The Zakura team, responsible for maintaining a full node for Zcash, stated it plans to introduce post-quantum signature opcodes to the Zcash network in January. The update aims to enhance the security of funds held in transparent addresses by making them resilient against attacks from quantum computers.
Post-quantum security for Zcash
Roman Akhtariev, an engineer working with Zakura, disclosed in a recent update that post-quantum signature opcodes are expected to be available for Zcash in January. While the team set this implementation goal, it did not specify a date for activation on the mainnet.
Akhtariev explained that the focus is on achieving full post-quantum-safe transparent pools, relying on hash-based signature schemes. This upgrade is aimed at users with transparent addresses, which are distinct from Zcash’s shielded addresses that use zero-knowledge proofs for privacy.
Currently, wallets can combine a hash-based signature scheme known as WOTS with the usual elliptic-curve key for transparent addresses. This pairing allows users to generate rotating transparent addresses that are post-quantum safe. However, Zakura acknowledged there is no integrated wallet experience for this functionality yet.
Mini dictionary: WOTS (Winternitz One-Time Signature) is a hash-based digital signature scheme considered to be secure against quantum attacks, offering post-quantum cryptography features.
Protection for public keys
Zakura clarified that a transparent Zcash address contains a hash of a public key. When funds are spent from such an address, the underlying public key becomes public. To safeguard remaining funds, users can transfer the leftover balance to a new address whose public key has not been revealed.
This mechanism is intended to maintain privacy and security, particularly if public keys could become vulnerable to quantum attacks while hash functions remain secure. Zakura noted this approach adds an extra layer of protection for Zcash’s transparent address users.
Improving privacy with PIR
Zakura identified a challenge related to wallet lookups. When a wallet checks multiple rotating addresses using a typical server request, the server learns those addresses likely belong to the same owner, undermining privacy even if blockchain analysis cannot make the connection.
To counteract this, Zakura is implementing private information retrieval (PIR) technology. Using PIR, a wallet can fetch specific data from a server without revealing which record it is accessing. The network divides transparent transaction data into block ranges, with each range managed by a shard that shares a compact filter. Wallets check these filters locally and perform private lookups only when necessary. According to Zakura, a range with 10,000 distinct payment scripts requires about 15 KB of filter data.
Mini dictionary: Private Information Retrieval (PIR) is a cryptographic method that allows a user to retrieve data from a server without the server knowing which specific data was accessed, helping protect user privacy.
| Method | Data Privacy Level | Server Awareness | Data Size Example |
|---|---|---|---|
| Standard lookup | Low | Knows queried address | N/A |
| PIR-based lookup | High | No knowledge of queried address | 15 KB per 10,000 scripts |
The same approach can restore a wallet’s transaction history from a mnemonic phrase, including addresses with no remaining funds. An experimental PIR feature has been added to the Vizor wallet and can be tested by enabling “Private queries” in its settings.
Industry context and future outlook
Ethereum Foundation researcher Justin Drake recently urged the industry to prepare for “bunker mode” by moving funds to fresh addresses that have not previously signed transactions. Drake warned of the possibility that cryptographic schemes like ECDSA could be compromised sooner than expected, advising caution and measured action rather than panic.
Zakura noted that while Zcash transparent transactions remain publicly visible on-chain, PIR addresses the privacy of wallet lookups required to manage these transactions. Post-quantum security and advanced privacy tools are becoming focal points as the blockchain sector adapts to emerging threats posed by quantum computing advancements.
Zakura’s engineering team aims to implement post-quantum signature opcodes in Zcash by January and introduce PIR for secure lookups in the Vizor wallet, strengthening privacy and resilience against future quantum attacks.




