Zcash is the gold.
Astrea is the infrastructure.
Zcash made private digital money real. Its shielded pool encrypts value instead of hiding it in a crowd, its supply follows Bitcoin's schedule, and it has run since 2016. We believe it is the closest thing to private digital gold. Astrea is not the money. Astrea is the infrastructure private money moves on: a bridge that takes shielded ZEC in without unshielding it, a ledger that keeps track with zero knowledge, contracts that put it to work, and a route to Ethereum and, in time, other chains, all of it post-quantum. This page makes the case for Zcash, shows where its privacy ends today, and explains how Astrea extends it.
Money is the last monopoly
The printing press broke the monopoly on information, and the internet broke the monopoly of geography. Money is the coordination tool that still runs on permission: every account can be frozen, every transfer can be watched, and every purchase you make without cash is stored somewhere indefinitely.
The idea of private digital money is older than the web. David Chaum published blind signatures in 1982 and shipped ecash through DigiCash in the 1990s: a bank could sign a token without seeing it, and could later verify the token without linking the spend to the withdrawal. The company failed on timing rather than mathematics. The cypherpunks who gathered in 1992 took the next step and wrote it down in 1993: "We cannot expect governments, corporations, or other large, faceless organizations to grant us privacy out of their beneficence. We must defend our own privacy if we expect to have any. Cypherpunks write code."
Bitcoin, in 2009, solved the problem that had defeated every earlier design: preventing a double spend with no central party. It did so by publishing everything. Every transaction, every address, and every balance is visible to anyone who looks, forever. The whitepaper's advice to use a fresh address per payment was a weak mitigation then. By 2014 companies were selling blockchain forensics to law enforcement, and address clustering had become an industry.
"In some ways, Bitcoin is actually worse than the banking system it sought to replace. At least bank records are private from the general public; Bitcoin isn't."
Maxime Desalle, "Mastering Zcash", January 2026Sources: Chaum, "Blind Signatures for Untraceable Payments" (1982); Hughes, "A Cypherpunk's Manifesto" (1993); Nakamoto, "Bitcoin: A Peer-to-Peer Electronic Cash System" (2008).
Zcash verifies a transaction without seeing it
Bitcoin's nodes check a transfer by reading it. Zcash's nodes check a transfer by verifying a proof. That single change is why the shielded pool can encrypt the sender, the recipient, and the amount while the network still rejects double spends and still enforces that no coins were created.
A shielded balance is a set of notes, encrypted chunks of value that only the owner can read. The chain stores a commitment to each note, a one-way fingerprint, in a tree that only grows. To spend a note you publish a nullifier, a value derived from the note with a private key, and a zero-knowledge proof that the note exists in the tree, that you hold the key, that the nullifier belongs to that note, and that the amounts balance. The nullifier stops the note being spent twice. Nothing in the proof says which note it was, so a spend hides among every shielded note ever created, and that crowd only grows.
This is encryption rather than obfuscation. A mixer or a decoy ring hides a needle in a haystack, and a better magnet finds it later. An encrypted ledger contains no needle to find: what an observer sees is indistinguishable from random bytes, so the privacy does not weaken as analysis improves. The proof itself is about 1.5 kilobytes and verifies in milliseconds, which is why every node can check every shielded transaction. Since the Orchard upgrade in 2022, the proving system needs no trusted setup, so there is no ceremony behind the coins and no secret that a participant might have kept.
The monetary rules are Bitcoin's. Supply is capped at 21 million ZEC, new coins arrive through mining rewards that halve roughly every four years, and turnstiles between the transparent and shielded pools mean that a counterfeit inside the shield would show up as more coins leaving than ever entered. Owners can hand an auditor, an accountant, or a tax authority a viewing key that reads history without spending. ZEC has been legal in the United States and traded on regulated exchanges since launch, and modern wallets shield funds by default.
"Bitcoin was supposed to be digital gold. Arguably, it is in certain ways, yet its transparency creates a different vulnerability. If every one of your transactions is visible on a public ledger, the state can simply identify your holdings, track your movements, and apply pressure through legal channels. The transparency that makes Bitcoin trustless also makes it targetable."
Maxime Desalle, "Mastering Zcash", January 2026Why we call it private digital gold
Gold earned its role by being scarce, hard to confiscate at scale, hard to track, and durable across regimes. Bitcoin reproduced the scarcity and the durability and published every holding. Zcash keeps Bitcoin's monetary rules and encrypts the ledger. On the properties that made gold a reserve, it is the closest thing in existence today.
| Gold | Bitcoin | Zcash | |
|---|---|---|---|
| scarce | mined slowly, supply grows about 1 to 2 percent a year | 21 million, halving issuance | 21 million, the same halving schedule |
| hard to confiscate at scale | physical custody, hard to seize in bulk | holdings are visible, so they can be targeted | shielded balances are visible only to their owners |
| hard to track | no ledger | every transfer is public forever; pseudonyms cluster | sender, recipient, and amount are encrypted; the network checks a proof |
| holds across regimes | millennia | since 2009 | since 2016, three protocol generations, legal and listed |
| usable | must be assayed, stored, and moved by hand | digital, but every use leaves a record | digital, shielded on a phone, and the network still verifies every spend |
Mechanism and parameters: Hopwood, Bowe, Hornby, and Wilcox, Zcash Protocol Specification; the Orchard pool runs on the Halo 2 proving system. Gold supply growth is the commonly cited long-run average from mine output. The belief statement is ours.
The crossing is where privacy ends
Zcash was built to keep value private at rest. It was not built to let that value act inside other economies. Every route out of the shield puts ZEC back on a public ledger, and the crossing itself is the evidence an observer needs.
The shielded pool is a good place to keep value. It is also the limit of where that value can go while staying private. To trade ZEC on an exchange, an owner sends it to a transparent address the exchange controls. To use it on Ethereum, an owner hands it to a bridge and receives a wrapped token whose every movement is public. To pay someone who is not on Zcash, the coins leave the pool. Each of those steps is a public entry or exit with a value and a time, and pairing entries with exits is exactly the analysis that has worked against Zcash in practice.
Kappos, Yousaf, Maller, and Meiklejohn studied the network through January 2018, when the original Sprout pool was the only shield. Their heuristics linked 28.5 percent of all coins ever deposited into the pool to their withdrawals by matching exact values a short time apart, attributed 65.6 percent of withdrawn value to founders and miners, and shrank the anonymity set by 69.1 percent in total. Every one of those heuristics works at the boundary. Transactions that stayed inside the shield were 0.3 percent of the total, and the paper reports that "relatively little information can be inferred" from them. The authors' own recommendation was to require all transactions to take place within the shielded pool.
Zcash has answered on its side of the boundary. Sapling and Orchard made shielding cheap enough for a phone, wallets such as Zashi now shield by default, the Tachyon project is removing the remaining scaling limits, and a fee on transparent use has been proposed. Those fix the wallet. They do not change what an exchange, a bridge, or a public market has to see when ZEC arrives, because the destination was never designed to hold a market. The pool is a vault. Economies need a bridge that keeps the vault's promise on the other side.
Figures from Kappos, Yousaf, Maller, and Meiklejohn, "An Empirical Analysis of Anonymity in Zcash" (USENIX Security 2018; arXiv 1805.03180): data to block 258,472 on 21 January 2018; 2,242,847 transactions, of which 6,934 were shielded-to-shielded. The pool held 3.6 percent of supply at the time. Orchard did not exist yet, so the anonymity set of today's pool is a different question; the boundary is the same.
Shielded ZEC enters Astrea by proof
A port city is not rich because of the gold in its vaults. It is rich because of its infrastructure: the harbor, the roads, the bonded warehouses, and the customs house that let value from one economy move into another without being opened on the dock. Astrea is that infrastructure for private money, and Zcash is the gold. Shielded ZEC is shipped to the bridge and stays in Zcash's shielded pool. Astrea proves the Zcash chain itself to confirm the shipment instead of taking a signer's word, keeps track of who owns what with zero-knowledge receipts, lets contracts put it to work, and carries it to Ethereum and back without ever unshielding it.
| In the port city | In the system |
|---|---|
| the vault | the Zcash shielded pool, where ZEC rests and where it returns |
| the bridge | a shielded deposit to the bridge's Zcash address, credited inside Astrea by a proof of the Zcash chain |
| the ship's papers | the proof itself: block headers and the work behind them, the note-commitment anchor, and the deposit note |
| the port city | Astrea: not the money, the infrastructure. A private ledger under a certified root, one accepted order, a receipt for every action |
| bonded warehouse | the bridge's own shielded balance on Zcash, never unshielded, with Astrea's private ledger keeping track of whose it is |
| customs stamp | a zero-knowledge receipt: the rules were followed, the cargo stays sealed |
| manifest | declared disclosure: the fields a venue or counterparty is allowed to see |
| cargo | the private state: owner, balance, strategy, counterparties, and whose deposit was whose |
| ships | agents acting under the tools, capital, and limits their owner set |
| other economies | Ethereum first, proved in through the beacon chain; any chain whose consensus and state can be proved, later |
A real customs officer can open a crate. Astrea's validators cannot open the ledger. They check receipts, not contents. One part of the analogy needs care: a warehouse has a key, and so does the bridge. Something has to be able to release ZEC on the Zcash side, and who holds that key matters more than anything else in the design. The next section answers it. The key is split across the validators as a threshold key, and it is used only for a withdrawal the proofs have already authorized. One limit belongs here as well. The validators hold the bridge's viewing keys, so they can see the amounts and times of deposits and withdrawals. They cannot see who sent a deposit or who claimed it.
ZEC rests in the shield
Nothing changes on Zcash. Holdings stay in the shielded pool until the owner decides to put them to work.
Ship it shielded
A deposit is an ordinary shielded transfer to the bridge's Zcash address. Its memo carries a commitment to the owner's Astrea account. The Zcash chain shows a shielded transaction and nothing else.
Prove the Zcash chain
A registered computation proves the block headers and the work behind them, the note-commitment anchor, and the deposit note, and imports the result into certified state after a declared confirmation depth.
Put ZEC to work
The owner claims the deposit with a proof of the memo's commitment. The coins stay in Zcash's shielded pool; inside Astrea they are a private balance kept with zero knowledge. Contracts hold and move it, and actions reach Ethereum through Astrea's proxy accounts, with Ethereum's state proved in through the beacon chain.
Return to the shield
A withdrawal is a shielded transfer back to the owner's Zcash address, with its own timing. A settlement receipt binds the public venue action to the private authorization.
Two of Zcash's own ideas carry over. Inside Astrea, ZEC is held as notes with commitments and nullifiers, the same shape Zcash uses, so a spend inside Astrea hides among every note the ledger has ever recorded. And the manifest is a viewing key's idea applied to a market: the owner decides what a counterparty sees, and the schema makes that decision checkable. What is new is the way the chains meet. Zcash's state does not arrive on a signer's word; Astrea proves it. Ethereum's state does not arrive on a relayer's word either: Astrea proves the beacon chain's finalized checkpoint, the execution state root beneath it, and the Merkle Patricia path to the contract slot, the same path the applications page describes for any outside fact.
The bridge is a design being built toward a testnet. The Zcash chain proof, the beacon-chain import, the private ledger, proxy execution, and the settlement receipt are engineering claims about that design, not measurements of a running network. The bridge's Zcash key is a threshold key across the validators, described in section 05, and a deposit is credited only after a declared confirmation depth, because Zcash is proof of work without cryptographic finality until the Crosslink upgrade lands. Astrea's machine-checked proof covers its consensus core only; the bridge's components are engineered and tested. Section 10 states each boundary in full.
The key that releases ZEC is the network itself
Zcash cannot check an Astrea proof. To release a shielded note it needs what it always needs: a Halo 2 proof and a spend-authorization signature under the note's key. So the question for any bridge is who holds that key and what makes them sign. Astrea's answer is that the key is the validator set, and the signature comes after the proof.
The bridge's spend-authorization key is a threshold key. It is created by distributed key generation among Astrea's validators, so no validator, operator, or machine ever holds it whole, and producing a signature needs a threshold of them, weighted by stake. The construction is Zcash's own: ZIP 312 adapts the FROST threshold-signature scheme to Zcash spend authorization, with a ciphersuite for Orchard on the Pallas curve and the re-randomization of the spend key handled inside the protocol. Astrea supplies what the ZIP leaves to implementers: the key generation, the viewing-key material validators need to detect deposits and build proofs, and the rule that decides when a share is released.
That rule is what makes the key safe to hold. A validator releases its share of a signature for one thing only: a withdrawal that already exists in Astrea's certified state with a valid zero-knowledge receipt. Coin selection from the bridge's notes is deterministic from that state, so honest validators assemble the same Zcash transaction. Any validator can construct the Halo 2 proof, because building it needs the viewing-key material and the note contents rather than the spend key. FROST then produces the one signature Zcash will accept. Nothing in this sequence asks a validator for an opinion. It asks for a share of a signature on a transaction the proofs have already authorized.
Why this adds no new trust
The signing threshold matches the consensus threshold. A group of validators large enough to sign a withdrawal the proofs did not authorize is the same group that could already rewrite Astrea's history, and the machine-checked safety proof for the consensus core is the statement that no smaller group can. Every other bridge design introduces a second set of keyholders whose honesty has to be assumed on top of the chains at either end. This one has a single set, and it is the set the network already runs on.
Accountabilitya rogue spend is provable
Validators hold the bridge's nullifier key, so every spend of a bridge note is visible to them. A spend that matches no certified withdrawal is provable misbehavior, and Astrea proves each withdrawal's nullifiers back in from the Zcash chain to close the loop.
Resharingthe set changes, the key does not move
When the validator set changes at an epoch boundary, the shares are reissued to the new set without moving funds or changing the public key. Old shares stop being useful.
Blast radiusseveral keys, capped outflow
The reserve is split across several threshold keys, so no single committee can release all of it, and policy caps how much may leave in an epoch.
Shapewithdrawals look alike
Zcash hides amounts and addresses but shows timing and the number of actions in a transaction. Withdrawal batches are padded to standard shapes and released on a schedule, and they travel through PRISM and Dandelion# like any other traffic.
Compared with other ways to hold bridged coins
Every bridge that moves coins off a chain without scripting has to hold a key on that chain. The designs differ in who holds it, what makes them sign, and whether a new group has to be trusted. The comparison below is the case for ours.
| Astrea bridge | NEAR chain signatures | vault swap networks | multisig lock-and-mint bridges | atomic swaps | |
|---|---|---|---|---|---|
| who holds the key | Astrea's validators, as one threshold key from distributed key generation | a separate MPC network of signer nodes | the network's node operators, in threshold-signed vaults | a fixed multisig of operators | nobody; each party keeps its own |
| what makes them sign | a withdrawal proved and ordered in certified state | an instruction from a contract on NEAR | the vault protocol's own accounting | the operators' software or vote | a secret revealed on the other chain |
| trust beyond the chains at either end | none added: the signers are the validators and the threshold is the consensus threshold | fewer than the threshold of MPC nodes collude | fewer than the threshold of operators collude | the multisig's holders stay honest and keep their keys | none, at the cost of transparent addresses and a public link between the chains |
| a rogue keyholder can | sign nothing the proofs did not authorize without a consensus-sized collusion, and any such spend is provable | sign whatever a threshold agrees to | sign whatever a threshold agrees to | sign whatever the multisig agrees to | nothing; there is no shared key |
| privacy of the crossing | a shielded transfer in, a shielded transfer out, a zero-knowledge ledger between | the swap is public on NEAR | the swap is public in the vault | the lock and the mint are public | transparent addresses on Zcash and a shared secret on both chains |
| cryptography on the bridge side | post-quantum proofs and paired signatures | classical secp256k1 and Ed25519 | classical | classical | classical |
Threshold signing for Zcash: Gouvea, Komlo, and Connolly, ZIP 312, "FROST for Spend Authorization Multisignatures", which specifies the Orchard ciphersuite and re-randomization and leaves key generation to the implementer. NEAR chain signatures and intents: NEAR Docs. Vault networks refer to THORChain and Maya Protocol. Multisig lock-and-mint is the common design of token bridges onto Ethereum. Atomic swaps on Zcash are limited to transparent addresses; see section 03.
Zcash cannot verify an Astrea proof, so the guarantee on the Zcash side is a signature from a threshold of validators, not a proof Zcash checks itself. Withdrawals need that threshold online. Validators, as holders of the viewing keys, see deposit and withdrawal amounts and times, though not who deposited or who claimed. Key generation, resharing, and the release rule are Astrea's engineering outside ZIP 312's scope, and they belong to the engineered set rather than the machine-checked one.
Post-quantum on the way in and the way out
Everything from the deposit proof inward runs on cryptography designed to survive a quantum computer. That is the second thing the bridge changes, and it is what separates it from the routes that move ZEC today.
Astrea's proofs are post-quantum in the primary profile, engineered for 160-bit post-quantum security with an absolute 128-bit floor, on a mathematical framework of our own. Its sessions and signatures carry classical and post-quantum halves together, X25519 with ML-KEM-768 for secrets and secp256k1 with ML-DSA-65 for signatures, both halves mandatory, with Resonance, Astrea's own post-quantum signature family, alongside them. PRISM hops and Dandelion# stems are wrapped the same way. So the proof that credits a deposit, the receipt that moves a balance, the session that carries an action, and the signature that authorizes it are all built for the day the classical half falls, and what is recorded today does not open later.
Neither end of the bridge is there yet, and the page says so. Zcash's spend linkage rests on symmetric primitives, but its note encryption and signatures are classical today; its developers have a recoverability plan and the Tachyon design in progress. Ethereum's beacon chain signs with BLS, which is classical. The bridge checks both chains' cryptography as it stands and does not change it. What it changes is everything on Astrea's side of the line.
Compared with the routes that move ZEC today
ZEC already crosses chains through NEAR Intents, where solvers fill a request and a verifier contract on NEAR settles it, with a threshold network of MPC nodes signing on other chains' behalf, and through vault-based swap networks that hold ZEC in threshold-signed vaults. They work, and Zashi's swaps use the first of them. They are a different design.
| NEAR Intents | vault swap networks | Astrea bridge | |
|---|---|---|---|
| what vouches for the other chain | a threshold of MPC nodes signing on its behalf | vault signers | a proof of the chain, checked by every validator |
| what the non-Zcash side sees | the swap, settled publicly on NEAR | the swap, in a public vault | the bridge's proxy and a manifest of declared fields |
| the ledger in the middle | public | public | zero-knowledge receipts |
| cryptography | classical secp256k1 and Ed25519 | classical | post-quantum proofs and paired signatures |
| what you trust | fewer than the threshold of nodes collude | fewer than the threshold of signers collude | validators verify proofs; the Zcash key is a threshold key across those same validators, so no second signer set |
NEAR's own description: Chain Signatures are threshold signatures produced by a network of MPC nodes, and the user accepts one trust assumption, that fewer than the threshold of nodes are colluding or compromised at the same time (NEAR Docs, Chain Signatures). Intents are filled by solvers and settled by the verifier contract on NEAR (NEAR Docs, Intents). Vault networks refer to THORChain and Maya Protocol. How the bridge holds its Zcash key is section 05.
The network sees what the ledger hides
A perfectly shielded transaction still has a shape on the network: when it was sent, how large it was, and which machine sent it. Zcash leaves that shape to ordinary gossip. A wallet hands the transaction to a node, the node forwards it to every peer, and the first hop knows where it came from. This is the same broadcast Bitcoin uses, and it has been enough to identify people.
Tramèr, Boneh, PatersonUSENIX Security 2020
"Remote Side-Channel Attacks on Anonymous Transactions". A remote attacker measured how long Zcash nodes took to respond and learned which node was the recipient of a shielded transaction, linking a shielded address to a network address. Monero was affected in the same way. Both projects patched after disclosure; the lesson is that timing alone reached through the cryptography.
Biryukov, Khovratovich, PustogarovCCS 2014
"Deanonymisation of Clients in Bitcoin P2P Network". Bitcoin transactions were linked to the machines that first broadcast them by watching how they spread, even through NAT and firewalls. Zcash inherited the broadcast model this paper attacks.
Kappos, Yousaf, Maller, MeiklejohnUSENIX Security 2018
"An Empirical Analysis of Anonymity in Zcash". Ledger-level timing: deposits into the shielded pool matched with withdrawals of the same value a short time later. The bridge removes this crossing, because a deposit is a shielded transfer; the network route below removes the other half.
Fanti, Venkatakrishnan, Bakshi, Denby, Bhaskar, ViswanathSIGMETRICS 2018
"Dandelion++". The two-phase broadcast Monero adopted in 2020 to blur where a transaction entered the network. Astrea's Dandelion# is a hardened descendant that encrypts the stem and fails closed instead of broadcasting early.
Zcash can run over Tor, and its wallets have started to. Full nodes can route their connections through it, and Zashi 2.1 sends block downloads, broadcasts, and server calls through Tor using Arti, the Tor Project's Rust implementation, funded in part by Zcash Community Grants. That hides a wallet's network address from the server and the relays, and it is worth doing. It does not remove the timing. Tor is a low-latency network with no cover traffic, and its designers state that it does not defend against an observer who can watch both ends of a connection and compare timing. Tor is a transport, not a wallet protocol: it does not know what a Zcash transaction is, so it cannot pad one to a standard shape or hold it for a scheduled release, and a transaction with four actions still looks different from one with two. And the light-wallet protocol tells the server which transactions are yours whatever the route, because a wallet that finds a payment in a compact block fetches that transaction by its identifier to read the memo. Zcash's wallet threat model documents this, and notes that the server can tell when a user received a shielded payment from bandwidth alone. The Zcash Foundation is studying oblivious message retrieval as a fix.
Astrea carries the bridge's traffic through PRISM, a mix route built into the protocol at the transaction level rather than bolted on beside it, and designed to remove the timing signal rather than hide who is sending it. Each relay receives an onion envelope with only its own handoff, so no relay learns both ends. Every packet and every transaction is bucketed into a declared size class, so a two-action transaction and a four-action transaction leave the wallet as the same shape and no packet is a fingerprint. Real packets share a schedule with cover packets, so a wallet that is syncing, broadcasting, or idle produces the same stream. Release is scheduled and jittered, so a transaction does not appear on the network at the moment the owner acted. Routes rotate, so no fixed neighbor set keeps a long view. Requests reach a service over the mix, so the service sees a request arriving from the route rather than from a network address it can name. For actions that will become public, Dandelion# carries them down an encrypted stem before the first broad broadcast, so the first broadcaster is far from the author.
The same route carries an agent's Zcash traffic and its Ethereum traffic, and that is where the bridge reaches beyond Zcash. A VPN puts a tunnel between you and the internet: the website sees the VPN's address instead of yours, and your internet provider sees a tunnel instead of the sites you visit. Astrea does the same for chains. Ethereum sees Astrea's address instead of yours, the network sees shaped traffic instead of your transaction, and the owner's machine appears nowhere. There is one difference. A VPN provider can read everything that passes through its tunnel, while Astrea's validators check zero-knowledge proofs and never see a balance or an identity. Ethereum is the first chain on the other side of the tunnel and ZEC is the first currency that travels through it; any chain whose consensus and state can be proved in can follow.
Tor's scope: Dingledine, Mathewson, and Syverson, "Tor: The Second-Generation Onion Router" (USENIX Security 2004). Zashi's Tor integration: Electric Coin Company, Zashi 2.1. The light-wallet leak: Zcash's wallet app threat model, Hornby, "Fixing Privacy Problems in the Zcash Light Wallet Protocol", and the Zcash Foundation on oblivious message retrieval.
PRISM and Dandelion# are engineered and tested against declared adversaries: a link observer, a relay cohort, and a broad correlator, each named on the privacy page. That evidence is not a mathematical anonymity theorem, and it does not hide the public state change a venue makes on its own chain. Deployment size, traffic volume, and observer reach still matter.
The wallet of the future is an agent
We believe the future of wallets and connectivity is an agent acting under rules its owner set, and that ordinary people will use an agent long before they understand a chain. Nobody outside the field wants to reason about anchors, nullifiers, gas, and bridges. People want to say what they hold, what they are willing to do with it, and what must never happen.
Smart contracts run on ZEC here. A registered computation on Astrea can hold ZEC, move it, escrow it, and settle with it, and every step is a zero-knowledge receipt, so a contract's users see the rules and the result without seeing each other's balances. Contracts that live on Ethereum are reached through the bridge, and the EVM's applications, protocols, markets, and liquidity come with them.
An owner creates an agent and sets its tools, its capital, and its limits. The agent holds ZEC as private capital inside Astrea, runs it through the contracts its strategy needs, reaches an Ethereum market through the bridge, and settles back into the shield, all inside the boundaries the owner drew. Markets see only what they need. The owner does not approve every action and does not expose the strategy to do so. Every action the agent takes leaves a receipt the owner, and anyone the owner chooses, can check.
The private AI that will carry these agents is AxiomAI, Astrea's own desktop app for private chat and code, live today: prompts are encrypted before they leave the device and run only inside attested hardware, and it is where an owner will create an agent, give it tools, and set its authority. The agents page makes the case for agents as the way people will transact, and astrea.systems has the product. This guide covers the infrastructure the agents run on.
Public markets can remain public
Astrea hides the private system behind a transaction: the owner, the agent, the balance, the authority, and the strategy. It does not hide the venue's own state change, which lives on the venue's public chain and should. A private economy needs proof of correctness, not a blackout.
Disclosure in Astrea is the owner's decision, in the same spirit as a Zcash viewing key. An owner can give an auditor, a counterparty, or a regulator a view of exactly the fields they need and nothing beyond them, and the schema makes that grant checkable. Nobody has to prove innocence to use the bridge. Zcash has been legal and listed for nearly a decade under the same principle: the right to use cryptographic tools is defensible, and the benefits of privacy extend well beyond the people who would abuse it.
What this page claims, and what it does not
Confirmation. A deposit is credited after a declared confirmation depth. Zcash is proof of work with 75-second blocks and no cryptographic finality; the Crosslink upgrade adds a finality layer and is not deployed yet. Ethereum state is imported only from finalized beacon-chain checkpoints. Astrea's own consensus carries a machine-checked safety and liveness proof for its consensus core.
Custody. The bridge's reserve stays in Zcash's shielded pool and is never unshielded. Its spending authority is a threshold key generated among the validators, used only for certified withdrawals, with the signing threshold equal to the consensus threshold. Zcash cannot verify Astrea's proofs, so on the Zcash side the guarantee is that signature rather than a proof Zcash checks itself. Validators, as viewing-key holders, learn deposit amounts and times. A deposit is tied to an Astrea account by the commitment in its memo, which the owner opens in zero knowledge, so no validator learns who deposited or who claimed.
Quantum. Astrea's proofs are post-quantum in the primary profile, and its sessions, signatures, PRISM hops, and Dandelion# layers carry classical and post-quantum halves, both mandatory. That protection covers everything from the deposit proof inward. Zcash's note encryption and signatures and Ethereum's beacon-chain signatures are classical today; the bridge checks them as they stand. Zcash's developers have a recoverability plan and the Tachyon design in progress.
Enclave and proof. The bridge's state transitions and results are established by zero-knowledge receipts. Any confidential-computing enclave used by an agent product protects keys and inference on the owner's side and is a separate trust assumption. "Verifiable by construction" refers to the proof.
Maturity. The bridge is a design being built toward a testnet. Nothing on this page reports a public deployment, an audit, or a benchmark.
Further reading
Maxime DesalleJanuary 2026
"Mastering Zcash". The long-form case for Zcash: origins, mechanism, the philosophy of privacy, economics, comparisons, and the road ahead. Quoted on this page in short excerpts; the argument in sections 01 to 03 owes it a debt.
Zcash protocol specificationHopwood, Bowe, Hornby, Wilcox
protocol.pdf. Notes, commitments, nullifiers, the Orchard pool, and the key hierarchy, exactly.
Kappos, Yousaf, Maller, MeiklejohnUSENIX Security 2018
"An Empirical Analysis of Anonymity in Zcash". The boundary heuristics and their figures.
Tramèr, Boneh, PatersonUSENIX Security 2020
"Remote Side-Channel Attacks on Anonymous Transactions". Timing side channels against Zcash and Monero nodes.
ZIP 312Gouvea, Komlo, Connolly
"FROST for Spend Authorization Multisignatures". The threshold-signature construction the bridge's Zcash key uses, with the Orchard ciphersuite on Pallas.
NEAR DocsChain Signatures · Intents
Chain Signatures and NEAR Intents. The MPC signer network and the solver-and-verifier settlement that the comparisons in sections 05 and 06 describe.