Zcash grew from academic attempts to add privacy to Bitcoin into an independent network built around zero-knowledge proofs. Its history is not one launch event: Sprout proved the idea, Sapling made shielded use practical, NU5 introduced Orchard and Halo 2, and later upgrades changed funding, node operations, and security response.
Key Facts
- Zerocoin research began as a proposal for adding privacy to Bitcoin before the work evolved into Zerocash.
- Electric Coin Company was formed in 2015 and Zcash launched in October 2016.
- Sapling activated at block 419,200 on October 29, 2018.
- NU5 activated at block 1,687,104 on May 31, 2022 and introduced Orchard, Unified Addresses, and Halo 2.
- NU6.2 activated at block 3,364,600 in 2026 after a temporary Orchard vulnerability mitigation.
The story starts with a missing property in Bitcoin
Bitcoin showed that strangers could agree on digital money without a central operator, but its transaction ledger was public by design. In 2013, researchers proposed Zerocoin as a privacy extension that could let users break visible transaction links. The work then expanded into Zerocash, a more ambitious protocol using succinct zero-knowledge proofs to hide payment relationships and values while preserving public verification.
The research team included cryptographers and computer scientists from institutions including Johns Hopkins, MIT, Tel Aviv University, and the Technion. What began as an add-on concept became a standalone system because integrating the full privacy design into Bitcoin would have required deeper consensus changes than a normal application layer could provide.
Zcash launched in 2016 with Sprout
The Zerocoin Electric Coin Company, now Electric Coin Company, was formed in 2015 to turn the research into working software. Zcash mainnet launched in October 2016. Its first shielded protocol is now called Sprout. Sprout demonstrated that a public proof-of-work network could verify encrypted payments using zk-SNARKs, but generating those proofs required substantial time and memory.
Sprout also depended on public parameters created through a multi-party ceremony. The ceremony was designed so that the system remained sound if at least one participant destroyed its secret contribution. This was a serious and carefully engineered answer to the trusted-setup problem, but it also made the cost of upgrading the shielded circuit obvious.
Overwinter and Sapling turned launch software into an upgradeable protocol
Overwinter activated in 2018 and established machinery for safer network upgrades, including transaction versioning and replay protection. Sapling followed at block 419,200 on October 29, 2018. Sapling radically reduced the memory and time needed to construct shielded payments, introduced improved key separation, and made full viewing keys practical for observing incoming and outgoing activity without exposing spending authority.
That shift mattered more than a benchmark. Privacy that only works on powerful desktops cannot become an ordinary payment option. Sapling opened the door to mobile wallets, exchange integration, and delegated proof construction. It also created a new shielded pool, so users and wallets had to migrate value from Sprout rather than pretending all shielded history belonged to one anonymity set.
Blossom, Heartwood, and Canopy changed speed, mining, and funding
The next upgrades did not replace the shielded protocol, but they changed the environment around it. Blossom shortened the block target spacing from 150 seconds to 75 seconds while preserving the intended issuance rate. Heartwood enabled shielded coinbase and added FlyClient-related consensus support. Canopy removed the Founders' Reward, activated a new development-fund structure, and coincided with Zcash's first halving.
These upgrades show why Zcash history cannot be reduced to cryptography alone. Block production, node compatibility, funding, wallet behavior, and governance all shape whether the privacy protocol remains usable and maintained. Zcash Improvement Proposals document those changes and the arguments around them.
NU5 introduced Orchard and removed the new-pool trusted setup
Network Upgrade 5 activated at block 1,687,104 on May 31, 2022. It introduced the Orchard shielded protocol, version 5 transactions, Unified Addresses, and the Halo 2 proving system. Orchard did not require a new protocol-specific trusted setup ceremony. Its action model also improved transaction-shape hiding compared with reading a separate proof count for each real Sapling spend and output.
Unified Addresses were the user-facing partner to that cryptographic change. They let a wallet present one container with compatible receiver types and choose the best path it understands. NU5 therefore connected protocol evolution to usability: users did not need to learn a new standalone Orchard address prefix to receive into the new pool.
NU6, NU6.1, and NU6.2 moved funding and security response forward
NU6 activated at the second halving in 2024 and introduced a deferred development-fund chain value pool. NU6.1 activated at block 3,146,400 in November 2025 and extended a model in which 8% of subsidy supports Zcash Community Grants while 12% supports a coinholder-controlled fund. These rules are part of consensus economics, not an off-chain donation program.
In 2026, an Orchard vulnerability response temporarily disabled Orchard transaction support before NU6.2 activated at block 3,364,600 with a corrected circuit and re-enabled the pool. ZIP 257 records the response and activation. The episode is uncomfortable but important history: mature privacy infrastructure is measured partly by how clearly it can contain, disclose, repair, and document protocol risk.
The current transition is about implementation as much as cryptography
Zcash now has multiple consensus implementations and a visible transition away from zcashd for future major upgrades. Zebra is the maintained independent full-node path for upcoming consensus work, while wallet infrastructure continues to move toward newer components. At the protocol layer, Ironwood and version 6 transaction proposals define possible next changes, but draft status must not be confused with activated consensus.
The durable pattern is experimentation followed by explicit migration: Sprout to Sapling, Sapling to Orchard, ceremony-based proofs to Halo 2, direct funding to lockbox and coinholder mechanisms, and legacy node infrastructure toward Zebra. The useful way to read Zcash history is not as a sequence of brand announcements. It is a record of what the network learned, replaced, and kept compatible.
FAQ
When did Zcash launch?
Zcash mainnet launched in October 2016 after the Zerocoin and Zerocash research programs evolved into a standalone protocol.
Who created Zcash?
Zcash emerged from a group of academic cryptographers and engineers and was brought to market by Electric Coin Company with Zooko Wilcox. The protocol has since involved multiple organizations and independent contributors.
What was the biggest Zcash upgrade?
There is no objective single winner. Sapling made shielded transactions practical, while NU5 introduced Orchard, Unified Addresses, version 5 transactions, and Halo 2 without a new pool-specific trusted setup.
Is Sprout still the main Zcash privacy pool?
No. Sprout is the original legacy pool. Sapling and especially Orchard are the relevant modern shielded protocols, with separate pools and migration considerations.