Tech Developers of Zcash (ZEC), a privacy-centric cryptocurrency, are aiming to implement quantum-resistant payment features by January. This initiative follows recent concerns regarding vulnerabilities to AI-assisted attacks on cryptocurrency wallets.

The focus is on public payments, where approximately 70% of ZEC is held. A new wallet tool will also prevent balance checks from disclosing linked addresses.

Roman Akhtariev, in a post for Zakura, a software used for managing the Zcash network, stated, “Our team plans for post-quantum signature opcodes to land in Zcash in January.” These opcodes are designed to allow Zcash to utilize hash-based signatures, which are more resilient against potential quantum computer attacks. Although the January timeframe has been set as a target, a specific activation date has yet to be confirmed.

This upgrade is intended to thwart attackers from using existing public keys to retroactively gain unauthorized access to user funds. The new software will produce signatures that are verified through hashes, which act as unique identifiers derived from confidential data. By employing hash-based signatures, Zcash aims to create a more secure method for authorizing transactions.

Maintaining fresh addresses before transactions helps obscure keys until they are used, while the new signatures will secure payments during the approval process. Akhtariev's announcement coincides with warnings from Ethereum researcher Justin Drake, who recently advised cryptocurrency holders to prepare for a "bunker mode," indicating that AI could potentially exploit weaknesses in the cryptographic frameworks of Bitcoin and Ethereum within a matter of months.

While Ethereum is targeting a transition to quantum-resistant cryptography by December 2029, no practical threats to wallet keys have been demonstrated thus far. Following Drake's warning, ZEC experienced a decline of approximately 11%, trading around $1,185 on Thursday.

New Address Management and Balance Checks

Zcash supports two types of transactions: shielded payments, which keep sender and recipient information private, and transparent payments, which function similarly to Bitcoin, with visible addresses and amounts on the blockchain. As of Thursday, about 11.96 million of the 16.98 million ZEC in circulation were in the transparent category, indicating that the upcoming updates will primarily target this public aspect of the network.

In a standard Zcash transaction, a secret key is used for spending approval, paired with a public key that allows network verification. Theoretically, deriving the secret key from the public key requires significant computational effort. However, Drake's concerns suggest that advancements could make this process feasible.

Transparent addresses initially conceal the public key behind a hash, but revealing that key during a transaction exposes it. To maintain privacy, moving leftover funds to a new address, which is linked to a different, undisclosed key, is recommended.

However, checking balances across multiple addresses can inadvertently disclose information. For instance, if a user spreads funds across ten addresses, they still need to verify their balances. Typically, this involves requesting records from a server, which could link seemingly unrelated addresses.

Zakura's lookup tool employs private information retrieval technology, enabling users to check their balances without revealing which specific address they are inquiring about. This tool is currently available in an experimental format through the "Private queries" feature in the Vizor wallet.

On the shielded side of Zcash, additional work is necessary. The project's quantum recovery design highlights that if an attacker obtains a recipient's address, they could store encrypted payment data today and attempt to decrypt it following a future mathematical breakthrough.