[Protocol Study Series] 12-session guided reading of the Zcash Protocol Specification, starting April 21

Hey folks! :waving_hand:

I’m launching a structured sub-series of Zcash Engineering Office Hours: a guided reading of the full Zcash Protocol Specification PDF.

The goal is for it to be a study group, not a lecture. Each session covers specific spec sections, with space to unpack the implications, dig into history, and take questions. Accessible enough for a motivated newcomer, but technical enough to be useful to people who are actually building.

Session 1: What Problem Does Zcash Actually Solve?
Tuesday, April 21 @ 11:00 AM EDT
Co-host: @shielded-nate (Nate Wilcox)
Spec: §1.1 Caution + §1.2 High-level Overview (p. 8–9)

The first 30 mins will be a guided read of the spec text: Notes, nullifiers, chain value pools, the traceability set argument.

The second 30 mins: open conversation with Nate on what these sections mean in practice, how the design decisions have held up across four protocol eras, and what questions are still worth asking.

Bring the PDF: https://zips.z.cash/protocol/protocol.pdf. We’re starting at page 8.


Tentative full 12-session arc (biweekly Tuesdays, subject to change as we go):

# Date Title Spec
1 Apr 21 What Problem Does Zcash Actually Solve? §1.1–1.2
2 May 12 Addresses, Keys, and the Privacy Onion §3.1
3 May 19 Notes, Commitments, and Nullifiers §3.2, 3.8, 3.9
4 Jun 2 Transactions Unpacked: JoinSplit to Actions §3.4–3.7
5 Jun 16 Merkle Trees and How the Chain Remembers §3.8, 4.9
6 Jun 30 Proving Without Revealing: zk-SNARKs in Zcash §4.1, 4.18
7 Jul 14 Sending, Receiving, and Scanning §4.7–4.8, 4.19–4.22
8 Jul 28 Signatures, Balance, and Binding §4.10, 4.13–4.15
9 Aug 11 Under the Hood: Hashes, Curves, and PRFs §5.4
10 Aug 25 Consensus: What Zcash Changed from Bitcoin §7
11 Sep 8 Network Upgrades: Sprout to NU6 §6
12 Sep 22 Circuit Deep Dive Appendix A
16 Likes

That’s cool! I can imagine these parts and PDFs beeing artefacts.

This is very cool @shieldedmark

Looking forward to every session

I’m working on something for developers too maybe you might be interested

You can give it a look

I love it. Collab somehow? DM me on X.

I’m looking forward to the 12 zession, will be there tomorrow note ready.

소식 전해주셔서 감사합니다

1 Like

Sorry, quick rescheduling. We will do the second session next week on May 12. I’ll post an updated schedule soon.

2 Likes

Back to it!

When: May 12, 3PM UTC
Where: Zcash Discord (recorded by @ZcashBrazil)
RSVP: Protocol Study #2: Addresses, Keys, and the Privacy Onion · Luma


Session 2 of the Zcash Protocol Study, a 12-session guided reading of the Zcash Protocol Specification.

Topic: §3.1 - Payment Addresses and Keys. The “privacy onion.”

​A single spending authority in Zcash decomposes into a tree of derived keys: full viewing key, incoming viewing key, outgoing viewing key, diversifier. Each key revealing a different slice of metadata to a different audience. §3.1 is where this is all defined, and nothing downstream in the spec makes sense without it.

​We’ll walk Sapling and Orchard side by side: what Orchard cleaned up, where the proof system forced cleaner separation between IVK and OVK, and why “many addresses, one viewing key” is the design that makes diversified addresses work.

Format: 50/50 structured study and open conversation with space to riff on implications, history, and connections. Think of it like a study group instead of a lecture. We aim to be accessible enough for a motivated newcomer and technical enough to be useful to people who are actually building.

We’ll be reading from https://zips.z.cash/protocol/protocol.pdf, §3.1.

​If you missed Session 1:

5 Likes

I just watched it; good job and keep it up <3

Session 2 (Addresses, Keys, and the Privacy Onion) is complete, and we’re back on schedule. Thanks to everyone who showed up live and to @ZcashBrazil for the recording.


Next up: Notes, Commitments, and Nullifiers (spec §3.2, §3.8, §3.9)

Session 3 covers the lifecycle of how a note is born (commitment), recorded (Merkle path), and spent (nullifier).

When: Tuesday May 19, 11 AM ET
Note that this breaks our typical two-week cadence to recover the original biweekly calendar. We will resume biweekly after this session.

RSVP: Protocol Study #3: Notes, Commitments, and Nullifiers · Luma
PDF: https://zips.z.cash/protocol/protocol.pdf, starting at §3.2.
Where: Zcash

Live on the Zcash Discord stage. Recorded by @ZcashBrazil.

2 Likes

Just a quick update: Trying to get through three foundational sections of the protocol was perhaps a bit too ambitious, so we will do Part 2 of Notes, Commitments, and Nullifiers in 2 weeks on June 2

That puts our new schedule at:

# Date Title Spec
1 Apr 21 What Problem Does Zcash Actually Solve? §1.1–1.2
2 May 12 Addresses, Keys, and the Privacy Onion §3.1
3 May 19 Notes, Commitments, and Nullifiers Pt. 1 §3.2, 3.8, 3.9
4 Jun 2 Notes, Commitments, and Nullifiers Pt. 2 §3.2, 3.8, 3.9
4 Jun 16 Transactions Unpacked: JoinSplit to Actions §3.4–3.7
5 Jun 30 Merkle Trees and How the Chain Remembers §3.8, 4.9
6 Jul 14 Proving Without Revealing: zk-SNARKs in Zcash §4.1, 4.18
7 Jul 28 Sending, Receiving, and Scanning §4.7–4.8, 4.19–4.22
8 Aug 11 Signatures, Balance, and Binding §4.10, 4.13–4.15
9 Aug 25 Under the Hood: Hashes, Curves, and PRFs §5.4
10 Sep 8 Consensus: What Zcash Changed from Bitcoin §7
11 Sep 29 Network Upgrades: Sprout to NU6 §6
12 Oct 13 Circuit Deep Dive Appendix A
1 Like

Protocol Study #3.5: Trees, Anchors, and the Nullifier Set. (aka Notes, Commitments, and Nullifiers, Part 2)

As mentioned above, we will be continuing where we left off last week. What we’ll read:

  • §3.2 (remainder): Notes
  • §3.8: Note Commitment Trees.
  • §3.9: Nullifier Sets.

PDF: https://zips.z.cash/protocol/protocol.pdf, starting at §3.2.
RSVP: Protocol Study #3.5 — Trees, Anchors, and the Nullifier Set (Notes, Commitments, and Nullifiers, Part 2) · Luma
Where: Zcash
When: Tuesday June 2, 3 PM UDT

1 Like

[Protocol Study #4] Transactions Unpacked: JoinSplit to Actions

June 16, 3pm UTC | Zcash Global Discord | RSVP

We now have the note primitives: a commitment goes into a tree, a nullifier is revealed on spend, a zk-SNARK proves the link. Session 4 threads them into the thing that actually moves value, the transaction, and follows how the shape of a shielded transfer changed across three eras of Zcash.

The whole session hangs on one question asked three times: how does a transfer prove it created exactly as much value as it destroyed?

  • Sprout answers it inside one bundled JoinSplit.
  • Sapling splits the transfer apart and answers across the whole transaction.
  • Orchard re-merges it into a single Action.

PDF: https://zips.z.cash/protocol/protocol.pdf, §3.4 to §3.7
Where: Zcash (Zcash Global Discord Stage)
RSVP: [Protocol Study #4] Transactions Unpacked: JoinSplit to Actions · Luma

Recorded and translated by @ZcashBrazil

2 Likes

Session 4 (Transactions Unpacked: JoinSplit to Actions) is in the can. Thanks to everyone who joined live and to @ZcashBrazil for the recording.

Session 5 is Tuesday, June 30, 11 AM ET.

Topic: Merkle Trees and How the Chain Remembers (spec §3.8 Note Commitment Trees, §4.9 Merkle Path Validity).

Session 4 kept leaning on one word: the anchor, the Merkle root a shielded spend proves its note sits under. Session 5 opens that root up. A single ~32-byte root stands in for every shielded note that has ever existed. We read how a commitment becomes a leaf, how the tree hashes up to that root, and how a Merkle path proves your note is in there without revealing which one. Plus why the tree hash changed three times: SHA-256 (Sprout), Pedersen (Sapling), Sinsemilla (Orchard).

Live on the Zcash Discord stage. Recorded by @ZcashBrazil.

Luma: Protocol Study #5: Merkle Trees and How the Chain Remembers · Luma
PDF: https://zips.z.cash/protocol/protocol.pdf, we’re reading §3.8 and §4.9.

5 Likes

Update: Jet lagged and a little unwell after the Prague summit. Didn’t party hard, just fell under the weather. Great trip otherwise. I want to push back the scheduled session for this week one more week.

That puts our new schedule at:

# Date Title Spec
1-5 N/A Completed -
6 Jul 21 Proving Without Revealing: zk-SNARKs in Zcash §4.1, 4.18
7 Aug 4 Sending, Receiving, and Scanning §4.7–4.8, 4.19–4.22
8 Aug 18 Signatures, Balance, and Binding §4.10, 4.13–4.15
9 Sep 1 Under the Hood: Hashes, Curves, and PRFs §5.4
10 Sep 15 Consensus: What Zcash Changed from Bitcoin §7
11 Oct 6 Network Upgrades: Sprout to NU6 §6
12 Oct 20 Circuit Deep Dive Appendix A
4 Likes

Session 5 (Merkle Trees and How the Chain Remembers) is in the can. Thanks to everyone who joined live and to @ZcashBrazil for the recording.


Next up…

Session 6: Proving Without Revealing: zk-SNARKs in Zcash

When: Tuesday, July 21, 3pm UTC

Live on the Zcash Discord stage.
Recorded and translated by Zcash Brazil.

RSVP on Luma: Protocol Study #6: Proving Without Revealing (zk-SNARKs in Zcash) · Luma
PDF: https://zips.z.cash/protocol/protocol.pdf, we’re reading §4.1 and §4.18.

4 Likes

I must be here

Lots of things to learn

Session 6 (Proving Without Revealing: zk-SNARKs in Zcash) is over, and I gotta say: the audience discussion was the best of the series so far. Thanks to everyone who joined live and to @ZcashBrazil for the recording.


Announcing Session 7: Sending, Receiving, and Scanning

Session 6 explained what a shielded transaction convinces the chain of without revealing anything. Session 7 is the wallet’s-eye view of the same transaction. How does a note actually get built and sent? How does the recipient, whom nobody notified, ever find it?

Protocol sections:

  • §4.7 Sending Notes
  • §4.8 Dummy Notes
  • §4.19-4.20 In-band Secret Distribution
  • §4.21-4.22 Block Chain Scanning

Live on the Zcash Discord stage. Recorded by @ZcashBrazil.

Luma: Zcash Protocol Study #7: Sending, Receiving, and Scanning · Luma

PDF: https://zips.z.cash/protocol/protocol.pdf

See you there!

4 Likes

This is the link to Session 6 notes

2 Likes

Thank you @Dre_Nesthub !

1 Like