Altcoins

How Much Zcash (ZEC) Do You Need? The Supply Math, the Trusted Setup, and the Real Risks

Is Zcash's 21 million supply real? The founders' reward, the 'toxic waste' key ceremony, the hidden 2018 counterfeiting bug, and how to check supply yourself.

Video: ZCASH: HOW MUCH ZEC DO YOU NEED? THE HONEST MATH DEPENDED ON A KEY 6 PEOPLE HAD TO DESTROY

Key takeaways

  • Zcash has a 21 million cap like Bitcoin. As of September 30, 2026, about 16.96 million ZEC existed, roughly 81% of the total.
  • For its first four years, 20% of new coins went to founders, investors, staff and advisers. Since 2020, 20% of each block has gone to development funds.
  • Zcash's early privacy relied on a secret key that six ceremony participants had to destroy. One was Edward Snowden, under a pseudonym.
  • A 2018 bug could have allowed unlimited counterfeiting. The company fixed it quietly and disclosed it 11 months later.
  • Before buying, check three things: supply against schedule, the public pool balances ('turnstile'), and where your coins sit.

21 million. That’s the number every Zcash holder is told, the same cap as Bitcoin. But for years that number depended on a promise: someone created a secret key and swore they destroyed it. Anyone who kept a copy could have printed Zcash nobody would ever see.

So before asking “how much Zcash do I need?”, there’s a more honest question: how many are there, really?

The supply schedule

Zcash launched on October 28, 2016. Once up to speed, it created 12.5 new coins every 2.5 minutes, paid to the miners securing the network. Roughly every four years that amount halves. The second halving was November 23, 2024; since then a block arrives every 75 seconds and pays 1.5625 ZEC.

As of September 30, 2026, there were 16,961,468 ZEC in existence, about 81% of everything that will ever exist.

Who got the coins

The first question for any new coin isn’t how many, it’s who got them.

Zcash cloned Bitcoin’s schedule with one change, as co-founder Zooko Wilcox described it: instead of all new coins going to miners, a share went to the founders. For the first four years, 20% of every new coin went to founders, investors, staff and advisers. Zooko said his own share was less than 1%; most went to others.

When the founders’ reward ended in November 2020, 20% of every block kept flowing elsewhere:

  • 2020 to 2024: a dev fund split between the company that built Zcash (7%), the Zcash Foundation (5%) and grants (8%).
  • Since November 2024: 8% to a grants committee and 12% into a locked pot. On November 24, 2025, that pot paid out 78,750 ZEC in one go to a wallet controlled by three organizations, where any two can sign.

Those are a lot of coins collected to fund development, and they could be sold at any time.

The honest math

Forget the price; the math doesn’t change.

ZEC held Share of the 21M eventual supply
1 1 / 21,000,000
21 one-millionth
210 one hundred-thousandth

If someone says “1,000 ZEC will make you a millionaire,” check it: that needs $1,000 per coin, which means the whole network must be worth $21 billion. Maybe it gets there, maybe it doesn’t, but now you know what you’re betting on.

Every one of those numbers assumes the 21 million is real. For years, that rested on a key six people had to destroy.

The “toxic waste” key ceremony

Zcash can hide who paid whom and how much. To do that, its original system needed a giant secret number built at the start. Think of it as a mint’s printing plate: whoever keeps it can keep printing money. Zooko’s own 2016 post called the private key “the toxic waste,” and explained the danger: Bitcoin can catch counterfeits because every payment is public, but Zcash hides amounts, so it risks losing that ability.

So the plate had to be destroyed. The ceremony used multi-party computation: six participants in separate, undisclosed locations each held one piece. If even one destroyed their piece, the key could never be rebuilt. All six would have had to be dishonest or hacked.

It’s a strong design, but Zooko wrote before launch that there was no way to prove they really did what they said. And one participant used a fake name. In April 2022, Edward Snowden revealed on camera that he had taken part under the pseudonym “John Dobbertin.”

The bug they kept secret

The ceremony turned out not to be the real danger. The math was.

On March 1, 2018, Zcash company scientist Ariel Gabizon found a flaw that could have let someone turn a transaction spending a tenth of a coin into one spending a billion: unlimited, invisible counterfeiting.

They didn’t tell the public. The company’s own disclosure says it kept the bug secret, even from its own engineers, to prevent exploitation and give other affected projects time to fix it, and maintained a cover story about a missing file. It was patched quietly on October 28, 2018 and disclosed on February 5, 2019, 11 months after discovery.

The company says it found no sign the bug was used: “We found no such footprint.” You’re allowed to doubt a company grading its own homework. So here’s a check that doesn’t require trusting them.

The turnstile: checking supply yourself

Zcash keeps a running total of how many coins sit inside each private pool, and the rule says that total can never go below zero. Any block that would push it negative is rejected by every computer on the network. So even if someone had printed fake coins inside a pool, they could never withdraw more than honestly went in. Total supply can’t quietly exceed 21 million.

In May 2020, researcher Sean Bowe’s technique went live in a new private pool called Orchard that needs no secret key at all.

But it isn’t bulletproof. On May 29, 2026, an outside researcher found a flaw in Orchard’s math. The pool was switched off for about a day and fixed in an emergency upgrade on June 3. Zcash says there’s no evidence it was used and total supply was unaffected, but its own post says the flaw could have permitted double-spending within Orchard. The turnstile protects the 21 million. It doesn’t protect honest users inside an affected pool.

How private is Zcash, really?

Shielded addresses reveal nothing about amounts or counterparties; transparent addresses are as public as Bitcoin. As of September 30, 2026, a public dashboard put about 29% of ZEC in shielded pools. The other 71% sits in the open.

And private isn’t untouchable. US authorities have seized Zcash and Monero, not by breaking the math, but by getting hold of the people and their keys.

Three numbers to check before you buy

  1. Supply vs. schedule. On September 30, 2026, the schedule called for about 16,961,837 ZEC; the dashboard showed 16,961,468. Under, not over.
  2. Pool balances. They’re public, and they’re why you no longer have to trust six strangers.
  3. Where your coins sit. A shielded pool, a transparent address, or an exchange that holds them for you and sees everything.

The six people and the secret key were the story everyone told. The number that matters was on a public page the whole time.

Frequently asked questions

How many Zcash coins are there?

Zcash is capped at 21 million ZEC. As of September 30, 2026, about 16,961,468 ZEC existed, close to the roughly 16,961,837 the issuance schedule called for. That's under the schedule, not over.

How much ZEC do you need to own a meaningful share?

One ZEC is 1/21,000,000 of the eventual supply. 21 ZEC is one-millionth, and 210 ZEC is one hundred-thousandth. Claims like '1,000 ZEC makes you a millionaire' assume a $1,000 price, which implies a $21 billion network value.

What was the Zcash trusted setup?

Zcash's original privacy system needed a secret number created at launch. Whoever kept it could have counterfeited ZEC undetectably, so six participants in separate locations each generated a piece and destroyed it. If any one of them destroyed theirs, the key could never be rebuilt.

Has anyone counterfeited Zcash?

The Zcash company says it found no evidence the 2018 bug was exploited. Independently, Zcash's 'turnstile' rule tracks how many coins are in each private pool and rejects any block that would push a pool below zero, so counterfeit coins couldn't be withdrawn beyond what honestly went in.

Is Zcash fully private?

Only shielded transactions are. As of September 30, 2026, a public dashboard put about 29% of ZEC in shielded pools; the rest sits at transparent addresses, as traceable as Bitcoin.

Education and commentary only, not financial advice. Crypto is volatile and you can lose money. Do your own research and speak to a qualified advisor before making investment decisions. Figures and quotes are as reported in the video on October 4, 2026 and may have changed since.