Skip to content

protocol

Zakura rolls PIR into Vizor wallet, targets post-quantum opcodes for Zcash in January

Zcash node developer Zakura ships private information retrieval in Vizor this week and plans hash-based signature opcodes on transparent addresses for January.

by 5 min read

Zakura, the alternative Zcash full-node client, is this week shipping private information retrieval (PIR) inside the Vizor wallet, and has pinned a January target for the next step: new signature opcodes on transparent addresses backed by hash-based schemes that are not broken by future quantum attack or by elliptic-curve side-channel leakage, per Decrypt's write-up of the engineering post from Zakura's Roman Akhtariev.

What ships this week

Vizor users can toggle "private queries" in the wallet's settings. With it on, the wallet uses PIR to fetch balance data across many addresses without the server learning which addresses the wallet is interested in. The design, as described by Zakura and summarized in secondary coverage, splits confirmed transparent activity into block ranges, each served by a shard; the wallet hashes the address's payment script locally, which keeps the specific address off the request.

PIR is not shielding. The server still returns block-range answers; what it does not see is the mapping from a particular query to a particular address. The scheme matters for the transparent pool, where today's wallets routinely leak the full address graph to any lookup service. It does not change the shielded-pool semantics.

Zakura's path to the shipping release was staged. The team released Zakura Common on August 29, 2026, a set of libraries that wallets which adopt it inherit — a release ForkLog's August coverage described as cutting private-transaction preparation from more than three seconds to under 200ms in Vizor's case. The PIR feature rides on that library stack.

What is planned for January

The January work is the harder half: a set of signature opcodes on Zcash's transparent-address pool that let a transaction authorize spends with a hash-based signature rather than the current ECDSA-equivalent one. The scheme Zakura has pointed to is WOTS (a Winternitz one-time hash-based signature, read from context — the article does not expand the acronym) as the backup signature primitive, with address rotation moving the wallet to a fresh transparent address after each spend so no address reuses a public key.

Three things are not yet committed in Zakura's post:

  • Activation. No block height, no Network Upgrade name. The next scheduled Zcash upgrade is NU7, with 25-second blocks on the testnet in November 2026 and mainnet to follow — our coverage of the testnet target: Zcash NU7 testnet schedule. Whether the hash-based opcodes ride NU7 or land in a later NU8 is open.
  • The shielded side. The quantum/AI resistance work in this track is scoped to transparent payments. Shielded-pool spends through Orchard/Halo 2 are a separate problem that uses pairing-based cryptography; the hash-based opcode plan does not address them.
  • Multi-wallet support. Vizor is the only wallet named shipping PIR this week. Zashi, YWallet, Nighthawk and other Zcash wallets are not addressed in the Zakura post.

Why "AI and quantum"

The framing in Decrypt's headline conflates two different threat models that Zakura's work addresses separately:

  • Quantum. A sufficiently large fault-tolerant quantum computer breaks ECDSA and Schnorr signatures via Shor's algorithm; hash-based signatures survive, since their security reduces to the hash function's collision resistance. WOTS and SPHINCS+ are the two mature families; NIST standardized SPHINCS+ in FIPS 205 in August 2024.
  • AI-aided side-channel. The near-term concern is harder-to-quantify: machine-learning-assisted analysis of timing, power or electromagnetic traces during ECDSA key operations. Hash-based signatures narrow the attack surface because their internal state is simpler; address rotation further limits any one key's exposure.

Neither threat has produced a wallet-draining break of ECDSA to date. Zakura's bet is that the migration path is cheaper to build before an incident than after, and that transparent-address users — including exchanges, miners' payouts and bridges — are the first population a quantum break would touch.

Pattern

This is the second quantum-safety plan in the privacy-coin space to land as shipping code in six months. Monero merged its Carrot/Jamtis address refresh in September; Zcash now adds a transparent-side PQ opcode plan on top of its existing shielded roadmap, which already includes work on NU6-3 Ironwood and the NU6-2 emergency hard fork. The pattern across the two coins is the same: assume the quantum migration will take two or three network upgrades to execute, and start the opcode work before the signature standard is forced on the ecosystem.

What to watch

  1. The Zakura engineering post linked by Decrypt, for the opcode specification and the WOTS vs SPHINCS+ decision. A pointer to a Zcash Improvement Proposal (ZIP) draft is the signal that this is tracking the formal upgrade process.
  2. ECC's and Zcash Community Grants' response on whether the hash-based opcode goes into NU7 or a later NU. ECC drives the reference client (zcashd/zebra); without its sign-off, the opcode cannot activate on consensus.
  3. The PIR-only tradeoff. The shard servers can still correlate a wallet's query batches over time. Zakura has not disclosed how it mitigates batch-correlation; the primary-source engineering post is where that detail should be.
  4. Vizor adoption. PIR is on by toggle, not by default. If uptake stays low, the server-side query graph remains the full address graph.

Related stories