The Zakura team, responsible for the Zcash client, plans to integrate post-quantum signature opcodes into the protocol in January 2027.
This initiative has been linked to the risks associated with transparent addresses, which contain a hash of the public key that becomes exposed when funds are spent. If it becomes possible to recover a private key from a public one, this vulnerability could affect already revealed addresses.
How transparent addresses operate. Source: Zakura blog.The updated software will generate a signature that the network verifies using hashes, employing a different method for confirming permission to spend funds.
Developers also suggested enhancing this approach by rotating addresses: after a transaction, the remaining balance would be sent to a new address. This reduces the risk of key exposure.
Another concern revolves around the privacy of queries to the infrastructure. If a wallet requests transaction history for multiple transparent addresses openly, the server could link them to a single user.
To address this, Zakura is working on Private Information Retrieval. This mechanism allows users to obtain necessary records without revealing which addresses the wallet is checking, while the transparent transactions themselves remain public. An experimental version of this feature is already available in the Vizor wallet.
According to CoinDesk, based on ZecStats data, 11.96 million out of 16.98 million ZEC tokens (approximately 70% of the circulating supply) are in the transparent pool. Therefore, the post-quantum strategy primarily addresses the public portion of the network. Separate protections will be needed for secure transactions against future threats.
The renewed discussion around hacking threats intensified following comments from Ethereum researcher Justin Drake, who emphasized the need for the industry to prepare for a "bunker mode." He believes that the ECDSA digital signature algorithm may become vulnerable even before sufficiently powerful quantum computers emerge.
It is worth noting that in March, the Ethereum Foundation presented a roadmap for safeguarding the network from quantum computers, aiming for completion by 2029.
In June, Nicolas Consigny, the lead of the Kohaku project at EF, proposed a post-quantum account protection scheme called SPHINCS- that does not require a hard fork.
Follow ForkLog on social media
Telegram (main channel) Facebook X