ZEC's decade of ups and downs: from a cypherpunk ideal down to $15, then a near hundredfold surge. Behind Zcash's rebirth lies the ultimate comeback of the privacy track.

This article was published on September 21

On the K-line chart, the only two points above $1,500 are just a few centimeters apart on a phone screen, but it took ZEC nearly 10 years to get there.

This "old antique" reached a peak of 25 BTC/ZEC on Bitfinex at launch, and even an absurd 3299.99 BTC/ZEC on Poloniex (a "nominal price" equivalent to over $2 million), back when Bitcoin itself was only around $700.

But that frenzy lasted even less time than today's meme coins. From the sixth day after launch — November 2, 2016 — until before September 14 of this year, ZEC never again went above $1,500.

Just one year before returning to its peak, its price was still hovering around $40.

A decade has passed, and Bitcoin has risen over a hundredfold. EOS came and died, Terra came and blew up, round after round of star projects were lifted onto pedestals, then quietly exited the stage. Meanwhile, some "zombies" from years ago — "great tech, hopeless price" — still hide in the forgotten corners of exchanges, occasionally pulling out a few green candles along with the broader market, then silently falling back.

Among them, Zcash — carrying the prophecies of a group of utopian zealots from last-century America — clawed its way out of the graveyard after hitting an all-time low of under $16 in July 2024, and walked nearly a hundredfold in two years.

In the 1990s, Zooko Wilcox-O'Hearn worked at David Chaum's DigiCash.

The gears of fate began turning the moment Zooko walked through DigiCash's doors. This "blond kid" with long hair in his youth would later become a renowned cryptographer and co-founder of Zcash, and also proposed the famous trilemma known as "Zooko's Triangle": a naming/identifier system in a network protocol cannot simultaneously be memorable, decentralized, and secure.

David Chaum, who founded DigiCash, can be considered the founding father of the cypherpunks. In 1983, he published the paper "Blind Signatures for Untraceable Payments," whose core blind signature technology allows a bank to confirm a payment without knowing what you bought. Six years after the paper's publication, Chaum founded DigiCash, launching eCash — the first truly meaningful "digital cash" in human history — on one hand, while helping traditional banks with private payments on the other.

On May 27, 1994, DigiCash processed the first real electronic cash transaction. Afterward, banks including Mark Twain Bank, Deutsche Bank, and Credit Suisse adopted the technology to experiment with small anonymous payments, and at its peak thousands of users and hundreds of merchants participated in the experiment.

But this creation, which predated Bitcoin by 20 years, was simply too far ahead of its time — so far ahead that a market that could barely even handle credit cards couldn't absorb it. On the day the company went bankrupt in 1998, Zooko was there. That seed stayed buried in his heart for nearly two decades.

After DigiCash shut down, Zooko didn't give up. He turned to MojoNation, a decentralized network where strangers rented out hard drives and bandwidth to each other, with a circulating token called Mojo. Naturally, this project also ended in failure, but Zooko's direction of faith never changed: he wanted a digital cash that no one could watch over.

When Bitcoin's mainnet officially launched in 2009, Zooko was among the earliest to champion it. But once the excitement wore off, he spotted a fatal flaw: Bitcoin's ledger is completely public, and anyone can see how much money is in your wallet and who you've done business with.

Bitcoin was a better eCash, but still not the perfect currency in Zooko's mind.

The cryptography world, like Zooko, was constantly searching for the "perfect" answer.

In 2013, cryptographers at Johns Hopkins University proposed the Zerocoin protocol, which evolved into the Zerocash paper the following year. The core of the paper was the zk-SNARKs algorithm — now mentioned and used countless times across the Web3 industry — which for the first time moved "everyone can verify a transaction is valid, yet no one knows its contents" from theory into practice.

The concept of zero-knowledge proofs was not first proposed by Zerocash, but Zerocash was the first design that could truly achieve both decentralization and end-to-end encrypted privacy in practice. Zooko later said in multiple interviews that he was "extremely excited" when he saw the paper. In 2015, Zooko brought the paper's authors together to found the Zerocoin Electric Coin Company, later renamed Electric Coin Company — the ECC that now operates Zcash.

Silicon Valley investor Naval Ravikant signed a $715,000 check when the company was founded. In subsequent funding rounds, 17 investors pooled roughly $3 million, including Barry Silbert of Digital Currency Group and Pantera.

Everything was in place, and Zcash's mainnet launch entered its countdown. Zooko and ECC prepared the most ceremonial "opening ceremony" in crypto history for Zcash's debut.

zk-SNARKs requires a set of public parameters, and the process of generating them produces a kind of "toxic waste" — whoever gets hold of it can silently mint coins out of thin air. You can think of these parameters as Zcash's "initial password": whoever holds the password can forge zero-knowledge proofs to inflate the supply or double-spend ZEC — in short, do whatever they want on the chain.

On launch day, a total of six people participated in Zcash's parameter generation ceremony. The three who were publicly identified included Zooko himself, Zcash technical advisor Andrew Miller, and Coin Center research director Peter Van Valkenburgh. To guard against targeted attacks, Zooko also invited three anonymous individuals.

The participant under the pseudonym Moses Spears was later revealed to be Derek Hinch, a security engineer at NCC Group, which was secretly hired to both honestly execute the ceremony and attempt to "attack" it from within as a security verification. The participant under the pseudonym Fabrice Renault was later revealed to be Bitcoin Core developer Peter Todd, whom Zooko specifically invited because he was skeptical of the entire ceremony at the time. Zooko believed that having a critic participate personally would actually increase credibility.

As for the last anonymous participant, John Dobbertin, his identity was not revealed until 2022, six years later.

In October 2016, six people spread across three continents worked in relay from a distance, each using a physically isolated computer to generate their portion of the parameters, then destroying the random numbers along with the hardware once done. Some wrapped their machines in electromagnetic shielding to prevent signal leakage; some simply set the computers on fire. As long as one of the six was honest, as long as one of the six sets of parameters was destroyed, Zcash's ZK system would be secure.

On October 28, 2016, Zcash's mainnet launched. In terms of economic model, Zcash almost copied Bitcoin wholesale: a total supply of 21 million, halving roughly every four years. Even because Zcash's average block time is two and a half minutes, the block reward was also designed at 12.5 ZEC. But to reduce early risk, Zcash chose to have the block reward ramp up linearly to 12.5 ZEC over the first 20,000 blocks.

Because of the slow-start mechanism, ZEC in circulation was pitifully scarce, and the price was bid up to absurd heights. As supply was released, the price halved and halved again within days, falling below $50 by early 2017. Beyond the "no supply," the ECC team also smuggled in a "private agenda": for the first four years, 20% of each block's reward went directly to the founding team, employees, advisors, and early shareholders — 2.1 million coins over four years, a full 10% of the total supply.

In the days when ZEC's price climbed back into four figures, F2Pool co-founder Wang Chun posted on X a chat record from six years earlier showing Zcash members confusing E