- Zakura is targeting January 2027 for quantum-resistant Zcash signatures.
- Fresh addresses limit public-key exposure but can create privacy risks.
- Private wallet queries offer a way to protect address relationships.
Zcash’s preparations for quantum computing have revealed a security trade-off that extends beyond replacing vulnerable digital signatures: protecting a wallet’s public keys can inadvertently expose its financial activity to third-party servers.
Developers at Zakura are working on a system that addresses both problems. The project combines transparent address rotation with private transaction lookups, allowing wallets to monitor funds without disclosing their complete address history to infrastructure providers.
The work accompanies a January 2027 target for introducing hash-based signature verification, which would reduce reliance on cryptography that sufficiently powerful quantum computers could eventually break.
While the proposed signatures address who can authorize transactions, the wallet infrastructure tackles a different question: who can observe the addresses a user controls?
For Zcash, where privacy is a defining feature, the distinction has practical consequences.
Why Fresh Addresses Are Not a Complete Defense
Zcash supports both transparent and shielded transactions.
Transparent transactions expose addresses and amounts on the blockchain, while shielded transactions use zero-knowledge cryptography to conceal sensitive payment information.
The difference becomes significant when examining future quantum threats.
A standard transparent address contains a hash of a public key. Once funds are spent, the underlying public key becomes visible as part of transaction validation.
Today’s computers cannot feasibly derive the corresponding private key from that information. A sufficiently capable quantum computer running Shor’s algorithm, however, could undermine the elliptic-curve cryptography used to authorize transactions.
One precaution is to avoid reusing addresses after their public keys have been revealed.
Consider a user holding 100 ZEC who sends 10 ZEC to another wallet. Returning the remaining 90 ZEC to the original address leaves those funds associated with a previously exposed public key.
Sending the change to a fresh address reduces that exposure because the new public key is not immediately disclosed.
This does not make the funds fully quantum-resistant. It limits the cryptographic information available to a potential attacker.
The difficulty emerges when users manage dozens or hundreds of addresses.
To calculate balances and identify incoming payments, many wallets query external servers. Those requests can reveal which addresses belong to the same user, even when the blockchain does not explicitly connect them.
A wallet holder may therefore reduce public-key exposure while creating a detailed record of their activity at the infrastructure level.
The addresses remain separate onchain, but the server handling the requests may learn that they belong together.
That is the privacy gap Zakura is attempting to close.
Checking Balances Without Revealing Wallet Addresses
Zakura’s solution uses private information retrieval, or PIR, a cryptographic technique that allows a client to retrieve database information without revealing which record it requested.
Applied to Zcash, the system lets wallets search for transactions without submitting a readable list of their addresses to the server.
According to Zakura’s engineering documentation, the implementation organizes confirmed blockchain activity into ranges of blocks and uses compact public filters to identify potentially relevant transactions.
A wallet downloads those filters and checks them locally. When a range contains possible matches, it retrieves the corresponding records through a private query.
A filter covering 10,000 distinct payment scripts requires approximately 15 KB of data.
That relatively small download helps wallets avoid retrieving unnecessary transaction records while reducing the information exposed to infrastructure providers.
The design also supports wallet restoration.
Recovering a wallet involves more than identifying addresses with positive balances. The software must reconstruct historical activity, including payments received and subsequently spent.
Zakura’s system is designed to retrieve those records privately, allowing users to restore wallets containing numerous previously used addresses.
An experimental implementation is already available through the Private queries setting in the Vizor wallet.
The protection has a clear boundary.
PIR does not conceal transparent transactions on the blockchain. Addresses, amounts and transaction relationships remain publicly visible.
Instead, it prevents a wallet’s balance-checking activity from unnecessarily revealing additional information to the server providing transaction data.
This makes private retrieval useful independently of the planned signature upgrade.
Extended Public Keys Introduce Another Weakness
Address rotation also raises questions about how wallets derive and manage their keys.
Most modern cryptocurrency wallets use hierarchical deterministic structures, allowing numerous addresses to be generated from a common recovery seed.
This makes backups simpler, but the relationship between derived keys can introduce security considerations.
An extended public key can reveal the public keys associated with multiple addresses belonging to the same account.
Under certain non-hardened derivation structures, combining an extended public key with one corresponding child private key can allow an attacker to recover the parent private key.
That may expose additional addresses derived from the same account.
An extended public key alone does not grant spending authority. The risk arises when it is combined with compromised private-key material.
Nevertheless, it demonstrates why address rotation cannot be treated as a complete solution.
A wallet could generate a fresh address for every payment while still exposing account-level information through an application, service or backup process.
The security benefit depends on how keys are derived, stored and shared, not simply how often addresses change.
January 2027 Is a Development Target, Not an Activation Date
Zakura is targeting January 2027 for post-quantum signature verification support in transparent Zcash transactions.
The proposed instructions would allow transactions to use signatures based on cryptographic hash functions rather than relying exclusively on existing elliptic-curve signatures.
The team has also discussed Winternitz one-time signatures, or WOTS, as a potential interim approach alongside conventional keys.
Hash-based signatures avoid the particular mathematical weakness that makes elliptic-curve cryptography vulnerable to Shor’s algorithm.
The approach has an established foundation in cryptographic research. The U.S. National Institute of Standards and Technology has standardized a stateless hash-based digital signature algorithm under FIPS 205.
That standard provides useful context, although it does not establish which exact construction Zakura will deploy.
The engineering challenges extend beyond signature verification.
Some hash-based schemes produce larger signatures, increasing transaction data requirements. One-time signature systems also require careful key management because reusing signing material can compromise security.
Wallets must support the new authorization process, while network participants must agree on the consensus rules governing it.
The January milestone remains a development objective. No confirmed mainnet activation date or mandatory migration schedule has been announced.
For existing ZEC holders, that means the proposed technology should not be mistaken for protection already available through ordinary wallet transactions.
Transparent Holdings Make Migration a Significant Task
The scale of Zcash’s transparent supply gives the proposed changes substantial relevance.
According to an October 9 snapshot cited by TokenPost, approximately 11.96 million ZEC was held in transparent unspent transaction outputs out of roughly 16.98 million ZEC issued.
That represents about 70.4% of the supply.
The figure does not mean all those coins are immediately vulnerable to quantum attacks.
Some addresses have never revealed their public keys, while others have been used repeatedly. Their potential exposure depends on transaction history and key-management practices.
There is also no publicly demonstrated quantum computer capable of breaking the signatures protecting major cryptocurrency networks at the scale required for practical theft.
Still, the figures indicate how much of Zcash’s issued supply depends on the transparent transaction environment.
A future migration would need to accommodate existing balances, compatible wallets and users with varying levels of technical experience.



