Zcash developers target January for quantum-resistant signatures after 'bunker mode' warning

The Zakura team aims to land opcodes that check hash-based signatures in Zcash in January.
The plan targets transparent addresses, where about 70% of ZEC sits.
A PIR feature for private address lookups is being tested in the Vizor wallet.
The development team behind Zakura, one of the node software programs that run the Zcash (ZEC) network, said it aims to add a signature scheme designed to withstand quantum computer attacks to Zcash in January. "Our team plans for post-quantum signature opcodes to land in Zcash in January," developer Roman Akhtariev wrote on Zakura's engineering blog. January is a target only, and no network activation date has been set.
Hide the public key, sign with hashes
A wallet approves a payment with a private key, and the network checks that approval with the matching public key. Today's cryptography assumes that working backward from a public key to the private key takes an impractical amount of computing. What the team wants to add are opcodes that check hash-based signatures. A hash is a function that turns data into a fixed-length fingerprint that cannot be reversed. The team said the design is meant for a scenario in which recovering private keys from public keys becomes practical but hashes remain secure.
A standard Zcash transparent address, which starts with t1, contains a hash of the public key rather than the key itself. The public key is revealed only when funds are spent from that address. The team said moving leftover funds to a fresh address with every transaction keeps the assets behind a public key that has not yet been disclosed. Using fresh addresses does not require a new wallet or a new recovery phrase, because a single recovery phrase keeps generating distinct key pairs. The team added, however, that handing an account's extended public key (xpub) to someone else exposes far more public keys at once than an ordinary spend, so that information also needs protecting.
Address lookups can tie separate addresses together
The catch is that spreading funds across many addresses leaks information when a wallet checks its balances. A typical light wallet asks a server for transaction histories by showing it each address, which tells the server that all of those addresses belong to one user. Addresses that look unrelated on the blockchain end up tied together during the lookup.
To prevent this, the team used PIR, or private information retrieval, a cryptographic technique that lets a database return a record without learning which record was requested. A wallet first downloads small activity filters and queries only the ranges that might contain its addresses. The team said a filter for a range containing 10,000 distinct payment scripts needs only about 15 KB. The feature is available as an experimental version under the "Private queries" setting in Vizor, a Zcash wallet, and the team said it is coming to Vizor this week. Transactions themselves remain public on the blockchain as before.
70% of ZEC in transparent addresses, no won trading on Upbit or Bithumb
Zcash payments come in two kinds: shielded payments, which conceal the sender, recipient and amount, and transparent payments, which show addresses and amounts much like bitcoin. Of the 16.98 million ZEC issued, about 11.96 million sat on the transparent side as of Oct. 8, according to CoinDesk's calculation from ZecStats data. The January plan targets that transparent side. The shielded side needs separate work. Zcash's quantum recoverability design document (ZIP 2005, at the proposal stage) warns that an attacker who obtains a recipient's address could collect encrypted payment records today and try to decrypt them after a future mathematical breakthrough.
The announcement came right after Ethereum researcher Justin Drake called on X on Oct. 7 (U.S. time) for the industry to prepare for "bunker mode." Drake said that in the worst case, artificial intelligence could find a shortcut through the mathematics protecting bitcoin and ether wallets "in months, not years." He urged large holders to gradually move funds to addresses whose public keys have never appeared onchain, with sophisticated holders going first. The warning came a day after OpenAI released 722 mathematical manuscripts produced by an unreleased model. Drake said the elliptic-curve mathematics behind bitcoin and ether signatures has regular patterns that AI could exploit, while hash functions are designed to strip out as much pattern as possible. Ethereum co-founder Vitalik Buterin agreed the risk is real but said holders who rush a migration could lose assets through mistakes. No practical attack on bitcoin or ether wallet keys has been demonstrated so far. The Ethereum Foundation has set December 2029 as its target for moving to quantum-resistant cryptography, and its long-term design is also leaning toward hash-based signatures.
On Binance, ZEC fell more than 10% on Oct. 8 (UTC) to close at $1,187, and traded around $1,225 at about 10:30 p.m. KST on Oct. 9. In South Korea, ZEC is not listed on the Korean won markets of Upbit or Bithumb.