+34 641 10 27 16

Zcash (ZEC): a complete guide to the coin, its network and its mining

Coin encyclopedia

Zcash (ZEC): Equihash 200,9, shielded pools and the move to Ironwood

A look at the network after the upgrade of 28 July 2026: the new Ironwood shielded pool, Orchard left on exit only, a fleet of six Equihash ASIC and an honest electricity break even.

Equihash 200,9Block 75 secondsCap 21 million ZEC80 percent to miner

About the coin

Zcash is a proof of work cryptocurrency with optional privacy. The main network launched on 28 October 2016 and the genesis block was mined the same day. The project grew out of the Zerocash academic paper of 2014, written by researchers from Johns Hopkins University, the Technion, MIT and Tel Aviv University. The code base is a fork of Bitcoin Core, so the UTXO model, the scripts and the transparent addresses look familiar at first glance.

The public face of the project became Zooko Wilcox (Zooko Wilcox-O'Hearn), who founded the Zerocoin Electric Coin Company, known today as Electric Coin Company (ECC). A multipolar structure has grown around the protocol: ECC, the independent Zcash Foundation, the Shielded Labs team, the Zcash Community Grants committee, and since January 2026 the ZODL developer group that split away from ECC. The network has no single decision making centre, and changes go through the ZIP proposal process.

The point of Zcash is that privacy is chosen rather than imposed. Coins can sit on transparent addresses, where everything is as visible as in Bitcoin, or they can be moved into a shielded pool that hides the sender, the recipient and the amount. The cryptographic foundation is zero knowledge proofs, first zk-SNARK and, since 2022, the Halo 2 system, which needs no trusted setup at all.

The coin is mined and will stay mined: the network remains on proof of work, the algorithm is Equihash with parameters 200 and 9, the target block time is 75 seconds and the supply cap is 21 million ZEC. Roughly 80 percent of the block reward goes to the miner and the rest to the development fund. Hardware for this algorithm was built by Bitmain and Innosilicon, and no new model has appeared since 2023.

Coin card

ParameterValue
NameZcash, ticker ZEC
Network launch28 October 2016
FounderZooko Wilcox (Zooko Wilcox-O'Hearn), Electric Coin Company
Scientific basisThe Zerocash protocol, a 2014 paper by six authors from four universities
Code originA fork of the Bitcoin Core code base, UTXO model
AlgorithmEquihash with parameters n equal to 200 and k equal to 9, written as Equihash 200,9
ConsensusProof-of-Work, no masternodes and no staking
Target block time75 seconds, since the Blossom upgrade in December 2019
Maximum supply21,000,000 ZEC, the same as Bitcoin
Block reward1.5625 ZEC after the second halving on 23 November 2024
Reward splitAbout 80 percent to the miner, 12 percent to the Lockbox, 8 percent to grants
Next halvingExpected around November 2028, the reward drops to 0.78125 ZEC
PrivacyOptional: transparent t-addresses and shielded z-addresses, plus Unified Addresses
Current shielded poolIronwood, activated on 28 July 2026 by the Ironwood upgrade
The former Orchard poolExit only since 28 July 2026, funds leave through the turnstile
Custom firmwareNone released for Equihash ASIC, the machines run factory software

Project history

  • 2014The Zerocash paper is published, describing how to build fully anonymous payments on top of the Bitcoin model using zero knowledge proofs. It became the technical foundation of the future network.
  • 2016The main network launches on 28 October. A trusted setup ceremony runs at the same time: several participants generate the shared zk-SNARK parameters in fragments and destroy their pieces of the secret. The block reward is 12.5 ZEC, of which 20 percent went to the founders under the Founders Reward scheme.
  • 2018The first ASIC for Equihash 200,9 reach the market in the spring: the Innosilicon A9 series first, then the Bitmain Antminer Z9. Graphics cards lose their economic sense within months and the community splits between supporters of an algorithm change and supporters of compatibility. The algorithm was kept.
  • 2018The Overwinter upgrade in June and Sapling in October. Sapling introduced a new shielded pool, cut the memory needed to build a proof from gigabytes to tens of megabytes and made operations several times faster. A second, much larger trusted setup ceremony was run for Sapling.
  • 2019The Blossom upgrade, 11 December. The target block time was cut from 150 to 75 seconds and the halving interval was raised to 1,680,000 blocks so that the four year cycle stayed intact.
  • 2020The Heartwood upgrade, 16 July. Shielded Coinbase arrived: a miner could now send the reward straight to a shielded address without passing through a transparent one.
  • 2020The first halving and the Canopy upgrade, 18 November. The block reward fell to 3.125 ZEC, the Founders Reward programme ended and a four year Dev Fund took its place: 20 percent of the subsidy was split between ECC, the Zcash Foundation and the grants committee.
  • 2022The NU5 upgrade, 31 May. The Halo Arc package and the Orchard shielded pool arrived, built on the Halo 2 proof system, which needs no trusted setup at all. Unified Addresses appeared at the same time, one address for several pools.
  • 2024The second halving and the NU6 upgrade, 23 November. The block reward fell to 1.5625 ZEC. Direct funding of ECC and the Zcash Foundation from the block ended: 12 percent of the subsidy now accumulates in the deferred Lockbox fund, 8 percent goes to grants and the rest to miners.
  • 2025The NU6.1 upgrade at block 3,146,400 on 24 November. Under the ZIP 271 specification the 12 percent Lockbox stream was extended by 1,260,000 blocks, to block 4,406,400, and a one time payment of 78,750 ZEC was made to a 2 of 3 multisig address controlled by the Zcash Foundation, ECC and Shielded Labs.
  • 2026February. The team that built the Zashi wallet leaves ECC and forms the independent ZODL organisation. On 16 February the wallet was renamed from Zashi to Zodl, the update applies automatically and user keys and history are untouched.
  • 2026May. On 29 May the researcher Taylor Hornby, working with Shielded Labs, finds a flaw in the proof circuit of the Orchard pool. The base point in the scalar multiplication chain was not pinned down: an assignment was used instead of a copy constraint, so a proof was accepted even with a substituted base point. By the BlockSec analysis this opened a path to double spending inside the pool. The flaw had existed since Orchard was activated in 2022, and no confirmed exploitation has been recorded.
  • 2026June. On 2 June, at block 3,363,426, an emergency soft fork was activated (the Zebra 4.5.3 release) that temporarily banned blocks and transactions with Orchard. On 3 June, at block 3,364,600, the NU6.2 upgrade was activated (Zebra 5.0.0) with a corrected circuit and a new consensus rule that rejects Orchard bundles with a non canonical proof size. Public disclosure followed on 4 June and the ZEC price dropped sharply on the news.
  • 2026July. On 28 July the Ironwood upgrade activated at block 3,428,143. It introduced a new formally verified shielded pool, Ironwood, starting from zero. The Orchard pool moved to exit only mode: you can leave it but not enter it, and the turnstile caps total withdrawals at the volume of provably deposited funds. That makes total issuance independently auditable.

How the network works

Zcash runs on the usual Bitcoin model of unspent outputs. A wallet signs a transaction, nodes verify it and pass it on, miners pack transactions into a block and iterate over the header until they find a solution that satisfies the current difficulty. Whoever finds it takes the block subsidy plus the fees. There is no second layer, no collateral and no voting by hardware in this network.

The difference starts where a transaction goes into a shielded pool. Instead of open inputs and outputs, the block carries a cryptographic proof that the sender owned the coins and is not spending them twice, while the amounts and the addresses stay encrypted. A validating node is convinced the transfer is correct without knowing its content. Correctness rests on the proof circuit, and a flaw in exactly such a circuit caused the emergency upgrades of summer 2026.

Shielded funds are tracked through a turnstile. At the consensus level the network counts how much ZEC entered each pool and how much left it, and it never allows more to leave than went in. The mechanism is built so that even a coin theoretically forged inside a pool could not reach the transparent part of the chain and break the cap of 21 million. After the Ironwood upgrade the turnstile on the Orchard boundary became the key tool for auditing issuance.

The network has had several pools: Sprout (2016), Sapling (2018), Orchard (2022) and Ironwood (2026). Every new pool is a separate proof circuit and a separate set of notes. Funds do not migrate automatically, the owner moves them, and older pools are gradually switched to exit only mode.

  1. 1. Building the transactionThe wallet decides which inputs to use, transparent or shielded. For the shielded part it builds a zero knowledge proof locally, on the user device. Secret keys never leave it.
  2. 2. Verification by nodesA node checks the signatures of the transparent part and mathematically verifies the proof of the shielded part. Verification takes milliseconds and does not require knowing the amounts. Nullifiers are checked at the same time, the markers that stop the same note from being spent twice.
  3. 3. Block assemblyA pool or a solo miner builds the block, including transactions and the coinbase payout. The coinbase must match the current shares: to the miner, to the Lockbox and to grants. A wrong split makes the block invalid.
  4. 4. The Equihash searchThe ASIC looks for a solution to the collision problem with parameters n equal to 200 and k equal to 9. A solution is called a Sol, and performance is measured in Sol/s rather than hashes per second. Every solution found is then checked against the current difficulty target.
  5. 5. Publication and confirmationThe block found spreads across the network and nodes verify it in full, including every proof inside it. The recipient treats funds as final after the required number of confirmations, and exchanges usually ask for 12 to 24.
  6. 6. Difficulty retargetDifficulty is recalculated every block from a moving average of recent blocks, using an algorithm of the DigiShield family. A sudden arrival or departure of hashrate is smoothed out over hours rather than weeks, so the network never stalls for long.
  7. 7. Pool accounting and the turnstileIn parallel, consensus keeps the balance of every shielded pool. Withdrawals are capped by deposits, and after Ironwood the entry into Orchard is closed completely, only the exit is open.

Mining algorithm

Equihash is a proof of work algorithm proposed by Alex Biryukov and Dmitry Khovratovich in 2016. It builds on the generalised birthday problem: you have to find a set of indices whose values sum to zero. The problem is shaped so that a fast solution needs a lot of memory, which means the algorithm was designed to be memory-hard and to keep the advantage of specialised hardware over ordinary hardware moderate.

The point people get wrong most often: Equihash is not one algorithm but a family. The n and k parameters set the size of the problem and the depth of the merge tree, and they are not a miner or pool setting. Each n and k pair is in effect its own problem with its own memory footprint and its own internal structure. Zcash uses the pair 200 and 9, where a solution needs on the order of 144 megabytes of memory. Other variants exist, 144,5, 192,7, 210,9 and 125,4, each used by other coins.

That leads to a practical conclusion for a hardware buyer. A machine built for Equihash 200,9 physically cannot compute 144,5 or 125,4: its memory volume and memory topology are baked into the silicon. The Antminer Z15 Pro does not switch to Flux, and a 144,5 miner does not switch to Zcash, no matter how many firmware builds and settings you go through. Check compatibility with a coin by the parameter pair, not by the word Equihash in a product description.

The idea of resistance to specialised hardware worked out only in part. For the first two years the network ran on graphics cards, but in the spring of 2018 ASIC from Innosilicon and Bitmain arrived, and the performance gap grew so wide that GPU mining on 200,9 died in a single season. The community discussed changing the algorithm to bring graphics cards back, but no decision was taken, and the network still runs on the original parameter pair.

The strength of the algorithm is that a solution is verified instantly and cheaply, while the memory in its design limits how dense the chips can get. The weakness is that the hardware market for 200,9 is effectively frozen: the last model came out in 2023, there is no competition between manufacturers and efficiency has not moved since. For a miner that means the whole calculation revolves around the coin price and the electricity tariff, not around a choice between hardware generations.

Full description of the Equihash 200,9 algorithm →

Economics and issuance

The supply cap of Zcash is 21,000,000 ZEC, exactly as in Bitcoin, and the halving also comes roughly every four years. After the block time was cut to 75 seconds the halving interval was raised to 1,680,000 blocks so that the calendar rhythm stayed the same. The network produces about 1,152 blocks per day.

Halvings: the first came on 18 November 2020 and cut the reward to 3.125 ZEC, the second came on 23 November 2024 and lowered it to 1.5625 ZEC. The third is expected around November 2028 and will take the reward to 0.78125 ZEC. Annual inflation under the current parameters is on the order of 4 percent and keeps falling.

The funding scheme for development has changed three times. From 2016 to 2020 the Founders Reward was in force: 20 percent of the subsidy went to the founders and early investors. From the Canopy upgrade in November 2020 a four year Dev Fund took over, with the same 20 percent split between ECC, the Zcash Foundation and the grants committee. Since the NU6 upgrade in November 2024 direct payments to companies have stopped: 12 percent of the subsidy accumulates in the deferred Lockbox fund, 8 percent goes to grants and about 80 percent stays with the miner.

The current version is fixed by the ZIP 271 specification and was activated by the NU6.1 upgrade on 24 November 2025 at block 3,146,400. The Lockbox stream was extended by 1,260,000 blocks, to block 4,406,400, which coincides with the third halving. At the same time a one off payment of 78,750 ZEC went to a 2 of 3 multisig address jointly controlled by the Zcash Foundation, ECC and Shielded Labs. The idea behind the design is that funds accumulate at the protocol level while the decision to spend them is taken separately and later.

There is no coin burning in Zcash and fees go entirely to the miner. Fees are low and barely affect miner income: the block subsidy makes up most of the revenue. That is an important difference from networks where a fee stream noticeably softens the effect of a halving.

Network parameters

ParameterValue
Network typeA public UTXO blockchain, a fork of the Bitcoin Core code base
ConsensusProof-of-Work on Equihash 200,9, no masternodes and no staking
Target block time75 seconds, since the Blossom upgrade on 11 December 2019
Difficulty retargetEvery block, from a moving average, an algorithm of the DigiShield family
Block size2 MB, a theoretical ceiling of about 25 to 30 transactions per second
Actual loadAbout 4,000 transactions per day, per the ZecHub digest for the week to 26 July 2026
ConfirmationsExchanges usually ask for 12 to 24, that is roughly 15 to 30 minutes
Coinbase maturity100 blocks, the block reward is unspendable for about two hours
Transparent addressesStart with t1 and t3, they work and read like Bitcoin addresses
Shielded addressesThe Sprout, Sapling, Orchard and Ironwood pools, Sapling uses the zs prefix
Unified AddressesThe u1 prefix, one address covers several pools and the wallet picks
Memo fieldUp to 512 bytes of encrypted text inside a shielded transaction
Viewing keysViewing keys give read access to the history without the right to spend
Node clientsZebra, Zakura, Zallet. The older zcashd is officially retired

Which ASICs work

The catalogue holds six models for Equihash 200,9 from two manufacturers, all of them released between 2018 and 2023, and no new machine has appeared on the algorithm since.

ModelHashratePower drawEfficiency
Antminer Z15 Pro 840 kSol/s2650 W3.155 J/kSol
Antminer Z15 420 kSol/s1510 W3.595 J/kSol
Antminer Z11 135 kSol/s1418 W10.504 J/kSol
Innosilicon A9++ ZMaster 140 kSol/s1550 W11.071 J/kSol
Innosilicon A9 ZMaster 50 kSol/s620 W12.4 J/kSol
Innosilicon A9+ ZMaster 120 kSol/s1550 W12.917 J/kSol

Browse miners in the catalogue →

Best machines for this coin

The ranking is built on efficiency in joules per kilosol, that is on real economics rather than on the popularity of a model or its release year.

Pros. The best efficiency on the algorithm and the only machine worth building a calculation around today: 840 kSol/s at 2,650 W, which is 3.155 J/kSol. It leads third place in the catalogue by more than three times.

Cons. A full size industrial machine: noise of about 75 decibels and almost 2.7 kW per unit. Released in 2023 with no successor, so the fleet will age without replacement. No third party firmware exists for it.

Best suited for. A site on an industrial tariff, or a private miner with a separate non residential room and a three phase supply.

Payback. By the calculation at the end of July 2026 the electricity break even sits roughly between 0.38 and 0.40 dollars per kilowatt hour. At Spanish household tariffs the machine stays in profit, but that margin was created by the rise of the ZEC price over the past year and will vanish if the price retraces.

Cooling. Air only, two factory blowers. No hydro or immersion versions were ever released for Equihash.

Pros. The second most efficient machine on the algorithm: 420 kSol/s at 1,510 W, 3.595 J/kSol. It trails the Z15 Pro by only 14 percent on efficiency while costing far less on the secondary market.

Cons. Exactly half the output per unit, which means twice the slots, cables and points of failure for the same total hashrate. A 2020 machine, so the risk of a power supply or hashboard failure is noticeably higher.

Best suited for. Someone building capacity in stages and buying refurbished machines with a seller warranty.

Payback. The electricity break even is roughly 0.34 to 0.35 dollars per kilowatt hour at the end of July 2026. Also above European tariffs, but with a smaller margin than the Z15 Pro.

Cooling. Air. It racks without modification, and a dense install needs an organised hot aisle exhaust.

Pros. More compact and quieter than the bigger models, drawing 1,418 W. A cheap way into the algorithm if the machine came almost free.

Cons. Efficiency of 10.504 J/kSol, more than three times worse than the Z15 Pro. A 2019 machine with almost no spare parts on sale.

Best suited for. Experiments, learning, testing a pool setup before buying proper hardware.

Payback. The electricity break even is roughly 0.115 to 0.12 dollars per kilowatt hour. At a Spanish household tariff that is already the edge, and if the ZEC price retraces this is the first Bitmain model to go into the red.

Cooling. Air, two fans. Still uncomfortable in a home because of the noise.

Pros. The best Innosilicon machine on the algorithm: 140 kSol/s at 1,550 W. On paper it beats the Antminer Z11 on absolute output.

Cons. Efficiency of 11.071 J/kSol, almost four times worse than the Z15 Pro. The manufacturer has effectively left the market, so there is no support and no spare parts.

Best suited for. Only if you already own the machine and it sits idle at a site with very cheap electricity.

Payback. The electricity break even is roughly 0.109 to 0.114 dollars per kilowatt hour. For Europe that means breaking even or losing money at any household tariff.

Cooling. Air. Given its age, budget for fan replacement and heatsink cleaning in advance.

Pros. The lowest absolute power draw in the catalogue: just 620 W. It fits an ordinary socket without a dedicated line.

Cons. Efficiency of 12.4 J/kSol and only 50 kSol/s. This is the first wave of Equihash ASIC, from 2018, and the machine is completely obsolete.

Best suited for. A collector item or a teaching unit, not something to count on for income.

Payback. The electricity break even is roughly 0.098 to 0.10 dollars per kilowatt hour. At Spanish tariffs it runs at a loss.

Cooling. Air, and fairly quiet next to the bigger models thanks to the low power draw.

Pros. The middle model of the line at 120 kSol/s. It sometimes turns up on the secondary market cheaper than the A9++, with a similar build.

Cons. The worst efficiency in the catalogue, 12.917 J/kSol: the same draw of 1,550 W as the A9++ but lower output. There is no price at which buying it instead of the A9++ makes sense.

Best suited for. Nobody as a working machine, only as a parts donor for the A9++.

Payback. The electricity break even is roughly 0.094 to 0.097 dollars per kilowatt hour, the lowest in the line. It does not pay off in Europe.

Cooling. Air, mechanically the same as the rest of the A9 series.

Hardware manufacturers

BitmainAntminer Z15 Pro, Z15 and Z11, from 3.155 to 10.504 J/kSol

Holds the whole top of the Equihash 200,9 market. The first machine was the Antminer Z9 mini in 2018, followed by the Z11 (2019), the Z15 (2020) and the Z15 Pro (2023). Bitmain has announced no new model on this algorithm since the Z15 Pro, and at the end of July 2026 it is still the last machine released for 200,9. Liquidity on the secondary market is higher for Bitmain than for any other vendor on the algorithm.

InnosiliconThe A9 ZMaster series, from 11.071 to 12.917 J/kSol

It was Innosilicon that brought the first Equihash ASIC to market in the spring of 2018 and effectively ended the graphics card era in this network. The A9, A9+ and A9++ line stayed competitive right up to the launch of the Antminer Z15. Today the company has no presence on the algorithm, there is no official support and no spare parts, and machines are bought second hand and run until they fail.

Nvidia and AMDHistorically, graphics cards, until the spring of 2018

For the first eighteen months Zcash was mined on graphics cards alone, and Equihash was one of the leading GPU algorithms of its time. Once ASIC arrived, the gap in performance per watt grew so wide that GPU mining on 200,9 disappeared in a single season. Today graphics cards make no sense on this parameter pair, and they remain relevant only for other Equihash variants.

New manufacturersNot one announcement for Equihash 200,9 since 2023

In three years the algorithm has not seen a single new vendor or a single new model. The reasons are plain: a narrow coin base, modest total network revenue next to SHA-256 and the high cost of designing a chip with a large memory budget. Plan any Equihash purchase on the assumption that the fleet will not be refreshed and that you will have to buy what already exists.

Firmware and overclocking

The short answer: custom firmware for Equihash ASIC does not exist. The support lists of HashCore Toolkit hold neither the Antminer Z15 Pro, nor the Z15, nor the Z11, nor the machines of the Innosilicon A9 series, and there are no plans to add them. All an owner gets is the factory software from the manufacturer.

The reason is not developer laziness but the shape of the market. The third party build ecosystem grew around SHA-256, where machines are counted in millions, a new Antminer model comes out every year and there is something to fight for: AsicBoost raises efficiency on the algorithm itself, and fine tuning of frequencies and voltages pays off across a large fleet. Equihash 200,9 has only six models, the newest from 2023, a fleet orders of magnitude smaller, and firmware development simply never pays for itself.

There is a technical reason too. The gain from AsicBoost comes from the structure of SHA-256 and has nothing to do with Equihash at all: the problem is different, the load profile is different and the bottleneck is memory rather than hashing logic. Even if firmware appeared, it could not repeat the gain that is typical for SHA-256.

The practical conclusion for a Z15 or Z15 Pro owner. The levers you have are pool choice, power quality, intake temperature and maintenance: cleaning heatsinks, replacing fans, servicing the power supply. Overclocking, undervolting and autotune are not coming from anywhere. If someone offers to sell you firmware for the Z15 Pro, treat it as a warning sign rather than good news: there are no verified builds in open access.

How to start mining

Getting started is simpler than on most algorithms, because there is almost nothing to choose from. You need the machine itself, a dedicated electrical line, a wallet address for payouts and a pool account. Setup comes down to entering the pool address, a login of the form wallet dot worker and a placeholder password. There are no special requirements for an operating system or extra software, an ASIC runs on its own.

Electrics. The Antminer Z15 Pro draws 2,650 W, which means a dedicated breaker and a 16 amp socket at the very least, and from three machines onward a three phase supply starts to make sense. The Z15 needs 1,510 W, the Innosilicon A9 series about 1,550 W, and the A9 ZMaster is far more modest at 620 W. Every model listed here has a built in power supply, so nothing has to be picked separately, though keeping a spare unit for a fleet older than three years is sensible.

Noise and heat. Industrial Equihash machines produce about 75 decibels, the level of a vacuum cleaner running around the clock. None of the six catalogue models can be run in a flat without modification, and modification is limited on this algorithm: no hydro or immersion versions were released and ready made quiet enclosures for the Z15 are practically absent from the market. The realistic setting is a garage, a utility room, a warehouse or a colocation site.

Home mining against industrial mining. The difference is sharper than usual because of the high electricity break even of the Z15 Pro and the Z15: at the end of July 2026 both machines stay in profit even at Spanish household tariffs. But that margin comes from the ZEC price rising about tenfold in a year, not from hardware efficiency. Plan a purchase knowing that if the price returns to the levels of 2025 only sites on an industrial tariff will stay in profit.

Profitability and what drives it

Miner income on Zcash comes from four factors: your share of network hashrate, the block subsidy minus the development fund, the ZEC price and the electricity tariff. Network fees are so small that you can leave them out of the calculation. The network produces about 1,152 blocks a day of 1.5625 ZEC each, of which roughly 80 percent goes to miners.

The dominant factor right now is the price. ZEC has risen about tenfold over the past year, and that is what moved old machines from loss into profit, not any improvement in hardware. The flip side: in June 2026, on the news of the flaw found in the proof circuit, the price lost more than 40 percent in two days. That is the real range of swings you have to be ready for.

The second factor is difficulty. It retargets every block, so it reacts to incoming capacity within hours. Trackers put the growth of network hashrate at about 27 percent over the month to the end of July 2026, with an all time high set on 28 July. Rising hashrate cuts your share directly: at an unchanged price the same Z15 Pro earns a quarter less than a month earlier.

The third factor is the tariff. At the end of July 2026 the electricity break even of the Z15 Pro is roughly 0.38 to 0.40 dollars per kilowatt hour, the Z15 about 0.34 to 0.35, and the Innosilicon machines 0.094 to 0.114. In other words the whole Innosilicon line and the Antminer Z11 sit at or beyond the edge at European household tariffs, while the bigger Antminer models keep a margin. Run the numbers for your own model and your own tariff in the calculator, these figures move with the price.

Open the profitability calculator →

Mining pools

PoolPayout schemeFeeNote
ViaBTCPPLNS and PPS+About 2 percent on PPLNS and 4 percent on PPS+The largest pool on the algorithm: MiningPoolStats data at the end of July 2026 puts it at around 7 GSol/s, noticeably more than a third of the network. The multi coin dashboard is handy if your fleet spans several algorithms.
F2PoolPPS+On the order of 2 to 3 percentThe second largest Zcash pool, about 4 GSol/s by the same source. A long history of supporting the coin and detailed documentation for setting up Bitmain machines.
AntPoolPPS and PPLNSFormally 0 percent on part of the plansThe Bitmain pool, historically strong with machines of its own make. Setting up a Z15 or a Z15 Pro takes a few minutes. Around 1 GSol/s at the end of July 2026.
2MinersPPLNSAbout 1 percentA small independent pool with public network statistics that are convenient for cross checking hashrate and difficulty. Russian language support.
Kryptex PoolPPLNSAbout 1 percentAnother pool with open charts of network hashrate. Suitable for small farms, and the payout threshold is low.
PoolinPPS and PPLNSAbout 2 to 4 percentIt appears in the Equihash pool lists of the specialised calculators. Before you connect, check that the payout thresholds and the withdrawal status are current.
FoundryTo be confirmedTo be confirmedIn March 2026 Foundry announced an institutional pool for Zcash. It targets large sites, and at the end of July 2026 the connection terms are not fully public. Note: the direction is confirmed by the announcement, the actual share of the pool in the network is unverified.
Solo mining on Equihash 200,9 has no practical sense: with a block of 75 seconds and network hashrate above 22 GSol/s, a single machine of the Z15 Pro class finds a block less often than once a year on average. Choose the scheme by your tolerance for variance: PPS and PPS+ give steady income for a bigger fee, PPLNS is cheaper but pays by contribution to the recent shifts. Hashrate distribution on this algorithm is noticeably concentrated, and joining a smaller pool is a contribution to network resilience.

Wallets

CategoryWallets
MobileZodl, formerly Zashi. The wallet was renamed on 16 February 2026 after the development team left ECC for the independent ZODL organisation. It supports Unified Addresses and shielded transfers, the update applies automatically and nothing has to be moved.
Mobile alternativesNighthawk Wallet for Android and iOS with shielded transfers by default, and YWallet, a multiplatform wallet with advanced features for experienced users.
Desktop and nodeZallet, the official wallet that replaced the built in zcashd wallet. The node itself is Zebra from the Zcash Foundation or the newer Zakura. The older zcashd client is officially retired.
HardwareKeystone 3 Pro supports shielded ZEC natively and pairs with Zodl. Ledger and Trezor work with transparent addresses, while full work with shielded pools through them is limited.
Multi coinExodus, Guarda, Trust Wallet and the like. Convenient for storage and swaps, but they support the private part of the protocol only in part or not at all, most often just t-addresses.
For pool payoutsPools accept both transparent and shielded addresses, but not all of them and not always. Before you configure your first worker, make sure the pool you picked supports the address type you entered.

The main rule of Zcash: the address type sets the level of privacy. A transfer between two transparent addresses is fully visible in the explorer, exactly as in Bitcoin. A transfer between shielded addresses hides the sender, the recipient and the amount. A transfer from transparent to shielded and back reveals the amount at the pool boundary, so partial privacy is a separate scenario you need to understand in advance.

After the Ironwood upgrade on 28 July 2026 users gained an extra task. The new pool started from zero and funds are moved out of the Orchard pool by the owner: there is no automatic migration. The Orchard pool sits in exit only mode, so it takes no new deposits. According to specialist outlets, only a very small share of funds moved into Ironwood in the first hours after activation, and the process is meant to be carried out gradually by users themselves. Update your wallet to a version that supports the new pool before you plan a move.

Where to buy and how to store

ZEC trades on most large venues and at the end of July 2026 it remains available on regulated exchanges in the United States, including Coinbase and Robinhood, while a number of other privacy coins have been delisted from them. The reason for that resilience is optional privacy: a transparent layer and viewing keys give the venues a compliance argument that coins with mandatory anonymity cannot offer.

Regulatory risk still exists, and it is worth weighing before rather than after you buy hardware. The EU anti money laundering regulation provides for a ban on anonymous accounts and on obliged entities handling anonymous crypto assets from 2027, and licensed venues in the European Union are already narrowing access. Lawyers differ on how exactly this will touch ZEC: the transparent layer may prove enough to keep a listing, or it may not. This section is for reference and is not investment advice.

If you are buying hardware rather than the coin: there is effectively no primary market for Equihash 200,9, and the last model was released in 2023. Almost every deal happens on the secondary market. Check the operating history, the condition of the fans and of the power supply, and insist on a load test of at least an hour with hashrate and temperatures recorded. Check separately that the machine is built for the parameter pair 200,9: listings often say only Equihash, which guarantees nothing by itself.

On the AML status of machines. Hardware bought on the secondary market can still be tied to a previous manufacturer account, and that is a separate question to settle before payment rather than after delivery. Ask the seller to confirm there are no locks and to hand over clean access to the web interface.

Strengths and weaknesses

Pros
  • The ZEC price rose about tenfold over the year to the end of July 2026, which pushed even old machines into positive territory on the electricity bill.
  • Classic PoW with no masternodes and no staking: the miner takes about 80 percent of the block subsidy, and the design is clear and predictable.
  • The next halving is only due around November 2028, which means more than two years without a scheduled reward cut.
  • Low competition for hardware: the machines are old, cheap on the secondary market, and there is no hype and no waiting list.
  • Difficulty retargets every block, so the network quickly restores its rhythm when capacity leaves or arrives, and there are no long stalls.
  • Technologically the network is still among the most advanced in privacy, and features such as viewing keys give it arguments in a conversation with regulators.
  • Verifying an Equihash solution is cheap and instant, so a node needs no special hardware to validate blocks.
Cons
  • The hardware market is frozen: the last model for Equihash 200,9 came out in 2023, there are no new announcements and fleet efficiency is not improving.
  • No custom firmware exists for the algorithm, so overclocking, undervolting and autotune are out of reach for the owner.
  • The network is small in total capacity and hashrate is concentrated between pools: one pool holds noticeably more than a third.
  • Volatility is extreme: in June 2026 the price lost more than 40 percent in two days on the news of a flaw in the proof circuit.
  • Cryptographic risk is confirmed in practice: the flaw in the Orchard pool circuit survived from 2022 to 2026 before it was found, and it forced an emergency soft fork.
  • Regulatory pressure on privacy coins is growing, and access through licensed venues in the European Union may narrow in the coming years.
  • Industrial machines on the algorithm run at about 75 decibels, and no quiet or immersion versions were ever built for it.

What the coin is used for

The main scenario for Zcash is payments where the amount and the counterparty should not be public: settlements between companies, payments to contractors, protection of commercial secrets, personal financial privacy. The transparent Bitcoin like layer does not go anywhere, and the user decides what to show and what to hide.

One property that coins with mandatory anonymity lack is selective disclosure. A viewing key gives a third party the right to read the history of an address without the right to spend the funds. That lets an auditor, a tax adviser or an exchange check the origin of funds at the owner's request. A payment disclosure mechanism proves a specific transfer without opening the rest of the history.

A shielded transaction carries a memo field of up to 512 bytes, encrypted along with the rest of the transfer. It is used for an invoice number, a payment purpose or a short message, none of which is published in the blockchain in the clear.

The share of shielded funds has grown noticeably in recent years: by the ZecHub digest, about 4.43 million ZEC sat in shielded pools on 26 July 2026. A large part of the traffic is still deposits into and withdrawals out of the pools rather than fully shielded transfers, so the anonymity of an individual user depends on exactly how that user handles the wallet.

Network statistics

ParameterValue
ZEC priceOn the order of 458 to 474 dollars, sources give different values
Market capitalisationAbout 7.9 billion dollars, bitinfocharts data for 30 July 2026
Circulating supplyAbout 16.7 million ZEC out of a maximum of 21 million
Network hashrateFrom 22.4 to 23.5 GSol/s, sources differ by about 5 percent
All time high hashrateAbout 27.6 GSol/s on 28 July 2026, CoinWarz data
Hashrate trendUp about 27 percent over the month and down about 7 percent over the week
DifficultyEstimates differ by almost a factor of two, from 176 to 234 million by tracker
Block heightAbout 3,430,000 on 31 July 2026
Block reward1.5625 ZEC, of which about 1.25 ZEC goes to the miner
Transactions per dayOn the order of 4,000, by weekly ZecHub data for the period to 26 July 2026
Shielded supplyAbout 4.43 million ZEC, roughly a quarter of issuance
Public nodesAbout 71: Zebra around 47, Zakura 16, the legacy zcashd 8
The figures were taken on 30 and 31 July 2026 and go stale within hours. Sources disagree on the key metrics, and that is not an error: hashrate and difficulty for Zcash are estimated, and different trackers use different averaging windows and different units. At the end of July 2026 CoinWarz showed about 22.4 GSol/s while 2Miners showed about 23.5 GSol/s, and the spread on difficulty is wider still, from 176 to 234 million. In June 2026 the price moved by more than 40 percent in two days. For profitability use a calculator that pulls values at the moment of the request rather than the numbers in this table.

Network security

Against the classic 51 percent attack model Zcash is protected more weakly than large networks simply because of scale: total hashrate is on the order of 22 to 23 GSol/s and much of it sits in a handful of pools. MiningPoolStats data at the end of July 2026 gives the largest pool noticeably more than a third of capacity. The network has no mechanisms such as quorum signatures to insure against history rewriting, so confirmation depth remains the only protection for a recipient.

The node layer is small in absolute numbers: about 71 public nodes at the end of July 2026 by the ZecHub digest, most of them on the Zebra implementation. The older zcashd client is officially retired and the community has moved to Zebra, Zakura and the Zallet wallet. The small node count is partly offset by several independent protocol implementations, which lowers the risk of one shared bug in a single code base.

The main incident in the history of the network happened in the summer of 2026 and concerned not proof of work but the mathematics of privacy. On 29 May 2026 the researcher Taylor Hornby found a flaw in the proof circuit of the Orchard pool: the base point in the scalar multiplication chain was not rigidly bound to the input value. By the BlockSec analysis, that made it possible to build a proof the network would accept with a substituted point and so to bypass the note uniqueness mechanism. The flaw had existed since the moment Orchard was activated in 2022. No confirmed exploitation has been recorded.

The response was fast and telling. On 2 June, at block 3,363,426, an emergency soft fork was activated that banned Orchard transactions completely, and on 3 June, at block 3,364,600, the NU6.2 upgrade went live with a corrected circuit and an extra consensus rule. On 28 July 2026 the Ironwood upgrade introduced a new shielded pool and moved Orchard to exit only, capping the exit with the turnstile. The point of that measure is to keep even theoretically incorrect notes from leaving the pool and affecting total issuance, and to make issuance itself independently verifiable.

Compatibility and requirements

ParameterValue
Hardware typeOnly ASIC for Equihash 200,9, graphics cards have been irrelevant since 2018
ManufacturersBitmain and Innosilicon, no other vendor works on the algorithm
Current modelsIn practice only the Antminer Z15 Pro of 2023 and the Antminer Z15
Compatibility with other EquihashNone: a machine for 200,9 does not compute 144,5, 192,7 or 125,4
Our firmwareNone, Equihash is not on the support list of the toolkit
Third party firmwareNothing found in open access, every machine runs factory software
Power supplyBuilt in and factory fitted. Z15 Pro 2,650 W, Z15 1,510 W, A9 series about 1,550 W
Electrical lineA dedicated breaker per machine, from three machines a three phase supply pays
CoolingAir only, no hydro or immersion versions were released for the algorithm
Noise and sitingAbout 75 decibels on industrial models, a living space is ruled out

Comparison with similar coins

ModelHashratePower drawEfficiencyElectricity break evenOur firmware
Antminer Z15 Pro840 kSol/s2,650 W3.155 J/kSolAbout 0.38 to 0.40 dollars per kWhNo
Antminer Z15420 kSol/s1,510 W3.595 J/kSolAbout 0.34 to 0.35 dollars per kWhNo
Antminer Z11135 kSol/s1,418 W10.504 J/kSolAbout 0.115 to 0.12 dollars per kWhNo
Innosilicon A9++ ZMaster140 kSol/s1,550 W11.071 J/kSolAbout 0.109 to 0.114 dollars per kWhNo
Innosilicon A9+ ZMaster120 kSol/s1,550 W12.917 J/kSolAbout 0.094 to 0.097 dollars per kWhNo
The electricity break even is the tariff at which a machine comes out at zero on the power bill, without counting the cost of the hardware itself, the rent of the space or the pool fee. The calculation is made for the end of July 2026 at a ZEC price of about 460 to 475 dollars, network hashrate of about 22.4 to 23.5 GSol/s and a subsidy of 1.5625 ZEC, of which roughly 80 percent goes to the miner. The thresholds look high because of the price, not because of machine efficiency: if ZEC returns to the levels of 2025 every value in the column falls by about an order of magnitude. Recalculate with current data in the calculator.

Outdated data and common errors

They write that the main shielded pool is Orchard. That held from May 2022 to July 2026. Since the Ironwood upgrade of 28 July 2026 the current pool is called Ironwood, and Orchard has moved to exit only: you cannot enter it, you can leave it, and withdrawals are capped by the turnstile. Reference sites last updated before the end of July 2026 miss this.

They write that Zcash necessarily requires a trusted setup ceremony. An outdated claim. A trusted setup was needed for the Sprout and Sapling pools. The Orchard and Ironwood pools are built on the Halo 2 system, which needs no trusted setup at all. That is one of the main changes of the NU5 upgrade in 2022.

They write that the target block time is 150 seconds. That was the case before the Blossom upgrade of 11 December 2019. Since then the target block time has been 75 seconds and the halving interval has been raised to 1,680,000 blocks.

They write that the Dev Fund is 20 percent between ECC, the foundation and grants. That scheme ran from November 2020 to November 2024 and ended with the NU6 upgrade. Today 12 percent of the subsidy accumulates in the deferred Lockbox fund, 8 percent goes to grants and about 80 percent stays with the miner. The ZIP 271 specification extended the Lockbox stream to block 4,406,400 in November 2025.

They call Zashi the main wallet. The wallet was renamed to Zodl on 16 February 2026 after the development team left Electric Coin Company in January 2026 and formed an independent organisation. Functionality, keys and user history did not change, and the update applied automatically.

They write that the main client is zcashd. The zcashd client is officially retired. The current node implementations are Zebra from the Zcash Foundation and the newer Zakura, while the wallet role belongs to Zallet. By the statistics of the end of July 2026 zcashd accounts for a minority of public nodes.

They write that the next halving is in 2024. The second halving happened on 23 November 2024 and cut the block reward from 3.125 to 1.5625 ZEC. The third is expected around November 2028 and will take the reward to 0.78125 ZEC.

They write that Equihash is one algorithm and the parameters can be tuned. The n and k parameters are set at the level of the coin and define the problem itself, not a mode of the miner. Equihash 200,9 (Zcash), 144,5, 192,7, 210,9 and 125,4 are different algorithms. An ASIC for 200,9 does not switch to another parameter pair through any setting or firmware.

They offer firmware for the Antminer Z15 and Z15 Pro. There are no verified third party builds for Equihash ASIC in open access, and these machines are not on the support list of our toolkit either. An offer to sell firmware for the Z15 Pro is worth treating as a reason to check the seller more carefully.

They copy profitability figures from third party model cards. At the end of July 2026 some popular reference sites showed a negative result for the Antminer Z15 Pro at a tariff of 0.10 dollars per kilowatt hour. That result comes from an outdated ZEC price. The same sources list a draw of 2,780 W instead of 2,650 W and an efficiency of 3.31 instead of 3.155 J/kSol. Check the specifications against the model card in the catalogue.

They quote one exact figure for hashrate or difficulty. For Zcash these metrics are estimates. At the end of July 2026 sources differ by about 5 percent on hashrate and by almost a factor of two on difficulty, from 176 to 234 million. Any single number without the name of the tracker and the time it was taken is worth treating as a rough guide.

They claim that the issuance of Zcash was forged in the summer of 2026. No confirmed exploitation of the flaw that was found has been recorded. This was a possibility that existed at the level of the proof circuit and was closed by the NU6.2 and Ironwood upgrades. The turnstile mechanism at the pool boundary was introduced precisely so that such a possibility can be excluded verifiably rather than in words.

Questions and answers

What is Zcash in simple terms

It is a proof of work cryptocurrency with the Bitcoin model, in which the user chooses whether a transfer is public or hidden. Hidden transfers are protected by zero knowledge proofs.

Who created Zcash and when

The network launched on 28 October 2016. The public face of the project became Zooko Wilcox, who founded Electric Coin Company. The technical basis is the Zerocash paper of 2014.

What algorithm does Zcash run on

Equihash with parameters n equal to 200 and k equal to 9, written as Equihash 200,9. Performance is measured in solutions per second, Sol/s.

Can you mine Zcash at home

Technically yes, in practice it is hard. Industrial models run at about 75 decibels and draw up to 2.65 kW. Realistic options are a garage, a utility room or a colocation site.

Which ASIC is the best for Zcash

The Antminer Z15 Pro: 840 kSol/s at 2,650 W, efficiency 3.155 J/kSol. It is the last model released on the algorithm, from 2023, and it leads everything else in the catalogue by a wide margin.

Are new Equihash miners still being released

No. Since 2023 the algorithm has not seen a single new model or a single new manufacturer. Plan a purchase on the basis that the fleet will not be refreshed.

Which pool should you choose for Zcash

By the data of the end of July 2026 the largest are ViaBTC and F2Pool, and there are also AntPool, 2Miners, Kryptex Pool and Poolin. Joining a smaller pool improves how capacity is spread across the network.

How does PPS differ from PPLNS

PPS and PPS+ pay a fixed amount for a share of work and give steady income for a higher fee. PPLNS pays by contribution to the recent shifts, the fee is lower but income swings more.

What is the situation with the Zcash halving

The second halving happened on 23 November 2024 and cut the reward to 1.5625 ZEC. The third is expected around November 2028 and will lower it to 0.78125 ZEC.

How much ZEC does a miner get from a block

About 1.25 ZEC. The full subsidy is 1.5625 ZEC, of which 12 percent goes to the deferred Lockbox fund and 8 percent to grants.

Why does difficulty change

Difficulty is recalculated with every block from a moving average, in order to hold the average interval at 75 seconds. Incoming capacity raises it within hours and departing capacity lowers it just as fast.

How should you store ZEC

The mobile wallets Zodl, Nighthawk and YWallet, or the desktop Zallet together with a Zebra or Zakura node. Among hardware wallets, shielded addresses are supported natively by Keystone 3 Pro.

What happened to the Zashi wallet

It was renamed to Zodl on 16 February 2026 after the development team left Electric Coin Company. Funds, keys and user history did not change, and the update applied automatically.

Where do you buy Equihash hardware

There is practically no primary market, and the last model was released in 2023. Buying happens on the secondary market, so a load test and a check for manufacturer locks are mandatory.

Can you install third party firmware on the Antminer Z15

No. No verified builds for Equihash ASIC have been found in open access, and these machines are not on the support list of our toolkit. The machines run factory software.

How do you cut the power draw of an Equihash machine

These models have no built in tools for undervolting or lowering frequencies. You can influence only intake temperature, the cleanliness of heatsinks, the condition of the fans and the quality of the power supply.

How loud is the Antminer Z15 Pro

About 75 decibels, the level of a vacuum cleaner running around the clock. No quiet enclosures and no immersion versions were built for the algorithm.

What power supply do you need

You do not need to pick one separately, all six catalogue models have a built in power supply. You do need a dedicated line: Z15 Pro 2,650 W, Z15 1,510 W, the Innosilicon A9 series about 1,550 W.

Does Zcash mining pay off in Spain

At the end of July 2026 the Antminer Z15 Pro and the Z15 stay in profit on the electricity bill even at a household tariff, while the Innosilicon machines and the Antminer Z11 sit at the edge or in the red. The margin of the bigger models comes from the rise of the price, not from efficiency, and it will vanish if the price retraces.

What happens if the ZEC price falls

The electricity break even falls in proportion to the price. In June 2026 ZEC lost more than 40 percent in two days, so this scenario is not hypothetical. Income partly recovers as some hashrate leaves and difficulty drops, but not fully and not at once.

Can you mine Zcash with a graphics card

Economically no. Since the spring of 2018 ASIC have been so far ahead of graphics cards on this parameter pair that a GPU does not even cover its electricity.

Does Zcash have merged mining

No. The protocol does not support mining another coin on the same hardware, so there will be no second source of income.

How many confirmations does Zcash need

Exchanges usually ask for 12 to 24 confirmations, roughly 15 to 30 minutes with a block of 75 seconds. A block reward becomes spendable only after 100 blocks.

What is the network fee on Zcash

Fees are low and barely affect miner income: the block subsidy makes up most of the revenue. There is no coin burning in the network, and fees go entirely to the miner.

Does the Antminer Z15 Pro mine other Equihash coins

Only those that use the parameter pair 200,9. The variants 144,5, 192,7, 210,9 and 125,4 are different problems with a different memory profile, and a machine for 200,9 does not compute them under any firmware or setting.