Key Highlights
- Shielded Labs has launched Epoch, a research and engineering project focused on strengthening Zcash against quantum attacks and other advanced security threats.
- The initiative will develop production-ready post-quantum cryptography to replace quantum-vulnerable components and expand formal verification across critical cryptographic elements.
- Shielded Labs is targeting a production-ready implementation by the end of 2027, with at least 128 bits of security for confidentiality and soundness.
Shielded Labs, an independent, donation-funded Zcash support organization based in Switzerland, has announced Epoch, a research and engineering project focused on developing post-quantum cryptography and expanding formal verification for the Zcash protocol. The project aims to address potential risks from quantum computing, artificial intelligence-assisted analysis, and other advanced threats.
According to the official announcement, Epoch will develop production-ready cryptography intended to replace quantum-vulnerable components in Zcash. It will also apply formal verification to critical cryptographic elements of the protocol.
The work is designed to complement Project Tachyon and other post-quantum initiatives within the Zcash ecosystem. Shielded Labs stated it will coordinate with Daira-Emma Hopwood, Dev Ojha, Sean Bowe, Tal Derei, and the Project Tachyon team.
Project scope and timeline
The initial phase will survey existing research and evaluate candidate constructions against Zcash’s security and performance requirements. The first objective is to produce a concrete proposal for a post-quantum design. Shielded Labs is targeting a production-ready cryptographic implementation by the end of 2027 that could serve as the basis for a future protocol upgrade.
The target implementation is expected to provide at least 128 bits of security for confidentiality and soundness, rely on minimal and well-understood security assumptions, and incorporate formal verification. It is also intended to remain practical for the current Zcash protocol. Parallel work will examine requirements for meeting Project Tachyon’s performance goals. Some elements remain open research questions, and findings from research and benchmarks are to be shared as the project advances.
An interim measure is already in place. Since the NU6.3 network upgrade, Ironwood notes have been designed to be quantum-recoverable, allowing funds to be recovered through a future recovery protocol if the current elliptic-curve-based protocol must be disabled.
The announcement noted that formal verification is intended to provide higher assurance against design or implementation errors. It referenced the Sprout vulnerability identified in 2018 and the Orchard vulnerability identified in 2026 as prior examples of such issues.
Epoch’s Cryptography Team
A three-person cryptography team has joined Shielded Labs to lead the project.
Ulrich Haböck serves as chief cryptographer. He joins from StarkWare, where he worked as a cryptographer after earlier roles as an applied cryptographer at Polygon Labs. He is the author of the logUp lookup argument and a co-author of the Circle STARKs paper. He studied at the University of Vienna and is based in Europe.
Luke Edwards joins as a cryptography engineer. He previously served as technical lead on the cryptography engineering team at Aztec, where he worked on the protocol’s cryptographic systems. He holds a PhD in applied mathematics from the University of Arizona and a bachelor’s degree in mathematics from Penn State. He is based in the United States.
Suyash Bagad joins as a cryptography engineer. He previously worked at Aztec on the Barretenberg cryptography library and the PLONK family of proof systems. He holds bachelor’s and master’s degrees from the Indian Institute of Technology Bombay. He is based in Europe.
Related industry developments
In related post-quantum work, LayerZero introduced Akita, a polynomial commitment scheme, on September 9. The company described it as a production-ready primitive providing quantum-resistant security for zero-knowledge proving systems, with proof sizes two to eight times smaller than existing post-quantum alternatives. Its first major deployment is planned inside Jolt, the zero-knowledge proving system developed with a16z crypto.
The Ethereum Foundation’s Protocol cluster stated on September 7 that it is targeting December 2029 for Ethereum Layer 1 to become resistant to quantum attacks across its execution, consensus, and data layers. The timeline forms part of longer-term planning as work begins on the Hegotá upgrade.
Separately, the first quantum-safe Bitcoin transaction under the Quantum-Safe Bitcoin scheme was mined on the Bitcoin mainnet. StarkWare disclosed the milestone on August 26. The transaction used nonstandard script formats and was routed through MARA Slipstream.
Also Read: Circle Urges EU to Rework MiCA Stablecoin Reserve Requirements
