Equihash algorithm: the Zcash network, ASIC miners and specs
Mining algorithms · Equihash
Equihash: a birthday problem instead of brute force, solutions instead of hashes
6 ASIC models in the catalog, from the Antminer Z15 Pro at 3.15 J/kSol to the Innosilicon A9+ at 12.92 J/kSol. We break down the algorithm, the Zcash network, the hardware and the economics.
What Equihash is
Equihash is a proof of work algorithm built not on grinding through hashes but on the generalised birthday problem. The miner is not looking for a number with a given count of leading zeros; it is looking for a set of values whose XOR sum equals zero. The authors, Alex Biryukov and Dmitry Khovratovich of the University of Luxembourg, presented the paper at the NDSS conference in 2016.
Hence the unfamiliar unit of measurement. Performance of machines on Equihash is measured not in hashes per second but in solutions, Sol/s, and in practice in thousands of solutions, kSol/s. One solution is the result of a full pass of the algorithm rather than a single hash function call, so putting these numbers next to the terahashes of SHA-256 does not work under any conversion.
Equihash was meant to be an algorithm bottlenecked by memory bandwidth, which would deny dedicated chips their advantage. It did not turn out that way. First researchers showed that the algorithm has no proven bound on time memory tradeoff resistance, and then, in 2018, Bitmain simply shipped an ASIC. Today the Zcash network is mined entirely on ASICs, and the asic.es catalog holds 6 Equihash models from two manufacturers.
Key characteristics
| Parameter | Value |
|---|---|
| Algorithm | Equihash, the generalised birthday problem |
| Authors | Alex Biryukov and Dmitry Khovratovich, 2016 |
| Publication | NDSS conference, San Diego, 2016 |
| Parameters | n and k, for Zcash they are 200 and 9 |
| Solution size | 2 to the power of k indices, for Zcash that is 512 |
| Performance unit | Sol/s, solutions per second, in practice kSol/s |
| Hardware type | ASIC |
| GPU | Not profitable since 2018 |
| Main coin | Zcash, ticker ZEC |
| Network launch | 28 October 2016 |
| Block time | 75 seconds since the Blossom upgrade, December 2019 |
| Block reward | 1.5625 ZEC, the miner gets 80 percent |
| Halving | Every four years, the last one on 23 November 2024 |
| Efficiency unit | J/kSol, compare only within the algorithm |
| Models in the catalog | 6 from two manufacturers |
How the algorithm works
In Bitcoin the task reads like this: pick a nonce so that the header hash lands below the target. In Equihash the task is a different one: find a set of 2 to the power of k distinct indices whose corresponding hashes XOR to zero. That is what the generalised birthday problem means, and it is solved with Wagner algorithm.
The work runs in two stages. First the miner builds a large list of hashes, for Zcash that is millions of entries, and holds it in memory. Then the list is repeatedly merged with itself: each round keeps only the pairs that match on the next chunk of bits. There are exactly k rounds, and by the last one the sets that sum to zero remain. Each such set is a solution, a Sol.
The parameters n and k set the shape of the task. Raise n and the memory requirement grows. Raise k and memory falls while verification time grows. Zcash has used Equihash(200,9) since launch and has never changed the parameters. Other networks picked sets of their own, and that matters: a machine built for 200 and 9 physically cannot mine a network on 144 and 5.
Verification, meanwhile, is cheap: a node only has to recompute 512 indices and confirm the sum is zero. The asymmetry between expensive search and cheap verification is exactly what the algorithm was created for.
- Block headerVersion, previous block hash, roots, time, target, nonce
- List constructionMillions of hashes are generated into memory from the header and a counter
- k merge roundsEach round keeps the pairs matching on the next chunk of bits
- SolutionA set of 512 indices with a zero XOR sum, that is one Sol
- Comparison with the targetSolution hash below the target means a block, otherwise a new nonce
History of the algorithm
- 2016Alex Biryukov and Dmitry Khovratovich present Equihash at the NDSS conference. The intent: an algorithm where the bottleneck is memory, not arithmetic.
- 2016On 28 October the Zcash network launches on parameters 200 and 9. For the first four years 20 percent of the reward goes to the founders.
- 2018Bitmain ships the Antminer Z9 mini and Z9. The ASIC resistance idea finally stops working and graphics cards leave the algorithm.
- 2019In December the Blossom upgrade halves block time, down to 75 seconds, and halves the reward with it.
- 2020On 18 November comes the Canopy upgrade: the first halving and the end of founder payouts. A development fund takes their place.
- 2022In May the NU5 upgrade starts the shielded Orchard pool on the Halo 2 proof system, which removes the need for a trusted setup ceremony.
- 2024On 23 November the second halving arrives together with the NU6 upgrade. The block reward falls to 1.5625 ZEC and organisation funding is replaced by grants and a reserve.
- 2026In June a bug dating back to 2022 is found in the proof scheme of the Orchard pool. The network closes it with an emergency soft fork and the NU6.2 upgrade within a few days.
- 2026On 28 July comes the Ironwood upgrade: the old shielded pool is closed for good and a new one starts. Withdrawal from the old pool is capped at the provably deposited amount.
Coins on this algorithm
| Coin | Ticker | Notes |
|---|---|---|
| Zcash | ZEC | The main network of the algorithm, parameters 200 and 9. Practically all Equihash power sits here |
| Komodo | KMD | The same parameters 200 and 9 plus state notarisation into the Bitcoin blockchain. Liquidity is noticeably lower |
| Pirate Chain | ARRR | Parameters 200 and 9, every transaction is shielded, there are no transparent addresses |
| Ycash | YEC | A 2019 Zcash fork on parameters 192 and 7. Machines built for 200 and 9 cannot mine this network |
| Bitcoin Gold | BTG | Parameters 144 and 5, a separate hardware family. The network formally runs, but hashrate is tiny |
| Horizen | ZEN | Used to run on 200 and 9. Its own chain was stopped on 23 July 2025 and the coin moved into a contract on another network |
ASIC miners for Equihash
All 6 Equihash models in the catalog, sorted by efficiency with the best on top. Performance in kSol/s, efficiency in joules per thousand solutions. Click a name to open the profitability calculator for that model.
| Model | Hashrate | Power | Efficiency |
|---|---|---|---|
| Antminer Z15 Pro | 840 kSol/s | 2650 W | 3.15 J/kSol |
| Antminer Z15 | 420 kSol/s | 1510 W | 3.6 J/kSol |
| Antminer Z11 | 135 kSol/s | 1418 W | 10.5 J/kSol |
| Innosilicon A9++ ZMaster | 140 kSol/s | 1550 W | 11.07 J/kSol |
| Innosilicon A9 ZMaster | 50 kSol/s | 620 W | 12.4 J/kSol |
| Innosilicon A9+ ZMaster | 120 kSol/s | 1550 W | 12.92 J/kSol |
Hardware manufacturers
The company effectively defines this market. The Z11 of March 2019 gave 135 kSol/s, the Z15 of May 2020 came straight in at 420 kSol/s on 1510 watts, and the Z15 Pro of June 2023 doubled that to 840 kSol/s. As of July 2026 the Z15 Pro is still the fastest and the most efficient machine on the algorithm, with no competitor.
The whole lineup dates to 2018 and 2019 and sits in a band from 11 to 13 J/kSol. The most interesting of the three is the compact A9 ZMaster: 50 kSol/s on 620 watts, far lighter on power requirements than the rest. The company has not released a new Equihash machine since 2019.
Firmware for Equihash miners
There is no custom firmware for Equihash. AsicBoost firmware is built for SHA-256 boards, on Scrypt it covers two models, and the Z series and the A9 line are not on that list. Network installation through HashCore Toolkit belongs to those same supported lines.
The same holds for third party developers. None of the known alternative firmware projects for Antminer claims support for the Z15, the Z15 Pro or Innosilicon machines: their lists carry only SHA-256 and two Scrypt models. The whole custom firmware market is concentrated on Bitcoin hardware, because the installed base there is orders of magnitude larger.
One more warning about a common piece of misinformation. A number of marketplaces publish articles along the lines of "install alternative firmware on a Z15 and get 460 kSol/s instead of 420". That directly contradicts the official supported hardware lists of the firmware developers themselves. Files of unknown origin from marketplaces and auctions do not belong on your machine: the risk of a brick and a voided warranty is real.
The practical conclusion. Efficiency in J/kSol is fixed at the moment of purchase and does not improve afterwards. It has to be calculated before the deal, not after.
What profitability depends on
Income on Equihash is set by Zcash network difficulty, the ZEC exchange rate and your efficiency in J/kSol. As on Dash, the miner does not get the whole block reward, and that detail is often missed.
Since the NU6 upgrade of November 2024 the reward splits like this: 80 percent to the miner, 8 percent to community grants and 12 percent into a reserve whose spending is decided by coin holder votes. The full block reward is 1.5625 ZEC, so the miner gets 1.25 ZEC. The next halving is expected in November 2028.
Zcash block time is short, 75 seconds, so there are many blocks per day and pool payouts come in evenly. The ZEC rate, on the other hand, has historically moved far harder than most coins: through the autumn of 2025 it rose several times over, and in the summer of 2026 it dropped sharply on news of a technical problem in the network. Calculate payback on current numbers with room to spare, not on the peak of the chart.
Popular pools
| Pool | Region | Notes |
|---|---|---|
| ViaBTC | Asia, global | PPLNS and PPS+ to choose from, the largest Zcash pool, minimum payout from 0.1 ZEC |
| F2Pool | USA, EU, Asia | PPS+ scheme, the second largest pool on the algorithm, daily payouts |
| AntPool | Global | PPLNS scheme, the Bitmain pool, a familiar interface for Antminer owners |
| 2Miners | Europe, USA, Asia | PPLNS and PPS+, a low payout threshold from 0.01 ZEC, servers in several regions |
| Flypool | USA, EU, Asia | PPLNS scheme, one of the oldest pools on the algorithm |
| Kryptex Pool | Europe, CIS | Russian language interface and support, an option for small setups |
Strengths and weaknesses
- Verification is cheap, so network nodes run on modest hardware
- Short block time, 75 seconds, gives even pool payouts
- The network has run since 2016 and survived several major protocol upgrades
- Zcash stays in the upper part of the market cap ranking, liquidity is decent
- The catalog leader Z15 Pro is twice as fast as the previous generation
- There is a compact 620 watt model for those who do not need a full rack
- The miner gets 80 percent of the reward, the rest goes to grants and the network reserve
- There is no custom firmware, efficiency is fixed at the moment of purchase
- No new models since 2023, there is nothing to refresh the fleet with
- The n and k parameters differ between networks, the fleet does not switch freely
- The ZEC rate moves sharply, a payback calculation needs a margin of safety
- Privacy features create regulatory risk on the EU market
Energy efficiency and J/kSol
Efficiency of Equihash machines is measured in joules per thousand solutions, J/kSol. These are not hashes and not terahashes: one solution is the result of a full pass of the algorithm. Comparing J/kSol with the J/TH from the SHA-256 pages or with the J/GH from the X11 page is not valid under any conversion. The comparison only makes sense within Equihash.
Inside the algorithm the spread is moderate by the standards of other pages, but still noticeable. The Antminer Z15 Pro needs 3.15 J/kSol, the Z15 needs 3.6, and the whole Innosilicon lineup together with the Antminer Z11 sits in a band from 10.5 to 12.92. Between the leader and the bottom row the difference is a little over four times.
The arithmetic goes like this: multiply efficiency by performance in kSol/s to get draw in watts, divide by 1000 to get kilowatts, multiply by your tariff and by 720 hours a month. Compare that sum with the mining forecast in the calculator, remembering that the miner gets 80 percent of the block reward, not all of it.
How to choose an ASIC for Equihash
Check the network parameters, not just the algorithm. The word Equihash on a coin page means nothing on its own. A machine built for 200 and 9 mines Zcash but does not mine Bitcoin Gold or Ycash. That is the first thing to establish before buying.
Look at J/kSol, not at kSol/s. Performance tells you about speed, efficiency tells you about the power bill. Between the Z15 Pro and the Antminer Z11 the efficiency difference is more than threefold at comparable draw.
Work out whether you need a full rack. The Z15 Pro takes about 2.6 kilowatts, its own breaker and an exhaust setup. The Innosilicon A9 ZMaster gets by on 620 watts, which is a fundamentally different siting scenario.
Accept that there will be no new models. The last Equihash machine came out in 2023. There is nothing to plan a fleet refresh around two years from now.
Do not count on firmware. On Equihash there is nothing to improve. Factory numbers are your numbers for the whole time you own the machine.
Budget for volatility. The ZEC rate moves harder than the market average. A payback calculation that only works at the peak price does not work at all in practice.
Common mistakes
Confusing Sol/s with hashes per second. These are different quantities. One solution is a full pass of the algorithm. Converting kSol/s into megahashes is pointless; you get a number with no physical meaning.
Assuming any Equihash network will do. Networks use different n and k, and a machine for 200 and 9 will not mine 144 and 5. These are different algorithms, not different settings of one.
Counting income on the full block reward. The miner gets 80 percent of 1.5625 ZEC, that is 1.25 ZEC. The rest goes to grants and into the network reserve.
Believing overclocking promises for the Z15. Articles about alternative firmware for the Z15 contradict the official support lists of the firmware developers themselves. That is marketplace marketing, not a working solution.
Buying an A9 because it is cheap. The A9 line spends more than three times the energy of a Z15 Pro on the same work. What you save on the purchase goes into the bills of the first few months.
Ignoring the regulatory backdrop. Zcash is classed among assets with privacy features, and European rules for such assets are tightening. This affects not mining itself but where and how you will be able to sell what you mine.
Frequently asked questions
What is Equihash in simple terms?
It is a proof of work algorithm where the miner looks not for a number with leading zeros but for a set of values with a zero XOR sum. The task is called the generalised birthday problem, and the set that is found is called a solution.
Who invented Equihash?
Alex Biryukov and Dmitry Khovratovich of the University of Luxembourg. The paper was presented at the NDSS conference in 2016.
What do Sol/s and kSol/s mean?
Solutions per second and thousands of solutions per second. One solution is the result of a full pass of the algorithm rather than a single hash function call, so comparing these numbers directly with a hashrate in H/s is not valid.
What do the n and k parameters mean?
They set the shape of the task. Raise n and the memory requirement grows. Raise k and memory falls but verification time grows. Zcash has used 200 and 9 since launch.
Why did Equihash not stay ASIC resistant?
For two reasons. Researchers showed that the algorithm has no proven bound on time memory tradeoff resistance, and in 2018 Bitmain simply shipped machines and took over the network.
Which coins are mined on Equihash?
The main one is Zcash. Komodo and Pirate Chain run on the same 200 and 9, while Bitcoin Gold and Ycash use other parameters. Horizen stopped its chain in July 2025.
Will an Antminer Z15 work for Bitcoin Gold?
No. The Z15 is built for parameters 200 and 9, and Bitcoin Gold uses 144 and 5. These are different algorithms and one machine cannot mine both.
Can Equihash be mined on a graphics card?
Technically yes, economically no. After ASICs arrived in 2018, graphics cards on Zcash do not pay for the electricity.
Which model is the most efficient in the catalog?
The Antminer Z15 Pro: 840 kSol/s on 2650 watts, which gives 3.15 J/kSol. That is the best figure among the six models in the catalog.
How many Equihash models are in the asic.es catalog?
Six, from two manufacturers: three Bitmain machines and three Innosilicon.
Is there custom firmware for the Antminer Z15?
None that is confirmed. No known alternative firmware project supports the Z series, and the articles promising overclocking contradict the official lists of the developers themselves.
What does J/kSol mean on this page?
Joules per thousand solutions, that is how much energy the machine spends per unit of work. The lower the number, the cheaper the mining. This figure can only be compared with other Equihash machines.
What is the Zcash block reward right now?
The full reward is 1.5625 ZEC. The miner gets 80 percent, that is 1.25 ZEC, another 8 percent goes to community grants and 12 percent into the network reserve.
When were the Zcash halvings and when is the next one?
The first was on 18 November 2020, the second on 23 November 2024. The reward fell to 1.5625 ZEC. The next one is expected in November 2028.
Why is the Zcash block time 75 seconds?
That came with the Blossom upgrade in December 2019. Before it the interval was 150 seconds, and the upgrade halved it along with the block reward.
What are shielded and transparent addresses?
Transparent ones work as in Bitcoin; everything is visible in the blockchain. Shielded ones use zero knowledge proofs: the transaction is verified as valid while the sender, the receiver and the amount stay hidden.
What happened to Zcash in the summer of 2026?
A bug dating back to 2022 was found in the proof scheme of the shielded pool. The network closed it with an emergency upgrade within a few days, and on 28 July 2026 the Ironwood upgrade closed the old pool and started a new one. Total issuance was unchanged and mining was unaffected.
Is Zcash moving to proof of stake?
A full move is not planned. What is discussed is a hybrid scheme where proof of work stays for block production and a staking finality layer is added on top. There is no mainnet date, and nothing changes for miners.
Which pools can I point the machines at?
Among the active ones: ViaBTC, F2Pool, AntPool, 2Miners, Flypool, Kryptex. Note that the first two together hold about half the network power.
Are there restrictions on Zcash in Europe?
ZEC is classed among assets with privacy features, and new European rules for licensed crypto services take effect in July 2027. They do not ban holding or mining, but they may affect how exchanges operate. This is not legal advice, so if you plan large volumes, check with your own specialist.
Technical specification of the algorithm
| Parameter | Value |
|---|---|
| Full name | Equihash, an asymmetric proof of work |
| Authors and year | Alex Biryukov and Dmitry Khovratovich, 2016 |
| Mathematical basis | The generalised birthday problem, Wagner algorithm |
| Parameters | n sets memory, k sets the number of merge rounds |
| Zcash parameters | 200 and 9, unchanged since the network launched |
| Solution size | 2 to the power of k indices, that is 512 for Zcash |
| Solution condition | A zero XOR sum of the chosen hashes |
| Asymmetry | Search is expensive, verification is cheap |
| Performance unit | Sol/s, solutions per second |
| Main network | Zcash, launched on 28 October 2016 |
| Privacy | zk-SNARK, shielded and transparent addresses |
| Block time | 75 seconds since December 2019 |
| Supply cap | 21 million ZEC |
| Other parameter sets in the wild | 144 and 5 for Bitcoin Gold, 192 and 7 for Ycash |
| Units | Performance in kSol/s, efficiency in J/kSol |