Zcash changes through network upgrades — coordinated updates to the rules every node agrees on. Each one switches on at an exact block height (ZIP 200), the same number on every machine, so the calendar date beside it is simply when that block happened to be mined. The history below is built from primary sources — the official upgrade pages, the Zcash Improvement Proposals (ZIPs) that specify each change, and the teams that built them — rather than second-hand summaries, because the dates in particular are easy to get wrong.
2014 — the idea: the Zerocash paper. Zcash began as research. A group of cryptographers published Zerocash: Decentralized Anonymous Payments from Bitcoin, showing how zero-knowledge proofs could let a blockchain confirm a payment while hiding its sender, recipient, and amount. To turn the paper into a usable currency, the Zerocoin Electric Coin Company — now the Electric Coin Company (ECC) — was founded in 2015 by Zooko Wilcox and spent the next year building the protocol toward launch. The paper · who created Zcash · Zooko Wilcox, ECC's founder.
October 28, 2016 — Zcash launches. The network went live, bringing the Sprout shielded pool online and making Zcash the first widespread application of zk-SNARKs. Because those early proofs needed a trusted setup, the launch was preceded by an elaborate multi-party ceremony to generate the system's secret parameters and then destroy the dangerous leftovers (the "toxic waste") — safe as long as even one participant erased their piece. Years later, in 2022, one of the participants was revealed to be the whistleblower Edward Snowden, who had taken part anonymously as "John Dobbertin." The launch · the ceremony · zk-SNARKs · Snowden, a ceremony participant · his identity revealed (2022).
February 14, 2017 — the Zcash Foundation is established. So that no single for-profit company would hold permanent power over the protocol, the Zcash Foundation was incorporated in Delaware as an independent non-profit body (later granted 501(c)(3) public-charity status) devoted to Zcash and to financial privacy as a public good. This began the two-organisation structure — the Electric Coin Company and the Foundation — that shapes Zcash's governance and the funding debates of later upgrades. The Foundation's first announcement · its mission · 501(c)(3) granted · ECC's announcement.
June 26, 2018 — Overwinter (block 347,500). The first network upgrade. Overwinter left privacy untouched and instead hardened the plumbing — adding transaction versioning and replay protection — so that every later upgrade could be rolled out cleanly and safely. It was the dress rehearsal that made the rest possible. Read more.
October 29, 2018 — Sapling (block 419,200). The leap that made privacy practical. Sapling introduced a far more efficient shielded pool: shielded transactions that once took minutes and gigabytes of memory now took seconds and could run on a phone, moving to the Groth16 proving system on a new elliptic curve. Sapling also quietly carried the fix for a serious flaw in the original system (next entry). Read more · Sprout's hardware cost · Groth16 · the BLS12-381 curve.
February 5, 2019 — a counterfeiting flaw is disclosed (already fixed). In March 2018, ECC cryptographer Ariel Gabizon found a subtle flaw in BCTV14, the proof construction behind the original Sprout pool, that could have allowed someone to mint undetectable counterfeit shielded ZEC. The fix was deployed silently — folded into the Sapling upgrade — before the flaw was disclosed publicly in February 2019 (CVE-2019-7167). No evidence was found that it was ever exploited, and Zcash's turnstile rule — a pool can never pay out more than was put into it — caps how much damage any such bug could do. ECC disclosure · Foundation's account · the turnstile rule (ZIP 209).
December 11, 2019 — Blossom (block 653,600). Blossom halved the target time between blocks, from 150 seconds to 75, roughly doubling transaction throughput and making confirmations feel quicker — without changing any privacy guarantee. Read more · block timing (ZIP 208).
July 16, 2020 — Heartwood (block 903,000). Heartwood let mining rewards be paid directly to shielded addresses ("shielded coinbase") — until then, freshly mined coins had to begin in the open — and added support for lighter-weight ways to verify the chain, pushing privacy further toward the base of the system. Read more · shielded coinbase (ZIP 213).
November 18, 2020 — Canopy (block 1,046,400): the first halving. Canopy coincided with Zcash's first halving — the roughly-four-yearly cut, inherited from Bitcoin's design, that halves the block reward and steadily slows the creation of new ZEC. It also retired the original Founders' Reward and replaced it with a Dev Fund (ZIP 1014) directing a share of the reward to ongoing development. Read more · the halving model (ZIP 234) · the Dev Fund (ZIP 1014).
May 31, 2022 — NU5 (block 1,687,104): Orchard, Halo 2, and the end of trusted setup. The most far-reaching upgrade. NU5 introduced Orchard, the shielded pool built on the Halo 2 proving system — which needs no trusted setup at all, removing the toxic-waste risk that the 2016 ceremony existed to manage. It also added Unified Addresses: a single address format that bundles your different address types into one string and doesn't reveal, on its face, which ones it contains. Read more · Explaining Halo 2 · Orchard uses Halo 2 (ZIP 224) · Unified Addresses (ZIP 316).
November 23, 2024 — NU6 (block 2,726,400): the second halving. NU6 coincided with the November 2024 halving — the network's second — again cutting the rate of new supply, and it restructured how development is funded after the first Dev Fund's term, including setting aside part of the reward in a protocol "lockbox" for the community to allocate later. Read more · the first halving (Canopy) · the lockbox (ZIP 1015).
December 2024 — shielded ZEC reaches hardware wallets. Privacy also has to be practical to use. In December 2024, Keystone — paired with the Zashi wallet — brought native shielded-ZEC support to a hardware wallet, so shielded funds can be held in cold storage. More recently, services built on Maya Protocol and NEAR Intents (via SwapKit) offer swaps into and out of ZEC across other chains. One caveat rides along with that reach: value is only protected while it stays shielded — the instant it crosses to a transparent chain, the other side of the trade is visible by design. Keystone integration · cross-chain swaps.
November 24, 2025 — NU6.1 (block 3,146,400). A smaller upgrade focused on funding governance: it put a community funding model (ZIP 1016) in place, sending 8% of the block reward to community grants (ZCG) and directing 12% into a fund controlled by coinholder decisions, in effect until the third halving. Read more.
March 2026 — a node bug in the old Sprout pool. Stepped-up security research surfaced
a bug — this time not in Zcash's cryptography but in the zcashd node software, where
under a specific condition a node could skip fully verifying Sprout proofs. It touched
only the long-deprecated Sprout pool (about 25,424 ZEC), was patched within days —
deployed by mining pools, then released as zcashd v6.12.0 — and the turnstile again
meant the total ZEC supply could not be
inflated. No exploitation was found.
Read more.
June 3, 2026 — NU6.2 (block 3,364,600): fixing the Orchard counterfeiting bug. The most serious incident in Zcash's history, and a near-miss. In a targeted, AI-assisted review of the Orchard circuit — using Anthropic's Opus 4.8 model — security researcher Taylor Hornby, working with Shielded Labs, found a soundness bug present since Orchard launched in 2022: an under-constrained part of the circuit that could have been used to create unlimited, undetectable counterfeit ZEC in the Orchard pool. It was discovered on May 29, 2026 and immediately disclosed to ZODL engineers; an emergency soft fork disabled Orchard on June 2, and the NU6.2 upgrade re-enabled it the next day with a corrected circuit. Because of Orchard's privacy, no one can cryptographically prove the bug was never exploited — though the teams involved judge that unlikely. Foundation: NU6.2 activation · Shielded Labs: the vulnerability.
Beyond the upgrades that have shipped, several efforts are in development. None of these is live; each would need community support and the standard governance process before it could activate.
zcashd's end of support.
Read more.The same period brought organisational upheaval. After a governance dispute with Bootstrap (the non-profit that oversees the Electric Coin Company), the entire ECC team departed in January 2026 and formed the Zcash Open Development Lab (ZODL), which raised more than $25 million in seed funding and is rebranding Zashi — the wallet its team originally built at ECC — to Zodl. ECC team leaves ECC · ZODL's $25M seed round · Zashi becomes Zodl.