Mert & Dev: Zcash Is About To Explode (Full Project Update)
Friday, 21 August 2026 · 4 min read · Listen to the episode ↗
Deve, co-author of the foundational post-quantum recursion paper Fractal and a founding contributor to Tendermint, Cosmos, and Osmosis, joins Mert to explain why he chose to build Ballard Group around scaling Zcash to 50,000 or more transactions per second at sub-second finality within two to three years.
Deve founded Ballard Group with the goal of scaling Zcash to credit card level throughput under proof of work, predicting the network will handle 50,000 or more transactions per second at sub-second finality within two to three years. He co-authored the first paper on post-quantum recursion, called Fractal, which became foundational to the broader zero-knowledge industry including binary fields, Binius, and Starks. He was also part of the founding teams for Tendermint, Cosmos, and Osmosis before choosing Zcash over building a privacy layer on Solana, based on the conviction that uncompromising privacy must exist at the base layer, especially as AI accelerates.
Roughly a year or more before the Ironwood upgrade, Zcash core teams ramped up red teaming and AI-assisted audits. A domain expert named Taylor used AI tools to find a vulnerability that could have allowed counterfeiting of shielded notes within the Orchard pool. The turnstile mechanism limits any such vulnerability to the Orchard pool only, not the entire Zcash supply, and approximately 85 to 90 percent or more of Zcash has since migrated out of the Orchard pool following Ironwood. If the turnstile does not trigger after migration, it confirms the vulnerability was never exploited. Mert placed statistical confidence of non-exploitation at roughly 95 percent, with logical confidence closer to 99.99 percent.
Ironwood is formally verified, meaning there is a mathematical proof that the circuit implementation perfectly matches the specification, so if a proof passes, total inputs equal total outputs and no new money is created. The Orchard vulnerability was an implementation bug distinct from any spec design error and took years or AI assistance to detect. Ironwood is also recoverable, unlike the prior Orchard pool, and is mathematically proven sound with no counterfeiting possible as long as cryptographic assumptions hold.
The next shielded pool, called Tachyon, will be quantum proof, use simpler circuits and simpler arithmetic, and reduce the attack surface by an order of magnitude. Tachyon introduces recursive zero-knowledge proofs into Zcash and achieves full post-quantum privacy with no conditionals, meaning quantum computers cannot learn anything about any transaction. Current Zcash quantum protections are conditional, with privacy leakage only a concern if a quantum computer operator already knows a user's address, and even then only payments received are exposed, not payments made. Ironwood already addresses fund safety from quantum computers, allowing users to migrate to a new quantum pool even decades after quantum computers arrive. Dev stated Zcash will have completed three of four quantum protection layers within a couple of months when Tachyon ships, with one additional low-urgency layer remaining afterward.
Tachyon also includes a folding technique, formerly called accumulation, which reduces transaction size by more than five times and eliminates node processing time and state size as scaling bottlenecks, leaving only consensus bandwidth as a remaining constraint. Tachyon changes wallet syncing so that scanning is eliminated entirely, replacing the current model where a million transactions require scanning a million items. Wallet sync speed has already been improved by approximately six times ahead of Tachyon shipping. The upgrade is led primarily by the Zekura team, with Shanbo identified as the fundamental project lead.
Dev argued Zcash already solves the two most important quantum protection layers, specifically commitment to a concrete plan and safe long-term fund holding, and that Bitcoin lacks a clear plan for quantum resistance. He noted that Satoshi's coins would be stolen under any Bitcoin quantum freeze scenario because they do not follow HD path assumptions, and that Bitcoin contributors exhibit risk aversion due to past success, which itself constitutes a form of the innovator's dilemma.
Zcash has a fixed supply of 21 million coins, uses proof of work, and launched as a fair launch without high fully diluted valuation and low float mechanics. A 20 percent block reward allocation has been built into the protocol since inception and is set to expire in 2028, after which token holders can re-vote to continue, modify, or end the allocation entirely, with the option to return all rewards to miners. Cypherpunk Technologies announced it represents up to 16 percent of Zcash mining hashrate, holds a large amount of ZEC, and publicly posts its stance on every governance vote. Mert noted that shielded Zcash is available on almost no exchanges and that Zcash is delisted in many jurisdictions, yet argued competition in the private money market is not fierce compared to other crypto sectors, and that anonymity set network effects make it very difficult for competitors to siphon liquidity from Zcash.
This summary was generated from the episode transcript and can contain mistakes.