Hardy Index Quantum readiness benchmark

What changed · What changed

Zcash's roadmap citations were repointed on 19 August, and the recovery path turned out to be live

A source that stopped being readable forced us back to the Zcash specifications, and the specifications said the profile was three weeks behind.

The short answer

On 19 August 2026 the Zcash profile was corrected. A news article carrying four load-bearing citations stopped being readable to automated checks, so the index repointed at the Zcash protocol specifications. Those show the quantum recovery path activated on mainnet in July rather than pending. No score changed. The recovery covers only funds moved into one pool.

What moved, and what forced it

Four citations on the Zcash profile pointed at a single news article from May 2026: the deployment and migration dimensions, plus two roadmap entries. On 18 August that URL began returning a rate-limit error to automated clients, which failed the source check on every build. An allowlist entry would have hidden the problem. The fix was the one our own source policy recommends: repoint at records a reader can open.

Going to the primaries corrected the record in a direction we did not expect. ZIP 2005, titled Ironwood Quantum Recoverability, is not a pending proposal. ZIP 258 specifies that it activates with the NU6.3 network upgrade at block 3,428,143, and the chain passed that block on 28 July 2026. The old deployment note said a ZIP "is deploying" a recovery path. The old verification note said the construction was "not yet deployed". Both were three weeks stale. We understated Zcash rather than overstating it, which is the rarer direction and no more acceptable.

Two claims are withdrawn rather than repointed. The profile previously said Zcash targeted quantum-recoverable wallets within a month and full post-quantum protection on a twelve to eighteen month horizon, and that a full protocol migration was set for 2027. Both came from a headline. Neither the ZIPs nor the Zcash Foundation's polling write-up states a date for the full migration, so the profile now says we could not confirm one.

The dated record behind the corrected roadmap.

  1. Zcash Foundation publishes NU7 polling results: quantum recoverability draws 90.5 per cent support among ZCAP participants and 94.6 per cent among coinholders. source
  2. The chain passes block 3,428,143, the activation height ZIP 258 specifies for NU6.3, which carries ZIP 2005 Ironwood quantum recoverability. source

TermsQuantum recoverability is not quantum resistance. It is a way to prove ownership of funds and recover them later, even if the signature scheme guarding them is broken. The signatures themselves are unchanged.

What the recovery path does not do

One substantive fact was missing from the profile altogether and has been added. The recovery path covers only funds that have been moved into the Ironwood pool. ZIP 2005 states that anything left in the Sprout, Sapling or Orchard pools would be inaccessible once those protocols were disabled. A holder reading the old profile would reasonably have taken the protection as automatic. It is not.

  • It is an opt-in migration of funds, not a network-wide default.
  • It does not replace RedDSA or RedPallas signatures, which are still elliptic-curve and still the thing a quantum computer would attack.
  • No post-quantum signature scheme has been selected. There is no NIST-standardised signature such as SLH-DSA in the protocol today.
  • It does not put a date on the full post-quantum migration. No primary source we can read carries one.

Why nothing moved on the score

Zcash keeps its current placement, with deployment, migration and verification unchanged. The reasons are worth stating rather than settling quietly, because they pull in opposite directions.

The tier is defined by a funded roadmap with public dates, and the only public date Zcash had has just been withdrawn as unverifiable. That points down. Against it, the chain has shipped a working mitigation on mainnet, which most of the tier has not. That points up. Our scoring spine measures dated promises and post-quantum signatures, and Zcash has now delivered something that is neither. The two effects cancel on the numbers, so the placement stands and deserves a re-read in both directions.

Where this stands today

  • Zcash 3 Committed Hardy 41.0 of 100

As rated by the Hardy Index, current as of 2 October 2026. Ratings change when the evidence does, and every change is recorded in the changelog.

If you hold ZEC

The practical change for you is the pool detail, not the score. If you assumed the July upgrade protected your balance wherever it sits, that assumption is wrong: the recovery path applies to funds in the Ironwood pool. Check which pool your wallet actually uses, and whether it supports Ironwood at all.

Beyond that, treat this as a chain with a real mitigation shipped and no confirmed date for the full migration. If you want the reasoning behind why shielded balances are exposed to capture today and decryption later, see harvest now, decrypt later. The correction itself is logged in the changelog.

Where to go next

Sources

Every dated event above carries its own primary source. These are those sources, each checked on the date shown.

  1. ZIP 258: Network Upgrade 6.3 Zcash Improvement Proposals · primary · checked 14 September 2026
  2. ZIP 2005: Ironwood Quantum Recoverability Zcash Improvement Proposals · primary · checked 14 September 2026
  3. NU7 Polling Results: What We Heard and Where We Go From Here Zcash Foundation · primary · checked 14 September 2026
  4. Zcash Protocol Specification Electric Coin Company · primary · checked 14 September 2026
  5. FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA) NIST · primary · checked 14 September 2026

This is a security-readiness assessment, not investment advice.