Can the supply of shielded zcash be verified?

How about the effect of past bugs on the shielded supply?

Reply to this note

Please Login to reply.

Discussion

There are currently three different shielded pools (basically three iterations of the zero-knowledge proof tech) and only the first one had a possible inflation bug.

You cannot audit the inside of a shielded pool, that’s not compatible with the privacy guarantees.

However, each pool has a so called turnstile mechanism which ensures that there are never more coins leaving the pool than coins that have entered it.

The bug in the first pool was fixed in 2018 and given how long ago that was and how little coins still remain in the pool it is very unlikely that the bug has ever been exploited. There is additional evidence that it hasn’t, which I’m sure you can easily find.

The latest iteration (the Orchard pool) also doesn’t have a trusted setup anymore.