large quantum computer would break, and the Halo 2 proof system rests on the same mathematics. Zcash is shipping a quantum recovery path and targeting a full post-quantum migration, but neither is complete.
Does zero-knowledge privacy make Zcash quantum-resistant?
No, and this is the most common misunderstanding about Zcash. Privacy hides the parties and amounts in a transaction. Quantum safety is about whether the signature authorising that transaction can be forged by an attacker with a quantum computer. Zcash's shielded pools deliver the first property. They do not deliver the second.
What is ZIP 2005 and what does it actually protect?
ZIP 2005 introduces Orchard quantum recoverability. It changes how recoverable Orchard notes are constructed so that if a future quantum adversary forced the network to disable the vulnerable shielded protocols, holders could still recover their funds into a future post-quantum recovery protocol. It is an escape hatch, not a post-quantum signature scheme.
Why does Zcash score better than most chains on exposure?
Because shielded funds do not publish a spending public key on-chain in the way a transparent account does, so there is less material for an attacker to collect today against a future quantum computer. That is a genuine structural advantage of the shielded design, and it is separate from whether the underlying signatures are quantum-safe, which they are not.
This is a security-readiness assessment, not investment advice.
Cookies. We use Google Analytics to count how many people read a page. That is
the only thing this site measures: no advertising, no profiling, no third-party marketing tags.
Until you choose, nothing is stored on your device.
What we would set, in full.