Epoch: Future-Proof Cryptography for Zcash

Shielded Labs is excited to announce Epoch, a new research and engineering project to future-proof Zcash against emerging threats from quantum computing, increasingly capable AI, sophisticated hackers, and adversarial governments.

Cryptocurrency and blockchain technology have entered an uncertain era. Attackers are gaining powerful new capabilities, while state actors around the world are applying growing pressure. Together, these forces are creating new challenges for the cryptographic foundations that cryptocurrency depends on. The promise of private, permissionless money is on shaky ground if the underlying technology cannot withstand the threats of the modern age.

We’re launching Epoch to protect Zcash users and the monetary base, and to bring greater certainty to Zcash’s long-term security. Our goal is to ensure that the financial sovereignty Zcash provides can survive and flourish in this new era, and for generations to come.

What Is Epoch?

Our goal with Epoch is to develop production-ready, high-assurance post-quantum cryptography designed to future-proof Zcash and keep it safe and secure for the long term. To lead the effort, we have assembled a three-person cryptography team: Ulrich Haböck as Chief Cryptographer, and Luke Edwards and Suyash Bagad as Cryptography Engineers.

The cryptography we develop through Epoch will be designed to remain secure even as the capabilities of attackers change dramatically, from cryptographically relevant quantum computers to AI-assisted attacks and powerful state-level adversaries. Just as importantly, formal verification will provide assurance that the implementation matches the underlying cryptographic design. We think of this as “post-everything” cryptography: security built for the threats we face today, and for whatever comes next.

Why This Matters Now

Nobody knows if or when a cryptographically relevant quantum computer will arrive. Our goal is to make that uncertainty irrelevant to Zcash. Rather than asking users to bet on how quickly quantum computing will advance, we want to upgrade Zcash so that their funds and privacy remain protected even if it does. That removes a major long-term risk and gives users confidence that Zcash will protect them well into the future.

An important interim step is already in place: since NU6.3, Ironwood notes have been designed to be quantum-recoverable, allowing funds to be recovered through a future recovery protocol if today’s elliptic-curve-based protocol ever has to be disabled. This does not make Zcash post-quantum today, but it creates a bridge to that future transition.

The same principle applies beyond quantum computing. AI is making it easier to find weaknesses in complex software and cryptographic systems, and those capabilities are available to attackers as well as the defenders working to secure the protocol. Hackers and adversarial governments will continue to gain new tools. Zcash needs cryptography that is designed with those threats in mind.

The threat is not only from new technologies. Some of the most serious cryptographic failures come from mistakes in design or implementation rather than weaknesses in the underlying mathematics. Zcash has experienced this firsthand with the Sprout vulnerability discovered in 2018 and the Orchard vulnerability discovered in 2026. Audits are essential, but they cannot catch everything. Formal verification can provide a much higher level of assurance by mathematically verifying that critical parts of the Zcash protocol behave as intended.

Phase 1: Research and Design

Epoch will focus on developing future-proof cryptography that could eventually replace the quantum-vulnerable components Zcash depends on. It will also bring formal verification to critical cryptographic parts of the protocol. This work will complement Project Tachyon and the other post-quantum efforts currently underway across Zcash. We will work closely with Daira-Emma Hopwood and Dev Ojha, as well as Sean Bowe, Tal Derei, and the rest of the Project Tachyon team, to keep the efforts aligned.

The first phase will survey existing research and evaluate which candidate constructions can meet Zcash’s security and performance requirements. Our first goal is to develop a concrete proposal for Zcash’s post-quantum design in coordination with those efforts.

From there, we are targeting a production-ready cryptographic implementation by the end of 2027 that could serve as the basis for a future Zcash upgrade. Depending on what we learn, the first implementation may be narrower in scope than Tachyon. It should provide at least 128 bits of security for confidentiality and soundness, rely on minimal and well-understood security assumptions, and be formally verified. It also needs to be practical for Zcash as it exists today. In parallel, we’ll explore what would be required for the same cryptography to meet Tachyon’s performance requirements. If we can go further, it could support greater programmability, scalability, shielded CSV, proof-carrying data, and capabilities that have not yet been conceived.

Some of these are still open research questions. We’re building on existing work across the Zcash ecosystem, but we do not yet know which approach will ultimately work best. We will share the findings from our research and benchmarks as the work progresses.

Team

All three members of the Epoch team come from organizations that have built and deployed production zero-knowledge systems. They bring deep experience both in cryptographic research and in turning that research into production software.

Ulrich Haböck, Chief Cryptographer. Ulrich is a leading expert at the forefront of current research in zero-knowledge proofs and post-quantum cryptography. He joins from StarkWare, where he worked as a cryptographer, following earlier work as an applied cryptographer at Polygon Labs (Polygon Zero). He is the author of logUp, the logarithmic-derivative lookup argument now used widely across the STARK ecosystem, and a co-author of the Circle STARKs paper with StarkWare’s Shahar Papini and David Levit, which introduced an efficient approach to STARKs over the Mersenne-31 field. His work on FRI, Brakedown, and zero-knowledge techniques for STARKs is also widely referenced by practitioners. Before moving into applied cryptography, Ulrich worked in academia and teaching. He studied at the University of Vienna and is currently based in Europe.

Luke Edwards, Cryptography Engineer. Luke joins from Aztec, where he worked on the cryptography engineering team beginning in 2022 and most recently served as its technical lead. At Aztec, he worked on the cryptographic systems underlying the protocol and on bringing advanced zero-knowledge techniques into production. He holds a PhD in Applied Mathematics from the University of Arizona and a BS in Mathematics from Penn State. Earlier in his career, he worked as a systems engineer at Raytheon and as a graduate researcher at Los Alamos National Laboratory. He is based in the United States.

Suyash Bagad, Cryptography Engineer. Suyash also joins from Aztec, where he worked on the barretenberg cryptography library and the PLONK family of proof systems, including performance improvements for various cryptographic primitives in ZK circuits. He holds both a B.Tech and M.Tech from IIT Bombay, where his graduate research focused on privacy-preserving proofs of reserves for Monero and MimbleWimble. He is based in Europe.

Staying Unstoppable

Shielded Labs’ mission is to build unstoppable private money to help ensure Zcash remains secure and sustainable for the long term. Money isn’t truly unstoppable if a quantum computer, AI, or another emerging technology can break the cryptography it depends on. Epoch is our effort to make sure that doesn’t happen, so that Zcash users can have confidence their funds and privacy will remain protected for the long term.

There’s a lot of work ahead. We’ll share what we learn as Epoch develops, including findings from our research and benchmarking as well as updates on the project’s progress. We’re excited to get started. If Zcash is going to remain unstoppable for generations to come, work like Epoch is essential.

Please join us in welcoming Ulrich, Luke, and Suyash to Shielded Labs!


Thank you to @zooko, Ulrich Haböck, Luke Edwards, Suyash Bagad, @daira, @frankbraun, and @thedesertlynx for the feedback and review.

13 Likes

I always chuckle at “future-proof cryptography” when I remember that a deck of cards, via a game of deterministic Klondike with pile summation/reduction (mod) at every gn + c steps can theoretically provide 112.8 bits of quantum security entirely by hand-

Anyways, this is very cool!!!

Random note

(No, I was not referencing Bruce Schneier’s Solitaire, that is very hard to do, requires learning, and leaks information. Klondike, however, you can play on a board, with the board holding state instead of your brain, and you can probably find a gambler who can do it fast enough for military encryption in 1650)

Random note #2

Doing the math, at roughly 5-7 moves per 7 characters in a strong scheme (OTP-like, functional corresponding randomness) or 5-7 moves per message (weak scheme, 7-character Vigenere cipher, using the game as a keystream generator with n being nonce), yes, you could conceivably do it at scale. A cryptography team of gamblers, preferably ones who can do card counting, they simply have to sum piles and divide fast.

Overall, not very realistic for quantum security, but god they would be undefeated till like 1840 (eventually Charles Babbage’s Analytical Machine, and eventually, himself, will break it; but I doubt he could break the strong cipher which switched keys every len(key) letters.

Really glad to see this happening. Preparing Zcash for the quantum era while strengthening security through formal verification is a smart move. Excited to see how Epoch develops!

Although, just for the name, I would’ve gone with Zepoch :slight_smile: