Zero
Launch assets into Zcash's shielded economy. Every asset is born with an Asset ID, proven with Halo 2 and rooted in a ZEC reserve.
The protocol underneath.
Custom assets on Zcash are specified in ZIP 226 and ZIP 227, and the circuit that carries them is being built in the official Orchard repo right now.
Add ZSA circuit
The Orchard repo is Zcash's implementation of its modern shielded protocol. This pull request adds the ZSA circuit: the proving logic that lets custom assets move inside the shielded pool.
Transfer and Burn of Zcash Shielded Assets
Defines OrchardZSA: an extension of the Orchard protocol that enables the issuance, transfer and burn of custom assets on the Zcash chain.
Issuance of Zcash Shielded Assets
Defines how custom assets are created. Every asset gets a globally unique Asset ID, and issuance is transparent so supply can be tracked.
AssetId := (issuer, assetDescHash) MAX_ISSUE := 2^64 − 1 finalize → no more supply, ever
Where shielded ZEC lives today.
Ironwood went live on 28 July 2026 with NU6.3 at block 3,428,143. It runs the same Orchard protocol, now formally verified, after a flaw was found in the original pool's circuit in May. The original Orchard pool is closed to new deposits and funds leave it through a turnstile. The Orchard protocol, and PR #546 with it, carries Zcash's shielded future. Block 3,508,470.
What the ZSA circuit changes, file by file.
Notes, value commitments and the Action circuit are now parameterised by an asset type. A new ZSA circuit sits beside the current one, now called Vanilla internally. Each row links to the diff.
See the 14 files, line by line +
src/note/asset_base.rsnew+82New AssetBase type: the point that says which asset a note holds.Asset ID + DNA on every card
src/note.rs+140 −7Notes gain an asset field and rseed_split_note.Note stream: every note names its asset
src/note/commitment.rs+58 −17NoteCommitment::derive now takes the asset.Commitment tree leaves (cmx)
src/note/nullifier.rs+14 −3Nullifier::derive takes is_split_note, offset by a fixed point.Nullifier set + feed
src/constants/nullifier_l.rsnew+44That fixed point, L, for split-note nullifiers.Nullifier set
src/constants/zatoshi_asset_base.rsnew+49ZEC's own asset base: zatoshi is the native asset.The ZEC root
src/value.rs+13 −4ValueCommitment::derive_with_asset binds value to an asset.Per-asset reserves in the root map
src/circuit/value_commit_orchard.rsnew+391In-circuit value commitment with the asset as base point.Per-asset reserves
src/circuit/note_commit.rs+1,120 −147Note commitment gadget evaluated per asset (zatoshi or not).Commitment tree
src/circuit/circuit_zsa.rsnew+1,685The ZSA Action circuit, beside the current one (now "Vanilla").Proof monitor
src/circuit_version.rsnew+61OrchardCircuitVersion: Vanilla or ZSA, each with its own proof size.Proof monitor · terminal zsa
src/bundle.rs+89 −24A zsa_enabled flag in bundle Flags.Waits for NU7
src/builder.rs+39 −6split_flag on spends, asset on outputs. Still pinned to zatoshi for now.Genesis + launch
src/circuit_data/circuit_description_zsanew+28,969The fixed description of the ZSA circuit: most of the PR's line count.Proof monitor
How our tech lines up with ZSAs.
Every part of the Orchard maps to a section of ZIP 226 or ZIP 227 and to the code in zcash/orchard.
note/asset_base.rsnote.rs · Note.assetNoteCommitment::derive(asset)Nullifier::derive(is_split_note)ValueCommitment::derive_with_assetcircuit/circuit_zsa.rsissued_assets.finalIssuance bundleZIP 317 changesnext PRFlags.zsa_enabledzcashd · librustzcash · orchardDerive an Asset ID yourself.
Type an asset description and the Orchard runs ZIP 227 step by step: a BIP-340 issuer key, a BLAKE2b hash of the description, the encoded Asset ID and its Asset Digest. Copy the Python and check every byte.
The fingerprint beside it is the asset's DNA: 64 nibbles of the Asset Digest set the grid, 32 bytes set the bars. Same ID, same DNA. A fingerprint you can't design.
—issuance authorizing key · secret—BIP-340 PubKey(isk) · secp256k1—0x00 || ik—BLAKE2b-256 · "ZSA-AssetDescCRH"—0x00 || issuer || assetDescHash—BLAKE2b-512 · "ZSA-Asset-Digest"GroupHashP("z.cash:OrchardZSA", AssetDigest)the Pallas point stored in each noteZEC stays the root. The spec says so.
ZIP 227 keeps ZEC as the token that pays every ZSA fee, "similar to how ETH is needed for ERC20 transactions". Fees in a custom asset were considered and dropped, because lifting value out of a shielded transaction would leak information about it.
That is the Orchard's model: many assets bloom, one asset is the root.
Launch today. Native with NU7.
Launch on pump.fun, paired with ZEC
Coins launch from your own wallet. Zero computes each coin's ZIP 227 asset description hash and writes the ZEC pairing into its description.
Launch a seed →The ZSA circuit in zcash/orchard
PR #546 parameterises notes, commitments and value commitments by asset and adds the ZSA circuit, with the builder still pinned to zatoshi.
Read the PR ↗Zcash Shielded Assets activate
ZIP 226 schedules ZSAs for Network Upgrade 7: issuance, transfer and burn of custom assets inside the shielded pool, with fees in ZEC.
ZIP 226 ↗Every asset is a branch rooted into ZEC.
Branches carry notes, notes become actions, actions settle as proofs. New launches sprout at the top.
Created, spent, nullified. Then the next one.
Values never leave the pool. All the network sees is a commitment going in and a nullifier coming out.
- 01Note createdA commitment (cmx) is appended to the Orchard tree. Value stays shielded.
- 02Action executedOne Orchard action spends an old note and creates a new one under a single proof.
- 03Nullifier consumedThe spent note's nullifier is published. Same note, never again.
$GHOST
halo2 · pallas/vesta · no trusted setup · 0 verified
Every note is a leaf. The root is the anchor.
Launch a seed.
Zero derives an Asset ID, issues a final supply, generates the proof and roots the asset in a ZEC reserve. Then it grows. To launch a real coin on pump.fun, paired with ZEC, launch a seed →
- Asset ID derived
- Final supply issued
- Proof generated
- Shielded market open
- Notes flowing
- Nullifiers consumed
- Inner orbit
- Deepest root in ZEC
- Top of the root map
Whatever blooms above, the roots are ZEC.
Every market reaches down into one layer.
Technical cards, not memecoin cards.
Inspect the Orchard from a prompt.
Read any asset's state, verify a proof, list the nullifier set or run a genesis. Tap a step to open it in the terminal.
