A debate on X this week exposed a core question for on-chain privacy: when quantum computers are able to break elliptic-curve cryptography (ECC), will they be able to retroactively deanonymize every transaction ever made of privacy coins like Zcash? Nic Carter, co-founder of Coin Metrics and partner at Castle Island Ventures, argued that the answer […]A debate on X this week exposed a core question for on-chain privacy: when quantum computers are able to break elliptic-curve cryptography (ECC), will they be able to retroactively deanonymize every transaction ever made of privacy coins like Zcash? Nic Carter, co-founder of Coin Metrics and partner at Castle Island Ventures, argued that the answer […]

Is Zcash Quantum-Resistant Yet? Experts Weigh In

2025/11/01 07:00

A debate on X this week exposed a core question for on-chain privacy: when quantum computers are able to break elliptic-curve cryptography (ECC), will they be able to retroactively deanonymize every transaction ever made of privacy coins like Zcash?

Nic Carter, co-founder of Coin Metrics and partner at Castle Island Ventures, argued that the answer is effectively yes for most privacy coins. “For privacy coins, even if they migrate to post-quantum cryptographic schemes, all historical transactions prior to that migration can be decrypted,” he said on October 30, 2025. “So all historical txns will be stripped of privacy in >~5y. Everything is built on ECC.”

Carter’s point is based on “harvest now, decrypt later.” Attackers don’t need to break you today. They just copy the data now and crack it once quantum is strong enough. On blockchains, that problem is worse because the data is already public and permanent. “Blockchains are uniquely bad for quantum because normally the quantum thing is ‘harvest now decrypt later’ so adversaries have to be preemptively harvesting traffic but blockchains just.. publish.. everything.. forever.”

He warned specifically that even if a privacy coin upgrades to quantum-resistant signatures in the future, old activity is still exposed once ECC falls. “While privacy coins can adopt post quantum sigs, understand that all previously hidden addresses, relationships between addresses, etc, will be revealed once ECC is broken,” Carter said. “And obviously everything is on chain so you don’t even need to harvest traffic today.”

Is Zcash Already Quantum-Resistant?

That claim triggered pushback from Zcash supporters, who argue Zcash is structurally different from something like Monero.

Mert Mumtaz (Helius) agreed that Carter’s warning applies to “many privacy coins like Monero,” but said it’s “not necessarily true for zcash’s privacy, given advanced opsec.” He acknowledged that “advanced opsec is not the norm,” but said that if it is followed, Zcash users “get you certain guarantees w.r.t information leakage.” He also said “some things are in the works to make this even stronger,” pointing to research by Zcash engineer Sean Bowe.

Bowe’s position is that Zcash’s fully shielded pool simply does not put critical sender/receiver information on the ledger in the first place. “There is no quantum computer or powerful AI that will be able to look back at the Zcash blockchain 1000 years from now and figure out who made every fully shielded transaction,” Bowe said in July this year. “That information, among other things, never even touches the ledger. It’s already gone.” His condition is clear: “To be certain about your privacy you must start by using shielded Zcash. You almost cannot even begin otherwise.”

Carter partially credits that. “Zec is definitely ahead of anyone when it comes to quantum preparedness, not denying that,” he said. But he called the “already quantum-proof” framing unrealistic in practice.

He argued that Zcash’s long-term privacy story depends on very strong assumptions that often break in the real world: “assumes pubkey never being known. assumes: no metadata collection, no exchange key leaks, perfect metadata privacy.”

He added that Zcash’s shielded pools — Sprout, Sapling, Orchard — still “rely on ECC for key exchange, viewkeys, proof verification, which are all broken” under a powerful quantum adversary. His conclusion: “unrealistic to say zec privacy is perfectly q resistant. linkages between addrs are forever encoded on the blockchain, you and Sean know that. store now decrypt later still applies.”

In other words: Zcash builders say that if you stay fully shielded, the chain itself won’t hand quantum attackers a clean map of who paid whom. Carter says that in the real world, users leak, exchanges leak, metadata leaks — and once ECC breaks, those leaks plus the permanent ledger are enough to unwind the privacy anyway.

One final note: when asked directly, Carter denied holding ZEC. “Nope.”

At press time, ZEC traded at $366.

Zcash price
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

Cleaning Up Crypto ATMs Isn’t Anti-Crypto

Cleaning Up Crypto ATMs Isn’t Anti-Crypto

The post Cleaning Up Crypto ATMs Isn’t Anti-Crypto appeared on BitcoinEthereumNews.com. When Iowa Attorney General Brenna Bird filed lawsuits against CoinFlip and Bitcoin Depot earlier this year, a few astroturfed voices cried that this consumer protection push was “anti-crypto.” They’re wrong. Crypto ATMs – physical kiosks that let users buy crypto – have become a vehicle for fraud, and they need reform. Law enforcement, regulators, and consumer advocates have all raised concerns about these machines for years. DC AG Brian Schwalb sued Athena Bitcoin in September. Pennsylvania AG Dave Sunday has warned that BATMs are a “magnet for scammers.” Arizona AG Kris Mayes even posted “STOP” signs at some crypto ATM locations.  Congressional scrutiny is also increasing. Senator Cynthia Lummis (R-WY), a longtime Bitcoin advocate, has called for stronger safeguards. Earlier this year, Senate Judiciary Ranking Member Dick Durbin highlighted abuses, and a few weeks ago, Senator Elizabeth Warren called out crypto ATM operators, signaling that regulatory pressure will only intensify. The Evidence Nationwide, the FBI estimates that in the first half of 2025 , Americans lost $240 million to crypto ATM fraud. The Iowa AG’s office contacted the top 50 Bitcoin Depot users in Iowa between 2021 and 2024, representing more than $2.4 million in transactions. Of the 34 who responded, every single one confirmed they had been scammed. Likewise, an investigation by the DC Attorney General uncovered that 93% (!) of Athena ATM deposits in the District of Columbia during a five-month period were scam transactions.  The stories follow a predictable pattern: romance scams, bogus police calls, phony tech support. Scammers play on panic, steering victims to crypto ATMs where they’re told to pour in cash and send crypto to wallets run by criminals. Store clerks at the convenience stores and smoke shops where the kiosks are hosted have tried to intervene, but to do so effectively, they need training…
Share
BitcoinEthereumNews2025/11/05 08:29