Zcash Weekly — May 10, 2026
Your weekly digest of Zcash ecosystem news, protocol updates, and privacy insights. Edition #8//Top Stories
Quantum-Recoverable Wallets Arriving Within WeeksJosh Swihart (ZODL) spoke at Consensus Miami's Privacy track and announced that Zcash will ship quantum-recoverable wallets within approximately 30 days, with full post-quantum cryptography targeted within 12–18 months. Swihart also stated that Zcash is targeting Mastercard/Visa-level throughput. The timeline was validated days later by zkDragon, who confirmed that the quantum recoverability security proofs were agreed upon at the Rome Dev Summit and the PRs are now live in the codebase. Decrypt covered the announcement. Decrypt · Forum
Zcash Foundation Assumes Stewardship of Core Community AssetsThe Zcash Foundation officially took control of three foundational community assets: the zcash GitHub organization (librustzcash, zips, lightwalletd, zcashd), the z.cash website and domain, and the @Zcash handle on X. ZecHub received a multi-year grant to manage z.cash and @Zcash day-to-day, with z.cash now forwarding to zechub.wiki. ZODL, Shielded Labs, and independent contributors continue their existing work — all repositories remain open source with existing licenses. Forum
Three Critical Security Releases in Seven DaysIn the most intense security sprint the network has seen, three critical releases landed in rapid succession:
- Zebra v4.4.1 (May 4): Fixed a consensus-critical bug where V5 transactions signed with
SIGHASH_SINGLEwithout a matching output were accepted by Zebra but rejected by zcashd — a chain split vector. All node operators who upgraded to v4.4.0 needed to upgrade again. - zcashd v6.12.2 (May 6): Patched several vulnerabilities that could have caused consensus divergence with Zebra, including a Sapling deserializer flaw.
- zcashd v6.12.3 (May 8): Emergency fix for CVE-2024-52911 — a use-after-free in
ConnectBlock()that allows any peer to crash a node by sending a crafted invalid block. Network-wide outage possible via amplification.
//Ecosystem
Blockspäti Berlin — June 17–19. WebZero announced that Zcash will take over the legendary Berlin club for three days during Berlin Blockchain Week. Over 12 side events, open daily from 11am to 4am. Privacy workshops, co-learning sessions, and DJ lineups planned. This is the largest European Zcash community event of the year. Announcement Zcash Dev Summit + ZK Week in Rome (May 7–14). zkSummit, ZKProof, Eurocrypt, and the Zcash Dev Summit all ran concurrently in Rome. Project Tachyon presented on recursive proving and oblivious synchronization at zkSummit. The quantum recoverability security proofs were agreed upon during the summit. An unprecedented concentration of ZK talent in one city. ZF Welcomes New Global Events Manager. The Zcash Foundation hired Valerie Leisten as Global Events and Operations Manager — a signal that ZF is scaling its community presence. Forum CipherPay WooCommerce Plugin on WordPress.org. CipherPay for WooCommerce is now available directly from the WordPress Plugin Directory. One-click install, shielded Zcash payments in minutes. Non-custodial, open source. WordPress powers 43% of all websites. WordPress $3B in Shielded Self-Custody. Swihart confirmed that over $3 billion in zcash:native is currently stored in shielded self-custody — a milestone figure that frames Zcash's real-world usage beyond speculation.//Governance & Grants
Grant Status (verified via GitHub API, May 10):
Under Review (👀 Ready For ZCG Review):| # | Grant | Applicant |
|---|---|---|
| 293 | WalletConnect v2 Integration + BazaarSwap | flynnthemaestro |
| 292 | Rore — High-Performance Rust UI Engine | umidjon |
| 291 | Cypherpunk Policy Dinner ("CPD") Sponsorship | paulbrigner |
| 290 | Pesa ya Siri Tanzania 2026 | — |
| 289 | Zcash Arabia (May–September 2026) | ZArabia |
| 288 | Quantir Privacy-Safe Risk Intelligence | Quantir |
| 287 | Zcash in Internet Freedom Crowdfunding | Tor Project |
| 286 | KBCC 2026 Sponsorship & Adoption | — |
| 284 | Zcash University Outreach — Mexico 2026 | — |
- #283 — Grassroots Marketing at DWeb Camp: Approved ✅, startup payment completed, marked as complete.
//Protocol & Development
ZF Engineering Update (Apr 20 – May 3): Zebra v4.4.1 shipped with a batch of fixes: memory allocation bugs in block deserializers (coinbase data, Equihash solution, Sapling spend vectors), a stale sighash bug in the script validator, RPC security fixes, and the 160-header-message protocol cap. Also: new Criterion benchmark suite covering Sprout/Sapling/Orchard proof verification, and Sentry observability alignment. Forum FROST v3.0.0 Released. The Zcash Foundation shipped FROST v3.0.0 — the stable release of threshold signatures for Zcash. This is foundational infrastructure for multi-party custody solutions. zcash_client_sqlite Rapid Patching. Two patch releases in 48 hours (0.20.0 → 0.20.1 → 0.20.2) indicate active bug fixing. Wallet developers should review changelogs before upgrading. ZSAs Pulled from NU7. Zcash Shielded Assets (tokenization on Zcash) have been removed from the NU7 network upgrade scope. Swihart indicated that new community polling will determine what remains in NU7. The 25-second block time proposal from Evan Forbes and ValarDragon remains under active discussion. ZecHub explainer Project Tachyon Security Framework. Tachyon disclosed their security approach for the next shielded pool: formal verification, extensive fuzzing, detailed documentation, and continuous AI-assisted auditing, crediting zkSecurity. Sean Bowe noted that "the turnaround time for shipping complex novel cryptography continues to shorten."//Tweets of the Week
"Over $3B in zcash:native is currently stored in shielded self-custody."
"Zcash Quantum Recoverability security proofs got agreed upon Wednesday, and now the PR's are in. Whose going to be first to test out quantum recoverability on mainnet 👀"
"We're using every tool at our disposal to ensure that Zcash's next shielded pool meets the high security expectations of our users. This includes formal verification, extensive fuzzing, detailed documentation, and continuous AI-assisted auditing."
//Forum Highlights
- "Nothing More American" (#55642): @genzcash ZEC video reposted on the forum, framing financial privacy as an American value. Light but culturally resonant thread.
- Rore UI Engine (#55634): Active technical discussion. hanh provided architectural critique. pitmutt noted Zenith doesn't use Electron. Community interested but evaluating whether WGPU is the right abstraction for wallet UIs.
- Hito Hardware Wallet (#55539): Mikhail responded to community questions. 27 likes, 256 views — strong engagement for a hardware wallet grant.
- Cypherpunk Policy Dinner (#55592): 17 posts, 48 likes, 234 views. Active debate on ZCG sponsoring a DC policy dinner. Community divided on whether ZCG funds should go to advocacy events.
- Zebra v4.4.1 Thread (#55588): New activity from fivelittleducks (May 10) — security fix discussion continuing.
//Privacy Corner: Why Amount Privacy Matters
When you send a transparent Bitcoin transaction, the world sees the exact amount: 0.1337 BTC. Chain analysis firms build profiles from these amounts. Repeated payments of the same value link transactions together. Unusual amounts stand out. Round numbers suggest purchases.
Zcash's shielded transactions encrypt the amount. An observer sees that a transaction occurred, but not how much moved. This is critical for both individuals and merchants:
- For individuals: No one can tally your balance by watching your activity.
- For merchants: Competitors can't see your revenue. Customers can't see each other's purchases.
//Network Snapshot
| Metric | Value | 7d Change |
|---|---|---|
| ZEC Price | $590.08 | -1.5% (24h) |
| Market Cap | $9.85B | — |
| 24h Volume | $708.3M | — |
| Block Height | 3,337,830 | +8,001 |
| Network Upgrade | NU6.1 (Zebra 4.4.1) | — |
| Chain Size | 255.75 GB | +1.2 GB |
//Zcash Privacy Index
Powered by CipherScan — live data from the Zcash blockchain. Privacy Metrics (Week-over-Week)| Metric | This Week | Last Week | Change |
|---|---|---|---|
| Privacy Score | 31 | 31 | — |
| Shielded Pool | 5,152,249 ZEC | 5,152,566 ZEC | -317 ZEC |
| Shielded % of Supply | 30.8% | 30.8% | ~flat |
| Orchard % of Shielded | 87.9% | 87.8% | +0.1% |
| Avg Shielded TX/Day | 1,750 | 1,499 | +16.7% |
| Metric | Value |
|---|---|
| Total Volume | $3.83M |
| Total Swaps | 512 |
| Top Inflow | Ethereum ($1.15M) |
| Top Outflow | Ethereum ($1.05M) |
| All-Time Swaps | 120,547 |
| All-Time Volume | $1.49B |
| Metric | Value |
|---|---|
| Active Nodes | 270 |
| Countries | 36 |
| Tor Nodes | 13 |
| 7d Node Change | +0.7% |
| Avg Block Time | 76s |
| 24h Transactions | 6,559 |
→ Live data at cipherscan.app/privacy-stats
//Tool Updates
CipherScan: The CipherScan API is now fully public — no authentication, no sign-up required. Block data, privacy stats, transaction lookups, cross-chain swap tracking, and Zcash Names resolution are all available at open endpoints. If you're building on Zcash, this is free infrastructure. — cipherscan.app CipherPay: CipherPay for WooCommerce is now available on the WordPress Plugin Directory. Install directly from your WordPress dashboard — accept shielded Zcash payments in minutes. Non-custodial, private by default, open source. — cipherpay.app//What's Ahead
| Date | Event |
|---|---|
| May 14 | Q2 Retroactive Grants — review period begins |
| May 14 | Zcash Dev Summit Rome wraps up |
| ~Mid-May | Ledger Orchard full signing targeted |
| ~June | Quantum-recoverable wallets expected (per jswihart) |
| June 17–19 | Blockspäti Berlin — Zcash community takeover |
| TBD | NU7 community re-polling on scope |