Hardy Index Quantum readiness benchmark

Chain profile

Zcash

ZEC Committed

Privacy is not quantum safety: Zcash spends are authorised by elliptic-curve signatures, though ZIP 2005 has added a quantum recovery path for notes in the new Ironwood pool ahead of a full transition.

Is Zcash quantum-safe?

No, and the distinction matters more here than almost anywhere else in this index. Zcash is a privacy chain, and privacy is routinely confused with quantum safety. They are different properties. Zcash spends are authorised by RedDSA and RedPallas signatures, which are elliptic-curve schemes, and the Halo 2 proof system they underpin rests on the same mathematics. A large fault-tolerant quantum computer running Shor's algorithm is expected to break them. What Zcash does have is an unusually thoughtful sequencing of the problem, and it is live rather than promised. ZIP 2005, Ironwood Quantum Recoverability, activated on mainnet with the NU6.3 network upgrade: it changes how notes in the new Ironwood pool are constructed, so that if a quantum adversary forced the network to disable the vulnerable shielded protocols, holders could still recover funds into a future post-quantum protocol. That cover is not automatic. Funds left in the Sprout, Sapling and Orchard pools are outside it, so it reaches only what holders move. We could not confirm a published date for the full post-quantum migration itself.

Where we are making a judgement call Zcash is the clearest case in the index of two different security properties being conflated. Zero-knowledge privacy hides who paid whom. Quantum safety concerns whether the signature authorising a payment can be forged. Zcash currently has the first and not the second, and a reader who takes shielded transactions as evidence of quantum resistance has drawn the wrong conclusion.

At a glance

On mainnet today

RedDSA and RedPallas elliptic-curve signatures, with Halo 2 proofs

Post-quantum scheme

Not yet selected. ZIP 2005 added Ironwood quantum recoverability at NU6.3, ahead of a full transition.

NIST standard

None confirmed for the full migration at the time of writing

Readiness tier

Tier 3: Committed. A funded roadmap with public dates and active research exists, but no post-quantum signature is live on mainnet.

Score breakdown

Each dimension scored 0 to 10. The weight beside it is its share of the total score.
Show the weighted arithmetic and the sourced note for each dimension
Zcash Hardy Score by dimension, with weights and weighted contributions
No. Dimension Score Weight Contribution
1 Signature scheme 0 30% 0.0
2 Deployment stage 5 25% 12.5
3 NIST alignment 5 15% 7.5
4 Migration path 8 15% 12.0
5 Exposure 5 10% 5.0
6 Verification 8 5% 4.0
Hardy Score 41.0

1 Signature scheme 0/10, weighted 30%

Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.

Zcash spend authorisation uses RedDSA and RedPallas, both elliptic-curve signature schemes, and the Halo 2 proving system rests on the same curve mathematics. Nothing post-quantum authorises spends on mainnet today. source

2 Deployment stage 5/10, weighted 25%

Band 5: Tier 3: Committed.

Tier 3: Committed. ZIP 2005 is live on mainnet rather than pending: it activated with the NU6.3 network upgrade at block 3,428,143, creating the Ironwood pool whose notes are built to stay recoverable through a later post-quantum transition. That is a recovery path and not a migration, and no post-quantum signature authorises spends on mainnet. source

3 NIST alignment 5/10, weighted 15%

Band 3 to 5: NIST schemes are referenced as candidates without a committed selection, or the work is bespoke research.

Zcash has committed to a direction and to a recovery mechanism, but we could not confirm a specific NIST-standardised signature scheme selected for the full transition. The recoverability work in ZIP 2005 is a bespoke construction rather than an adoption of FIPS 204 or FIPS 205. source

Placement in the band The top of the band rather than a 3 or a 4: Zcash has committed to a direction and to a specific recovery mechanism, which is more than referencing candidates. It cannot reach 6 because ZIP 2005 is a bespoke construction and no NIST-standardised signature scheme has been confirmed for the full transition.

4 Migration path 8/10, weighted 15%

Band 6 to 8: A credible published plan exists with a mechanism identified, but key parts are unbuilt or undated.

The strongest sequencing logic in the committed group. Rather than waiting for a full migration, Zcash shipped a recovery path first, so that funds held in the Ironwood pool remain recoverable into a future post-quantum protocol even if the shielded protocols had to be disabled in an emergency. Solving the rescue case before the upgrade case is the right order. The limit is that it covers only what is moved: ZIP 2005 states that funds still in the Sprout, Sapling or Orchard pools would be inaccessible once those protocols were disabled. source

Placement in the band The top of the band: shipping a recovery path before the migration itself solves the rescue case first, which is the right order. It is not a 9 because moving into Ironwood buys recoverability rather than post-quantum spend authorisation, which no holder can obtain today, and the full transition remains undesigned.

5 Exposure 5/10, weighted 10%

Band 3 to 5: Most active accounts have revealed a public key, or the chain has no live supply to assess.

Shielded Zcash is a genuine exception in this index. Funds held in shielded pools do not publish a spending public key on-chain in the way a transparent account does, which materially limits what an attacker can harvest today. Transparent addresses behave like Bitcoin's and are exposed on spend. source

Placement in the band The top of the band rather than a 3 or a 4: shielded funds genuinely do not publish a spending key on-chain, which no other chain in this index can say. It cannot reach 6 because transparent addresses behave like Bitcoin's and are exposed on spend.

6 Verification 8/10, weighted 5%

Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.

Zcash's protocol is specified in a public document, changes go through numbered public ZIPs, the cryptography is peer-reviewed and the implementation is open source. The quantum recoverability work is identified by a specific ZIP number rather than described in a blog post. source

Placement in the band The top of the band: a public specification, numbered ZIPs, peer-reviewed cryptography and open source, with the quantum work identified by ZIP number rather than described in a blog post. It stops short of 9 because the recoverability construction, now activated at NU6.3, carries no published independent audit.

The deployment dimension is not a separate judgement. It is Tier 3 expressed as a number. See the tier mapping.

How it compares

All 31 rated chains on the 0 to 100 scale. Zcash is marked. Select any point to open that profile.

Nearest chains in the ranking

The 9 chains Zcash sits among, out of 31 rated. The last column is the gap in Hardy points from Zcash.

Chains ranked immediately around Zcash, with tier, Hardy Score and the gap to Zcash
Rank Chain Tier Hardy vs ZEC
9 XRP Ledger 3: Committed 46.5 +5.5
10 Sui 3: Committed 45.5 +4.5
11 Hedera 3: Committed 42.0 +1.0
12 Stellar 3: Committed 41.0 level
13 Zcash this chain 3: Committed 41.0
14 Aptos 3: Committed 40.5 -0.5
15 Polkadot 3: Committed 40.5 -0.5
16 Ethereum 3: Committed 40.0 -1.0
17 Cardano 3: Committed 37.5 -3.5

Roadmap

  1. February 2026 shipped

    Quantum recoverability is polled ahead of NU7 and records strong support: 90.5 per cent among ZCAP participants and 94.6 per cent among coinholders. The Zcash Foundation records it as a proposal to prioritise. source

  2. July 2026 shipped

    ZIP 2005, Ironwood Quantum Recoverability, activates on mainnet with the NU6.3 network upgrade at block 3,428,143, creating the Ironwood pool. Notes in that pool are constructed so they can later be moved into a post-quantum recovery protocol. source

Exposure

Exposure measures how much of the chain's value already sits behind a public key that an attacker can record today and break later. This is the part of the threat that a future upgrade cannot undo.

Zcash is the one chain in this index where the privacy design genuinely reduces quantum exposure, though not for the reason people usually assume. Funds held in shielded pools do not publish a spending public key on-chain the way a transparent account does, so there is materially less for an attacker to harvest today. That is a real advantage and it is why Zcash scores at the midpoint rather than near the bottom. It is not the same as quantum safety: the signatures authorising shielded spends are still elliptic-curve, so a quantum adversary that could break them could still forge spends. Transparent Zcash addresses behave like Bitcoin's and reveal their key on spend.

What this rating means for you

If you hold Zcash

Zcash has a funded roadmap but no post-quantum signature protecting funds on mainnet yet. Until it ships, your exposure is the ordinary one, and the steps that reduce it cost nothing.

Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating. How we make money.

From the newsroom

What we have published about this chain

Embed this rating

Paste this anywhere to show Zcash's current rating. It renders live from the index, so it updates when the rating does, and the review date is written into the image. There is nothing to sign up for and nothing to pay.

<a href="https://hardyindex.com/chains/zcash"><img src="https://hardyindex.com/badge/zcash.svg" width="260" height="76" alt="Quantum readiness rated by the Hardy Index"></a>

The image is /badge/zcash.svg. It is a plain SVG with no script and no tracking, it sets no cookie, and it records nothing about whoever loads it.

Questions

Is Zcash quantum-safe?

No. Zcash spends are authorised by RedDSA and RedPallas, elliptic-curve signature schemes that a sufficiently large quantum computer would break, and the Halo 2 proof system rests on the same mathematics. Zcash has shipped a quantum recovery path for the Ironwood pool and intends a full post-quantum migration, but the migration is neither designed nor dated.

Does zero-knowledge privacy make Zcash quantum-resistant?

No, and this is the most common misunderstanding about Zcash. Privacy hides the parties and amounts in a transaction. Quantum safety is about whether the signature authorising that transaction can be forged by an attacker with a quantum computer. Zcash's shielded pools deliver the first property. They do not deliver the second.

What is ZIP 2005 and what does it actually protect?

ZIP 2005 is titled Ironwood Quantum Recoverability, and it activated on mainnet with the NU6.3 network upgrade. It changes how notes in the new Ironwood pool are constructed, so that if a future quantum adversary forced the network to disable the vulnerable shielded protocols, holders could still recover their funds into a future post-quantum recovery protocol. It is an escape hatch, not a post-quantum signature scheme, and it covers only funds moved into the Ironwood pool: ZIP 2005 states that anything left in the Sprout, Sapling or Orchard pools would be inaccessible once those protocols were disabled.

Why does Zcash score better than most chains on exposure?

Because shielded funds do not publish a spending public key on-chain in the way a transparent account does, so there is less material for an attacker to collect today against a future quantum computer. That is a genuine structural advantage of the shielded design, and it is separate from whether the underlying signatures are quantum-safe, which they are not.

Sources

  1. Zcash Protocol Specification Electric Coin Company / Zcash Foundation · primary · checked 12 August 2026
  2. ZIP 2005: Ironwood Quantum Recoverability Electric Coin Company / Zcash Foundation · primary · checked 19 August 2026
  3. ZIP 258: Deployment of the NU6.3 Network Upgrade Electric Coin Company / Zcash Foundation · primary · checked 19 August 2026
  4. NU7 Polling Results: What We Heard and Where We Go From Here Zcash Foundation · primary · checked 19 August 2026
  5. FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA) NIST · primary · checked 12 August 2026
Cite this rating

A rating is only true as of the day it was reviewed, so both forms below carry the review date and the methodology version. If you are quoting the score, quote those too.

Plain text

The Hardy Index (2026). Zcash: quantum readiness assessment. Hardy Score 41.0 of 100, Tier 3: Committed. Methodology v1.4. Reviewed 1 October 2026. https://hardyindex.com/chains/zcash

BibTeX
@misc{hardyindex_zcash_2026,
  author       = {{The Hardy Index}},
  title        = {Zcash: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/zcash}},
  note         = {Hardy Score 41.0 of 100, Tier 3: Committed. Methodology v1.4},
  urldate      = {2026-10-01}
}

The whole dataset is reusable under the terms on the about page. A machine-readable version of this page is at /chains/zcash.md.

This is a security-readiness assessment, not investment advice.