Zcash did not begin in 2016. It began in 1982, with a cryptographer who thought money should not report on its owner, and passed through every hand that tried to build it before the technology was ready.
Chapter 01
1982
David Chaum
The idea of untraceable money
Long before blockchains, cryptographer David Chaum published “Blind Signatures for Untraceable Payments” (1982): a bank could sign a digital coin without seeing it, so the coin could later be spent without the bank linking it back to you. Digital cash that behaved like cash.
Chaum founded DigiCash in 1989 to build it. Its eCash ran a real pilot at a US bank in 1995, but the company went bankrupt in 1998. The world was not ready, and the money still needed a bank at the center.
One detail matters for this story: in 1996 a computer science student named Zooko Wilcox took a leave of absence to work as a junior coder at DigiCash. The company failed; the apprenticeship did not.
Chapter 02
1992
Hughes, May, Gilmore and a mailing list
The cypherpunks
In 1992 a mailing list formed around a simple position: privacy in the electronic age would have to be built with code, not requested from institutions. Eric Hughes opened his 1993 manifesto with the line “Privacy is necessary for an open society in the electronic age.”
The list became the proving ground for everything that followed: remailers, digital cash schemes, and the culture of shipping working cryptography instead of position papers. Zooko Wilcox, who later brought Zcash to life, was posting to the list by 1997: an “original cypherpunk,” as Zcash’s own site puts it.
Chapter 03
1997–2004
Back, Dai, Szabo, Finney
The missing pieces
Adam Back’s Hashcash (1997) made computation itself a scarce stamp. Wei Dai’s b-money and Nick Szabo’s bit gold (late 1990s) sketched money without a central issuer. Each solved a piece; none shipped as money.
Hal Finney, veteran cypherpunk and PGP developer, also wrote working code for zero-knowledge proofs. At the rump session of the Crypto ’98 conference in Santa Barbara, on August 25, 1998, he gave a five-minute talk, “A zero-knowledge proof of possession of a pre-image of a SHA-1 hash”: a program that proves you know a message with a given SHA-1 hash without revealing the message, built on a proof system Ronald Cramer and Ivan Damgård presented at the same conference. It was a talk, not a paper, and the session was filmed.
Hal Finney at the Crypto ’98 rump session · 7:14. Santa Barbara, August 25, 1998. Filmed by Takeshi Shimoyama, edited by Kevin McCurley. Watch on YouTube ↗
In 2004 Finney built RPOW, reusable proofs of work: tokens minted from hashcash that could pass from person to person. The prototype ran on a central server and never took off. When Bitcoin appeared he was, by his own account, the first person besides its creator to run it, and he received the first Bitcoin transaction ever sent (January 12, 2009).
Finney died in 2014. The problem he spent decades on, private electronic cash that needs no permission, is the problem Zcash exists to finish.
The Bitcoin whitepaper (October 31, 2008) and genesis block (January 3, 2009) solved decentralized consensus. Money finally worked without a bank.
But it worked in public. Every amount, every counterparty, every balance, forever, on a ledger anyone can read. Bitcoin realized the cypherpunk dream of permissionless money while inverting its premise of privacy.
On January 26, 2009, eighteen days after Bitcoin’s first release, Zooko Wilcox wrote a short post on his own blog, Zooko’s Hack Log, about why digital cash had failed at DigiCash and where it might work next. It ends by pointing to bit gold, b-money and “BitCoin by Satoshi Nakamoto.” It is one of the earliest known blog posts to mention Bitcoin, and Zooko has called it the first. By March 2009, bitcoin.org listed “Zooko’s blog” among its related links, beside b-money and bit gold. The link led into Tahoe-LAFS, the decentralized storage system Zooko was building at allmydata: the blog lived on its test grid.
In August 2010 a BitcoinTalk thread asked whether Bitcoin could work without publishing every transaction, and another user suggested zero-knowledge proofs. Satoshi called the problem a very interesting one and said a solution would make a much better Bitcoin possible. He doubted the tool, though: to rule out a double-spend, a node seemed to need to know about every transaction.
“It's hard to think of how to apply zero-knowledge-proofs in this case.”
Two days later, in the same thread, he floated “key blinding”, a fresh, unlinkable key for every payment, and pointed to an unfinished draft on recipient-hiding encryption. He named no author. The draft is widely attributed to Daira-Emma Hopwood, writing under a former name. By then Hopwood was also a Tahoe-LAFS developer alongside Zooko, and in 2016 was the first-named author of the Zcash protocol specification.
On August 21 Tahoe-LAFS began accepting bitcoin donations, and Zooko, signing as the project’s community organizer, opened a thread about building Bitcoin payments into it. Satoshi’s reply left the proposal aside. It opened with Zooko’s name and thanked him, in public, for blogging about Bitcoin back when it was announced on the Cryptography mailing list. His last forum post came that December. In 2022 Zooko pointed back to the August thread: four months later Satoshi was gone, and three years after that, a solution was found.
Zerocoin (2013, Miers, Garman, Green and Rubin at Johns Hopkins) proposed a cryptographic washing machine bolted onto Bitcoin. Zerocash (2014, Ben-Sasson, Chiesa, Garman, Green, Miers, Tromer and Virza) went further: a full currency where sender, receiver and amount are hidden, yet every transaction is verified.
The tool that made it possible was the zk-SNARK, a succinct proof that a statement is true without revealing why. The proofs predate these papers; Zerocash was the moment they became a payment system on paper. It needed a team willing to make it real.
Six witnesses, air-gapped machines, one secret guest
The Ceremony
Zcash’s original proving system required secret parameters that, if any single party kept them, could be used to counterfeit coins invisibly. So on October 22 and 23, 2016 the launch team ran a multi-party ceremony: six witnesses in separate places, air-gapped hardware, destroyed key material. If even one of them was honest, the combined secret could never be rebuilt.
The stations were paranoia made real. Peter Todd ran his from a rented car on a drive through British Columbia, a trip he called the “Cypherpunk Desert Bus.” At the Denver station, a phone behaved strangely enough mid-ceremony that the moment became a Radiolab story. And one witness, known only as “John Dobbertin,” stayed pseudonymous for six years: in April 2022, Zcash Media revealed he was Edward Snowden.
On October 28, 2016 the genesis block was mined. That day, in a thin early market on the Poloniex exchange, one ZEC briefly reached roughly 3,300 BTC, and it still traded at 48 BTC later in the day, CoinDesk reported. The experiment was live.