Zcash developers have started moving Project Tachyon’s recursive-proof cryptography into the production stack that already builds and checks shielded transactions.
On September 28, Project Tachyon lead Sean Bowe said the team is upstreaming Tachyon’s recursive proofs into Zakura Common, the shared cryptography libraries used by the Zakura full node and other Zcash software. The first delivery is Udon (zakura-udon), a Rust crate that replaces Common’s pasta_curves fork and much of the arithmetic inside Halo 2, the prover used by Ironwood.
The change is a software integration, not a consensus upgrade. Udon is available for developers. Tachyon itself remains a proposed protocol and would still need community review, ZIP work, and mainnet activation before it could alter how the live chain verifies private payments.
Udon unifies Pasta arithmetic for Ironwood and Tachyon
Zakura and Tachyon already share the Pasta elliptic curve cycle that Zcash chose for Halo 2 and later reused in Ironwood. Bowe wrote that Tachyon’s proofs would otherwise be more expensive, use more memory, and produce larger binaries. Because Tachyon reuses much of Ironwood’s cryptography, Common’s optimized kernels can absorb part of that cost.
Tachyon also extends the same stack: it needs longer generator vectors for vector commitments, proving over both curves in the cycle, and a slightly different Poseidon parameterization.
Udon is meant to stop those extras from living behind compatibility shims. The crate owns field and curve arithmetic previously split between pasta_curves and halo2_proofs, and it is specialized to Pallas and Vesta. Bowe said that collapse lets Pasta-specific optimizations become ordinary calls instead of extension traits, hidden bridges, or runtime type checks. Udon also leaves buffer ownership and parallelism with the caller, stays no_std at runtime, and ships a companion crate, Bento, for embedding prepared tables without a second allocation pass.
That work sits on a stack already in production. Zakura Common was released in late August and reported mobile proof generation more than 14 times faster, with many proofs falling under 200 milliseconds.
Zakura 1.4.0 later put iPhone 17 proving at 21 times faster than the pre-Zakura baseline. Zakura 1.5.0, shipped September 24, moved Common to 2.0.0 and cut block-commit latency for miners. Separately, Zakura published a Lean analysis of zero knowledge for the optimized Ironwood prover, arguing that speedups must preserve the privacy property separately from soundness.
Recursive proofs still need protocol work after the merge
Udon does not turn on Tachyon’s scaling design. The protocol’s public overview describes proof-carrying data that would let block producers aggregate shielded transactions and shrink the state validators keep. The team’s longer target remains payments at the scale of tens of thousands of transactions per second; Zakura’s repository still frames that as roughly 50,000 TPS, versus today’s far lower chain throughput.
A September 29 Tachyon post, titled ‘Building Tachyon’s Proof Tree with Shared Evidence,’ added another piece of that design. Instead of forcing validators to retain every historical nullifier, Tachyon would split history into epochs and reuse authenticated epoch data for bounded non-membership checks. Wallets would bind those results to a note. That post landed one day after the Udon release, underscoring that the merge is one track among several still under construction, including the Ragu recursive toolkit.
The timing also follows the summer Ironwood transition. After an Orchard soundness flaw, NU6.3 created a new shielded pool and required funds to exit the legacy pool through a turnstile. Tachyon later said formal verification of Ironwood supply soundness had been completed. Udon now tries to put the next proving layer on that same Common base rather than a separate experimental tree.
For users, nothing changes on-chain today. Wallets and nodes can adopt faster Common libraries without a fork. Tachyon activation would be a later consensus decision. Until then, Udon is best read as plumbing: it places recursive-proof arithmetic next to the Ironwood code that privacy-focused Zcash payments already use, so later protocol work does not have to re-optimize the same Pasta kernels in two places.
Also read: Aave Proposes Monad V4 Hub for Tokenized Equity Lending
