Shielded Labs, an organization that works on the Zcash cryptocurrency protocol, announced on October 1 a research and engineering project called Epoch. Its goal is production-ready post-quantum cryptography that could replace the parts of Zcash that a large quantum computer could break, together with formal verification of the protocol’s critical cryptographic components. Source: Shielded Labs

Zcash’s current protocol is built on elliptic-curve cryptography, a kind of public-key cryptography that a sufficiently powerful quantum computer could break. That threat is why new quantum-resistant algorithms have been standardized; our explainer covers what post-quantum cryptography is.

What Epoch will do

Shielded Labs says the first phase will survey existing research and test which candidate constructions can meet Zcash’s security and performance requirements, with a concrete post-quantum design proposal as the first goal. It is targeting a production-ready cryptographic implementation by the end of 2027 that “could serve as the basis for a future Zcash upgrade.”

The organization set several requirements for that implementation: at least 128 bits of security for confidentiality and soundness, minimal and well-understood security assumptions, formal verification, and practicality for Zcash as it exists today. It says the first version may be narrower in scope than Project Tachyon, a separate Zcash effort it will coordinate with, and that some of the questions remain open research problems.

The team has three members: Ulrich Haböck as chief cryptographer, who joins from StarkWare, and Luke Edwards and Suyash Bagad as cryptography engineers, both from Aztec.

Why formal verification is part of it

Shielded Labs says some of the most serious cryptographic failures come from mistakes in design or implementation rather than broken mathematics, and points to Zcash’s own Sprout vulnerability, found in 2018, and Orchard vulnerability, found in 2026. Formal verification uses mathematical proof to check that code behaves as its design intends, which the group says offers more assurance than audits alone.

What has not changed

Zcash is not post-quantum today, and Shielded Labs says so. It describes one interim step already in place: since the NU6.3 upgrade, Ironwood notes have been designed to be “quantum-recoverable,” so funds could be recovered through a future protocol if the current elliptic-curve-based one ever had to be disabled. Epoch itself is a plan and a timeline, not a network upgrade, and any change to Zcash would still need to go through the network’s own upgrade process.

Epoch joins other blockchain projects testing post-quantum designs, such as the Tezos Quantumnet experimental network. Shielded Labs says it will publish research findings and benchmarks as the work progresses.