Zcash is a cryptocurrency built from the same code as Bitcoin, with one addition: it can hide who sent a payment, who received it, and how much moved. That privacy is optional, chosen per transaction. Most of the supply never gets that choice made, and about 3 in every 4 ZEC sit in public view.
That single word, optional, changes how you should read everything below. Zcash runs two ledgers inside one chain. One side is transparent and reads as easily as Bitcoin's. The other is shielded, where outsiders see that a valid payment happened but learn nothing about it. Which side a coin sits on comes down to what its holder chose.
So the useful question is not really "is Zcash private". It is "when is Zcash private, and what does it take to get there".
What Zcash actually hides, and what still leaks
A shielded Zcash transaction hides three things from the public ledger: the sender's address, the receiver's address, and the amount. Anyone can still see that a valid transaction happened. What they cannot see is who was involved or how much moved, because that information is never published in the first place.
That is a real and unusual guarantee, and the project documents it as confidentiality rather than as anonymity (source: Electric Coin Co.). So it is worth being precise about where it stops. Privacy on a blockchain works as a stack of separate leaks rather than a single setting. Shielding closes some of them and leaves others wide open.
| What someone might learn | Shielded transaction | Transparent transaction |
|---|---|---|
| Sender address | Hidden | Public |
| Receiver address | Hidden | Public |
| Amount | Hidden | Public |
| That a transaction happened | Visible | Visible |
| Your IP address, if you broadcast carelessly | Can leak | Can leak |
| Your identity at the exchange you bought from | Known to the exchange | Known to the exchange |
| The link between your exchange withdrawal and your wallet | Broken only if you shield after | Fully visible |
Transparent and shielded are two sides of one chain. Your wallet picks a side when you send.
Read that last row twice, because it catches almost everyone. Most exchanges will only send withdrawals to a transparent address, so in practice the ZEC you withdraw usually lands transparent. The exchange knows who you are, and the ledger records the address it sent to. Shielding those coins afterwards protects what you do next, but it does not erase the trail that already exists. Privacy is forward-looking, not retroactive.
There is also a plain-language point worth making early. You will see Zcash described as anonymous or as impossible to trace. Those words oversell it and they can get people into trouble, because they suggest a guarantee the system does not offer. What Zcash gives you is strong confidentiality on the transactions you choose to shield, sitting on top of a public network that still leaks context around the edges. If you want the general version of that idea, our guide to crypto privacy basics covers how these leaks work across any chain.
Which raises the question most explainers skip entirely: does any of this happen automatically?
Privacy on Zcash is a choice, not a default
Zcash privacy does not switch itself on. It is opt-in, one transaction at a time. When you send ZEC, your wallet either uses a transparent address, which behaves exactly like a Bitcoin address, or a shielded address, which uses the private machinery. Both are normal and both are valid. The network is happy either way.
This is the most important thing to understand about the asset, and it explains a fact that surprises people: most ZEC does not sit in the shielded pools. At the time of writing, roughly three quarters of the supply sits in transparent addresses. Anyone can check that figure from a node or a block explorer (source: Zcash Block Explorer). The reason has little to do with what users prefer. Exchanges hold and move enormous amounts of the supply, and they overwhelmingly use transparent addresses, because transparent addresses are simpler to integrate and easier to account for. So the default state of the network is public, and privacy is something individual holders switch on.
Picture the same ten coins taking two different routes. In the first, you buy ten ZEC and withdraw them to a transparent address. Later you send five to a friend's transparent address. The public ledger now shows a wallet that received ten and sent five. It also shows exactly which address got them. In the second, you buy the same ten and withdraw them to a transparent address. Then you shield the whole balance and send five from your shielded address to your friend's shielded address. The public ledger shows a wallet that received ten and shielded them, and then it shows nothing further. Same coins, same amounts, completely different public record.
That is the choice. It costs you a little time and a slightly higher fee, and it buys you confidentiality from that point forward.
When you would actually choose to shield
Nobody shields everything, and there is no reason to. The sensible approach is to think about what a public record would reveal that you would rather it did not.
Paying someone directly is the obvious case. A transparent payment tells the recipient your full balance and your entire transaction history, because they now have your address and the ledger is open. Most people would not hand a stranger their bank statement to settle a dinner bill, and a transparent payment does something close to that.
Cross-border transfers are another. If you regularly move money to family in another country, a public ledger builds a permanent, searchable record of exactly how much you send and how often, which is information that has real safety implications in some places.
Donations sit in the same category. Supporting a cause should not require publishing the fact, the amount, and the timing forever, and shielded payments let a recipient prove they received funds without the donor's side being on display.
Commercially sensitive transfers round it out. A business paying a supplier in crypto publishes its costs and its counterparties to every competitor watching the chain. That is basic commercial confidentiality rather than a privacy preference.
So if it is a choice, what exactly are you choosing between?
The two sides of the chain: transparent and shielded
The two sides are different address types on the same chain. A transparent address behaves like a Bitcoin address. It publishes everything. A shielded address publishes nothing beyond the fact that a valid payment happened. Your wallet picks one when you send, and that choice is the whole difference.
The analogy that helps here is a postal one. A transparent transaction is a glass envelope, so the address and the contents are readable by anyone who handles it. A shielded transaction is a sealed envelope with a tamper-proof receipt attached, proving the letter is legitimate and correctly stamped without anyone opening it. Both travel the same route and both are accepted by the same system.
In Zcash terms, the glass envelope uses a transparent address. It works essentially the way Bitcoin does, which is unsurprising given Zcash was built from the Bitcoin codebase (source: Electric Coin Co.). That inheritance is worth sitting with for a moment, because it means a transparent Zcash address carries exactly the same privacy limits as a Bitcoin one, and our guide to how private Bitcoin really is applies to it almost word for word. The sealed envelope uses a shielded address, and those live in what Zcash calls a shielded pool.
There have been four of those pools over the network's life, arriving one per generation as the cryptography improved (source: Zcash Improvement Proposals). The reason there was more than one at all is practical. You cannot upgrade cryptography in place, so each new pool launched alongside the old one, which kept running for anyone who still held funds there. The current pool broke that pattern in July 2026: it replaced its predecessor rather than running beside it, and it closed the old one behind it. That happened for a specific reason, covered later on this page and in full in our guide to how the shielded pools work.
You do not need to track pool history to use Zcash, and this guide deliberately keeps it shallow. What matters at this level is the shape. One chain has a public side and a private side, and your address type tells the wallet which one you are using. Newer wallets hide most of that behind a single unified address that bundles several receiver types together, so the sender's wallet simply picks the best one it supports (source: Zcash Improvement Proposals).
Sealing that envelope takes real cryptography, so it is worth knowing what does the sealing.
How a shielded transaction proves itself without revealing anything
A shielded transaction carries a mathematical proof. The proof convinces every node on the network that the payment follows the rules. It shows the coins exist and that they belong to the spender. It also shows they have not already been spent. It reveals none of the underlying details. This class of proof is called a zero knowledge proof (source: Electric Coin Co.).
The name sounds abstract, so here is the everyday version. Imagine proving you are over eighteen without showing your date of birth or your name. You hand over a token that the bar can check. The check comes back valid, and the bar learns exactly one thing: you are old enough. It learns nothing else about you. A zero knowledge proof does that for money.
The reason this is hard, and the reason Zcash needed years of research rather than a weekend of coding, is the not-already-spent part. On a transparent chain, the network prevents double spending by simply looking: it can see which coins moved where. On a shielded chain it cannot see anything, so the proof itself has to guarantee it. Zcash handles this by publishing a one-way marker whenever a coin is spent. The network can check that marker against every previous one for duplicates, and it learns nothing about which coin the marker refers to.
That machinery has a history, and it is the reason there is more than one shielded pool. Two of the upgrades replaced the proving system outright with a better one, and one of those removed a requirement that had bothered people for years: a setup ceremony that participants had to be trusted to perform honestly. The current pool is the exception, because it reuses the previous protocol on a corrected circuit rather than introducing a new proving system. Our guide to what a zero knowledge proof actually is goes into the machinery, and the trusted setup question has a page of its own. This guide stays at the level of what the proofs do for you.
The important takeaway is a trade rather than a triumph. Because the shielded side is genuinely opaque, the network's ability to verify what is inside it rests entirely on those proofs being sound. When the proofs are sound, the guarantee is extremely strong. When they are not, nobody can see the problem by looking at the ledger, which is exactly the situation Zcash found itself in during 2026. We will come back to that.
Where ZEC comes from, and who gets paid
ZEC is the coin that runs on the Zcash network, and its supply schedule will look familiar to anyone who knows Bitcoin. There will only ever be 21 million ZEC. New coins arrive as block rewards, and the reward halves roughly every four years (source: Electric Coin Co.).
The same logic as our explainer on how halving schedules work applies here.
There are two differences worth knowing, and a worked comparison makes both concrete. Bitcoin issues one block roughly every ten minutes; Zcash issues one roughly every 75 seconds. Over a single hour that is about 6 Bitcoin blocks against about 48 Zcash blocks, so Zcash pays out far more often in far smaller pieces while both curves head to the same 21 million ceiling.
The first is speed. Zcash targets a much shorter gap between blocks than Bitcoin does, so blocks arrive far more often and each one carries a proportionally smaller reward. The total issued over time still tracks the same curve.
The second is more unusual, and it is where Zcash genuinely diverges. The block reward is not paid entirely to miners. A portion is directed by the protocol itself toward funding development, written into the consensus rules rather than left to donations or a foundation's treasury. Since the 2024 halving that share has been split between a community grants budget and an in-protocol reserve known as the lockbox (source: Zcash Improvement Proposals). In other words, the network sets aside money for its own upkeep automatically. The catch is that the lockbox portion cannot actually be spent yet. No mechanism for releasing it has been agreed, and deciding that is still an open question.
New coins are produced through mining, using a proof of work system called Equihash. If you want the general mechanics, our guide to proof of work covers them. The practical note for a retail reader is short: network difficulty now sits in the hundreds of millions, which reflects large amounts of purpose-built hardware, so mining Zcash at home on a laptop or a gaming card is not a realistic path to acquiring ZEC (source: Zcash Block Explorer). Buying it is.
One thing Zcash does not have, despite a persistent belief otherwise, is staking. There is no way to lock up ZEC and earn a protocol yield today. Work on a hybrid design that would add a proof of stake layer has been going on for some time, but it has not shipped and no activation date has been published. Treat any service offering "Zcash staking" with real caution, because whatever it is doing, the protocol is not doing it.
Someone has to build all of this, which is where Zcash gets genuinely unusual.
Who builds Zcash, and who decides what changes
No single company controls Zcash. It came out of academic cryptography rather than a forum post, the research was published as the Zerocash paper by academic cryptographers, and the network launched in 2016. Development today is spread across several independent organizations, and protocol changes go through a public written proposal process (source: Zerocash paper).
It was one of the first large-scale uses of zero knowledge proofs outside academia. That origin still shapes the project. It moves slowly and it argues in public.
That process is where the useful detail is. Each proposal gets a number and a status, and that status is the single most useful thing a reader can learn about Zcash, because it is what separates what exists from what is merely being discussed.
The ladder runs roughly like this. A proposal starts as a draft, which means someone is writing it and nothing is decided. It can become proposed, which means it is a serious candidate under review. It reaches final or active once it is settled and in force. A great deal of confusion about Zcash comes from articles that quote draft proposals as though they were features.
One warning if you go and read the proposals yourself: the repository can lag the live network. Upgrades have been documented after they shipped rather than before, so a status field is a good guide to intent and a poor guide to what the chain is doing this week. Check the network, not just the paperwork.
That distinction matters right now more than usual, because Zcash has an unusually crowded list of things being worked on. Changes to how the network funds itself, support for other assets inside shielded transactions, and the proof of stake work mentioned earlier are all still proposals. Every one of them is interesting, and none of them is something you can use today.
The funding question is genuinely unsettled rather than merely pending. The mechanism that directs part of the block reward toward development has been extended and restructured more than once, and the current round of proposals about how accumulated funds should be released and who should decide is still open. It is a real governance dispute, in public, with real disagreement.
That same process is also what handled the most serious thing that has happened to the network.
The 2026 security incident, and what it revealed
In May 2026 a researcher auditing the shielded protocol found a flaw in its circuit that could have let someone create ZEC out of nothing. The flaw had been present since that pool went live in 2022, it was found by an audit rather than by an attacker, and the network's response was fast and blunt (source: Zcash Community Forum).
Developers pushed an emergency update that disabled the affected pool across the whole network. No funds were stolen or lost, though for a period they could not be moved (source: Zcash Improvement Proposals). A later upgrade re-enabled shielded spending on a corrected circuit, and a further upgrade in July 2026 moved the network onto a fresh pool and sealed the old one behind it.
The lasting lesson is the part worth carrying away from this page. Because the shielded side is genuinely private, nobody could look at the ledger and confirm whether the flaw had ever been used. Zcash tracks value crossing between pools, so coins moving in and out are accounted for, but it cannot see counterfeiting that happens entirely inside a pool. Developers said they believed exploitation was unlikely. Belief is not the same thing as proof.
The fix was designed around exactly that gap. Rather than asking anyone to take an assessment on trust, the new pool seals the old one and lets funds leave only through a gate that refuses to release more ZEC than legitimately went in. If counterfeit coins were ever created, they are now stuck. You do not have to trust anyone's judgment: run a node and you can check the supply limit is being enforced yourself (source: Shielded Labs).
That is the trade at the heart of every privacy chain. Confidentiality and public auditability pull against each other, and Zcash chose confidentiality. The price showed up here, because for a period the honest answer to "how much ZEC exists" was "we will have to check". The full account, with dates, block heights and the market reaction in the right order, is in our write-up of the 2026 shielded-pool vulnerability.
None of which tells you whether the asset belongs in your portfolio.
Is Zcash safe, and is it legal to hold?
For individuals, Zcash is legal to hold and trade in most countries, though the rules differ and change. The network has one documented protocol failure in its history, caught by an audit and fixed. Safe is doing a lot of work in that question, so split it into four risks that behave differently.
Protocol risk is the chance that the cryptography or the code has a flaw. The 2026 incident is the honest answer here: the risk is not theoretical. It has materialized once, and an audit found it before an attacker did. The counterweight is that the response was fast and documented in public, which is roughly the best behavior you can ask of a project in that situation.
Market risk is ordinary volatility, and ZEC has plenty. It is a smaller asset than Bitcoin and it trades thinner. It moves hard when confidence shifts. June 2026 is the clean example: ZEC roughly halved within about a week of the vulnerability becoming public, and the sharpest single day tracked a large holder exiting rather than the disclosure itself (source: BitMEX). Our page on what actually moves this asset breaks that pattern down.
Custody risk is about you rather than the network. If you hold your own keys and lose your backup, nobody can help you. Shielded funds add a practical wrinkle rather than a recovery one. Your seed phrase still restores the wallet. But the wallet also needs a rough date for when the account first received funds. Without it, the wallet has to scan far more of the chain, so a restore can take a long time. If you leave coins on an exchange, you are trusting that exchange. Our guides to holding your own keys and custody choices for investors cover the trade-off properly.
Availability risk is the one specific to privacy assets, and it is the one most people underestimate. Some venues do not list ZEC. Some list it but will only send withdrawals to transparent addresses, so you cannot withdraw straight into a shielded address and have to shield the funds yourself afterwards. Some have removed the asset entirely. That is a compliance decision by each venue, and it can change with little notice, which affects how easily you can exit a position.
On the legal side, the honest answer depends entirely on where you live, and it changes. In most jurisdictions holding and trading ZEC is legal for individuals, while the rules that bite hardest apply to the businesses that serve you rather than to you directly. Exchanges operate under identity and reporting requirements, and those are harder to satisfy for an asset that can hide transaction details, which is why venue availability varies so much. Several large venues accept ZEC deposits from both address types but send withdrawals only to transparent addresses, and others have removed the asset outright. Our page on venues that have delisted ZEC tracks that pattern. Our explainer on how privacy coins are regulated walks through the general pattern.
None of this is legal advice, and the position differs by country. Check your own jurisdiction rather than trusting a general article, including this one.
If you have weighed that and still want exposure, here is how people actually get it.
How to get exposure to ZEC
There are three practical ways to get exposure to ZEC. Buy it and withdraw it to a wallet you control. Buy it and leave it on the exchange. Or trade a derivative, such as a perpetual futures contract, without ever holding the coin. Only the first lets you use the privacy features.
The first is buying spot on an exchange and withdrawing to a wallet you control. This is the route to take if you want the asset itself or plan to use the shielded features. Our step-by-step guide to buying ZEC covers the procedure. It is also the only route that lets you actually use Zcash as Zcash rather than as a price exposure. The trade-off is that you take on custody responsibility.
The second is buying spot and leaving it on the exchange. Simpler, with no backup to lose and no shielding. You are trusting the venue, and you should understand that coins held by an exchange sit in transparent addresses under the exchange's control, so none of the privacy features apply to them.
The third is trading a derivative rather than owning the coin. On BloFin, ZEC/USDT spot has been live since August 29, 2024 for buying the coin itself (source: BloFin spot instruments endpoint), and ZECUSDT is a separate perpetual futures contract sized in contracts of 0.1 ZEC for leveraged price exposure, with leverage available up to 75x and funding settling every eight hours (source: BloFin instruments endpoint). That means you can take a position in either direction without ever holding ZEC, which suits shorter-horizon traders and is a genuinely different activity from owning the asset. If perpetuals are new to you, start with spot versus perpetual futures, because leverage magnifies losses as well as gains, and our page on trading ZEC on BloFin covers this contract in detail.
BloFin lists ZEC because there is real demand for it, and we would rather you size a position knowing how it behaves than find out on a bad day. It is not like trading a large-cap. ZEC is thin and confidence-driven, and June 2026 showed it can move by tens of percent in a single day when a technical story and a large holder's exit land together. On a leveraged contract, that combination is what liquidates people: the position size that feels comfortable in a quiet week is the one that removes you in a volatile one. Size for the news day, not the calm one.
Whichever route you take, treat ZEC as a position within a wider plan rather than as a standalone bet, and our guide to building a crypto portfolio is a reasonable starting point.
Before you do any of it, be clear about what Zcash is not.
When Zcash is the wrong tool
Zcash is not private by default, not impossible to trace, not the same thing as Monero, and not a way around reporting obligations. Those four beliefs are common, confidently stated and wrong. Each one costs the people who hold it something real. Getting them straight is probably the most valuable thing this guide can do.
It is not private by default. This is the big one, and it is worth repeating because it costs people real privacy. The protocol specification describes shielding as a per-transaction choice rather than a network-wide state (source: Zcash protocol specification). Buying ZEC and holding it does not make anything private. Withdrawing it to a wallet does not either. Privacy happens when you use shielded addresses, and if you never do, your Zcash activity is about as public as your Bitcoin activity.
It is not impossible to trace. The shielded side is strong, but the boundaries around it leak. Your exchange knows who you are. Your withdrawal is on the public ledger. Your network connection can expose where you are. Anyone describing the asset as impossible to trace is either simplifying badly or selling something, and treating that description as a guarantee is how people get into difficulty.
It is not Monero, and the difference is structural rather than cosmetic. Monero makes privacy mandatory for every transaction, so there is no transparent side and no choice to make. Zcash makes it optional, which gives you stronger cryptography when you use it and no protection at all when you do not. Neither approach is simply better, and they suit different priorities. We compare them properly in how Zcash compares with Monero, and if you are coming at this from the other direction, what Monero does differently is the place to start.
It is not a way around your obligations. Privacy technology has entirely legitimate uses, and most of this guide has described them: not publishing your salary, not exposing your suppliers, not broadcasting donations. It also attracts illegitimate use, and pretending otherwise would be dishonest. What is worth saying plainly is that using a privacy asset removes no reporting or tax obligation, and it makes nothing invisible to the venue you traded on. It is also not a defense if the underlying activity is unlawful. Confidentiality from the general public is not the same thing as invisibility to authorities, and the two get conflated constantly.
There is also a simpler version of when Zcash is the wrong tool. If you want privacy on every transaction without thinking about it, the opt-in model will eventually catch you out. If you want the deepest liquidity and the widest venue support, a privacy asset is structurally disadvantaged, because some venues will not list it. And if you specifically want an asset whose entire supply anyone can independently count, the 2026 episode showed that a shielded pool complicates that in a way a transparent chain does not.
If none of those describe you, and you want strong confidentiality that you control on a per-transaction basis, backed by cryptography with a long public research record, that is exactly what Zcash was built to be.
Frequently asked questions
What is the difference between Zcash and ZEC?
Zcash is the network, and ZEC is the coin that runs on it. It is the same relationship as Bitcoin the network and BTC the coin. In practice people use "Zcash" for both, and exchanges list the asset under the ticker ZEC. If you see a price quoted for Zcash, it is the price of one ZEC. The distinction matters in one place: the privacy features belong to the network, so what you can hide depends on which addresses your wallet uses, not on the coins themselves.
Is Zcash anonymous?
Not quite, and the distinction is worth holding onto. Shielded Zcash transactions are confidential, meaning the sender, the receiver and the amount are all hidden from the public ledger by cryptography. Anonymity is a broader claim about your identity never being connected to your activity, and that depends on things Zcash does not control, such as the exchange you bought from and how you connect to the network. Confidential is accurate. Anonymous overstates it.
Can anyone see my Zcash balance?
It depends which addresses hold it. Funds in a transparent address have a fully public balance that anyone with the address can look up, exactly as with Bitcoin. Funds in a shielded address do not: the balance is not visible on the ledger at all. If you want to show a specific person what you hold or what you received, Zcash supports viewing keys, which let you grant read access to someone such as an accountant without giving them the ability to spend.
Why do most people not use the shielded pools?
There is a second-order effect worth knowing beyond the exchange behavior described above, and it cuts against the intuition that more privacy is always better for you personally. Privacy tools work on the size of the crowd you hide in. When most of the supply stays transparent, that crowd is smaller. A smaller crowd gives an observer fewer options to weigh. So the usefulness of shielding to you depends partly on how many other people are doing it, which is why adoption is treated as a security property in Zcash rather than just a statistic.
Does Zcash have staking?
No, and the useful part of the answer is how to tell what a platform is actually selling you. The protocol pays no yield. So anything sold as Zcash staking is a product built on top of it. Usually your coins are lent out or used as collateral, and the return comes from a borrower rather than from the network. That means you are taking counterparty risk rather than protocol risk, and nothing in Zcash's design covers it. Ask who pays the yield and what happens if they cannot.
Researched and written by the BloFin Academy editorial team with AI-assisted drafting. Primary sources include the Zcash Improvement Proposals repository, Shielded Labs, Electric Coin Co., and the Zcash Community Forum. All facts independently verified against cited documentation current as of August 2026. Protocol claims were checked against the live chain as well as the specification, because the proposal repository can lag deployed upgrades. Zcash is changing quickly, so check the current network state before relying on any protocol detail here.
This article is for educational purposes only and is not financial advice. Cryptocurrency is volatile and you can lose money. Regulatory treatment of privacy assets differs by jurisdiction and changes over time, so check the rules that apply where you live. Do your own research before making any decision.
