A coinholder-governed future for Zcash
We have been around Zcash since before the genesis block in 2016 and we are strongly pro-Dev-Fund. We don't want the Dev Fund abolished. We don't want it slowly strangled because somebody decides there is already "enough development." We don't want Zcash to stop progressing and ossify. We want to accumulate an enormous Zcash development fund that is issued thriftily, iteratively, granularly, and with onchain protocol(s) as much as possible.
Zcash has an enormous amount of work left to do.
Cryptography. Scalability. Wallets. Better synchronization. Hardware support. User interfaces. Developer tooling. Documentation. Markets. Merchant tooling. Private DeFi. Cross-chain infrastructure. Security. Quantum resistance. AI-agent payments. Education. Outreach. Protocol research. Things we have not even imagined yet.
No corporation, nonprofit, committee, founder, board or collection of well-connected individuals should have a hereditary right to some percentage of Zcash issuance. The Dev Fund should belong to Zcash itself. And ultimately, decisions about its use should flow from ZEC holders.
Zcash was built with the Dev Fund
Let's begin by acknowledging something that sometimes gets lost in Dev Fund debates. Zcash did not emerge fully formed from the forehead of Satoshi Nakamoto or any of the founders or all-star engineers or cryptographers. People who made a living from the Dev Fund built Zcash. Researchers invented new cryptography. Engineers implemented it. Security researchers broke things before attackers could. Wallet developers struggled through difficult integration problems. Designers worked on making privacy usable. Infrastructure operators kept things running. Educators explained a genuinely complicated system to new people. Was all of this paid for with the Dev Fund? Serious question. If someone has an example of work that pushed Zcash along that was not paid for from the Dev Fund, I'd love to hear these counterexamples. From our recollection, nothing significant happened that was not funded or incentivized by the Dev Fund.
History Lesson
From Zcash's launch in 2016 through the first halving, 20% of block issuance went to the "Founders' Reward." Over its lifetime that represented 2.1 million ZEC, or 10% of the eventual 21 million supply. When that mechanism expired, Zcash was nowhere near finished. So, a new funding mechanism was created. ZIP 1014 established a new Dev Fund beginning with Canopy in 2020. Twenty percent of block rewards continued supporting development: 7% of total block rewards went to Bootstrap/ECC, 5% to the Zcash Foundation and 8% to Major Grants, which became Zcash Community Grants.
Without ZIP-1014 Dev Fund, the Zcash story would almost certainly have ended there with a whimper. But instead, with this source of funding, the supported organizations produced Halo, Orchard, Unified Addresses and NU5. NU5 eliminated the trusted setup for the new Orchard pool and dramatically changed the cryptographic foundation on which future Zcash development could proceed.
The Zcash Foundation built Zebra from scratch as an independent, consensus-compatible Rust implementation of a Zcash node and developed FROST threshold-signature tooling.
Community grants funded independent development: Zaino, Ledger shielded support, Zcash Shielded Assets work, wallet infrastructure, libraries, security audits, media, education, integrations, regional communities and scores of other efforts.
It is impossible to rerun history without the Dev Fund and see what the counterfactual Zcash looks like.
But my view is simple: Zcash as we know it would not exist without sustained funding for people who work on Zcash. When we hear "end the Dev Fund," we think that solves the wrong problem. The problem was never that development got funded. The problem with the ZIP-1014 Dev Fund was how it made just two US corporations dependent on continuously liquidating Zcash.
The worst mistake was confusing organizations with public goods
ZIP 1014 was an important advance over the Founders' Reward. But it retained a structural mistake. Certain organizations received ZEC automatically because the consensus rules named them as recipients. That is very different from saying:
Here is a reserve belonging to the Zcash ecosystem. Come convince ZEC holders that what you are doing deserves some of it.
ECC did important work. ZF did important work. ZCG funded important work. That doesn't mean ECC, ZF, ZCG, or anybody else should possess an eternal protocol-level entitlement. Organizations have payroll. Management. Benefits. Lawyers. HR. Contractors. Travel. Infrastructure. Administrative expenses. Those things can be perfectly legitimate expenses. The question was whether Zcash consensus should automatically fund an organization, or whether Zcash should fund work that ZEC holders repeatedly choose to support.
The lockbox was a major conceptual breakthrough
The post-2024 funding debate produced one of the best ideas in Zcash governance so far:
Don't immediately give all newly issued Dev Fund ZEC to somebody. Put it somewhere. Wait. Make spending it a separate decision. ZIP 1015 directed 12% of block rewards into a deferred funding pool, the lockbox, and preserved 8% for Zcash Community Grants. NU6.1 took the next step. The current Community and Coinholder Funding Model directs 12% toward a coinholder-controlled fund and 8% toward ZCG through the third halving. Good! Let that reserve become enormous.
There is nothing wrong with Zcash possessing a massive development treasury. The virtue of the lockbox is not that we eventually figure out which organization deserves to control it. The virtue is that nobody controls it by default.
Going Forward
Fairly easy to petition. Hard to spend.
This is the principle we would build around: It should be fairly easy for anyone with genuine skin in the game to ask Zcash for money and difficult to actually get it. Fairly easy does not mean frictionless. A completely free proposal system could become unusable almost immediately. Millions of spam proposals are not decentralization; too many would be a burden and ultimately a denial of service. So there should be a some economic hurdle to making an ask. Some ideas:
- Prove ownership of some ZEC
- Put some ZEC (% of request?) in escrow while voting takes place
Maybe there is a refundable proposal bond. Maybe part of it gets burned if a proposal is obvious spam. Maybe the amount scales slightly with the requested funding. We don't know the perfect mechanism.
We should experiment.
The principle is what matters:
Anyone with some real economic connection to Zcash should be able to petition the treasury, but flooding the system with garbage should cost something.
No committee should decide whether you are socially important enough to submit an idea. But neither should creating 100,000 meaningless proposals be free. Permissionless does not have to mean frictionless.
Cap the size of individual asks
Put a hard limit on individual asks. Suppose the maximum ordinary proposal is one one-thousandth of the coinholder reserve. At a 142,000-ZEC reserve, that would mean roughly 142 ZEC. That is serious money. But one proposal cannot drain the treasury. Maybe the appropriate denominator is 1/500 or 1/200. Maybe the cap should react to treasury size, volatility or voting participation. Again: Iterate.
The essential principle is that funding should be granular. If you need much more money, come back.
Granularity changes everything
Imagine that a world-class cryptographer wants to spend the next year working full time on a difficult Zcash problem. Great! Don't necessarily give an organization $3 million and hope for the best. The cryptographer can ask for 30 or 50 ZEC this month. Coinholders approve it. Next month the cryptographer comes back. Here is what I did. Here is the code. Here is the research. Here are the benchmarks. Here is what I learned. Here is what I intend to do next.
Another proposal appears.
Coinholders vote again. If the work is brilliant, keep funding it. Maybe increase the amount. If the work becomes irrelevant, stop. If somebody else has a better approach, fund that person too. If both approaches seem worthwhile, fund both. The default becomes continuous experimentation rather than institutional permanence.
The same thing works for teams. A team might ask for 100 ZEC for a development sprint. Ship. Ask again. Ship. Ask again.
The treasury becomes something like an enormous decentralized customer continuously purchasing improvements to Zcash. Funding is not employment tenure. Funding is a stream of independently revocable decisions.
Nobody gets a four-year blank check
We don't want Zcash deciding every four years which aristocrats receive newly issued money for the next four years. We want a continuous market for contribution. That means there should be no presumption of renewal. A successful grant does not create an entitlement to the next one. Each tranche stands on its own. And silence should never be approval. If a proposal does not achieve the required participation and affirmative support, nothing happens. The ZEC stays in the reserve. That makes the system naturally thrifty.
We don't need a committee whose job is to "save money." The protocol simply starts from: Don't spend. Someone who wants to change that state must persuade holders.
Coinholder Republic
This isn't one-person-one-vote democracy. Zcash doesn't have citizens; it has coins. What we are describing is explicitly coin-weighted governance. One ZEC, one unit of voting weight. We can start there. People who own ZEC have direct exposure to the consequences of decisions that increase or destroy the usefulness and value of the network. That doesn't make them omniscient. It doesn't guarantee good decisions. It doesn't eliminate politics, campaigning, stupidity, fashion, tribalism, lobbying, custodial concentration or attempted capture. Nothing can. But, coin-weighted voting connects authority to an objectively measurable stake inside the system instead of an invitation to a mailing list, appointment to a nonprofit board, attendance at the right conferences, friendship with the right people, or participation in some vaguely defined off-chain "community."
The emerging coinholder-grant experiments show that holders can discriminate among proposals. Fund this. Don't fund that. Come back later. Try again for less. Prove it. That is exactly what a treasury needs.
Coin-weighting creates its own attack surface
We should also be intellectually honest about the weakness of pure coin-weighted governance. What happens if a tiny number of enormous holders coordinate? What happens if an exchange votes custodial coins? What happens if voting power can be temporarily borrowed? What happens if someone accumulates enough ZEC specifically to extract a much larger amount from the treasury?
The simplistic answer is: "Coinholders voted. Therefore it is legitimate." We don't need to be that doctrinaire. Governance is security engineering. You assume somebody will eventually try to break it. The treasury should therefore have defense in depth.
Maybe Zcash needs a Zenate and maybe it only gets a veto
Here is one possibility we could deliberately leave open. Suppose ZEC holders elect a relatively large body - a Senate, council, assembly, whatever we eventually call it. Its job would not be to decide who gets money. It couldn't award itself grants. It couldn't redirect the Dev Fund. It couldn't substitute its preferences for ordinary coinholder votes. But perhaps it has one narrowly defined emergency power: A supermajority, say two-thirds, can veto an obviously malicious treasury extraction. That would give the Zcash Dev Treasury a circuit breaker. Imagine five enormous holders suddenly coordinate to approve a giant sequence of grants to themselves. Coin-weighting alone may technically authorize it. A broad, separately selected body could have the ability to say: "No. Something abnormal is happening. Stop. Investigate." That is very different from handing a small committee control of the treasury. The Senate cannot spend. It can only stop spending under extraordinary circumstances. And even that power should probably be constrained.
Maybe this "Senate" turns out to be unnecessary. Maybe good proposal caps and economic game theory make treasury capture prohibitively expensive. Maybe another mechanism works much better. This is a spitball idea that comes from thinking about pure coin-weighted voting adversarially. But, perhaps we should not prematurely rule out hybrid governance and emergency brakes simply because we like the elegance of pure coinholder voting.
A secure system often has multiple independent mechanisms that must fail before catastrophe occurs.
Sovereignty does not require absolutism
This is an important distinction. Saying that authority should ultimately derive from ZEC holders does not mean every governance action must be a raw instantaneous token vote with no checks whatsoever.
Republics have constitutions. Corporations have boards and shareholder votes. Blockchains use multisigs, timelocks, threshold signatures and emergency mechanisms precisely because different layers of authority can protect against different failures.
Zcash governance could combine: coinholder sovereignty, expert delegation, economic friction, spending caps, time delays and narrowly bounded veto powers. What matters is that none of those secondary institutions become sovereign themselves. The Zenate should not own Zcash. ZF should not own Zcash. ECC should not own Zcash. ZCG should not own Zcash. Whales should not own Zcash merely because they happen to possess the biggest voting bloc this afternoon. Governance should be a system of checks that ultimately serves Zcash holders and the protocol.
Private coinholder governance is getting real
For years, objections to coinholder voting were partly technical. How do shielded holders vote without revealing their balances? How do we prevent double voting? How do we produce auditable results? How do wallets support the process? Those are legitimate questions. And Zcash is increasingly answering them with software. The new coinholder-voting work demonstrates that private voting from shielded ZEC with auditable aggregate outcomes is increasingly practical. That is remarkable! We should keep iterating and not decree that today's mechanism is perfect forever.
Iterate! That itself should be a fundamental principle of Zcash governance.
Do not ossify governance either
Cryptocurrency culture sometimes treats immutability as synonymous with virtue. For monetary ownership rules, predictability is extremely important. For human governance mechanisms, freezing the first version forever is probably goofy. We should expect Zcash governance in 2030 to be better than Zcash governance in 2026. Maybe direct voting works wonderfully for some classes of grants and poorly for others.
Maybe coinholders eventually elect specialized councils. Maybe holders delegate their votes to cryptographers for cryptography proposals, wallet experts for wallet proposals and economists for monetary proposals. Maybe those delegations are private, revocable and expire automatically. Maybe elected councils can approve tiny expenditures while anything above a threshold requires direct coinholder ratification. Maybe a large elected Senate exists solely as an emergency veto. Maybe it doesn't. Maybe proposal bonds need adjustment. Maybe one-one-thousandth is too large. Maybe it is too small. Maybe we discover better defenses against borrowed voting power or custodial concentration. Change it.
The purpose of a constitution should not be to specify every future decision. It should be to make peaceful iterative improvement possible.
Representatives can exist without becoming aristocrats
Direct coinholder voting does not require every holder to become a cryptographer, UX expert, security auditor and marketing specialist. Representation can exist.
Coinholders might elect a cryptography council, or a wallet council, or a security council, or a small-grants council, or a large body whose only meaningful power is stopping an attempted raid on the treasury. Those bodies can investigate proposals, publish recommendations and perhaps administer narrowly bounded budgets. The crucial distinction is where their authority originates and how it ends. They should not own a percentage of issuance. They should receive a limited, revocable mandate. A republic, not an aristocracy.
And whenever feasible, the authority chain should be visible and enforceable on-chain.
The treasury should create a mad rush to improve Zcash
Think about the incentive this creates.
Imagine the message to every cryptographer, programmer, designer and entrepreneur in the world:
If you can demonstrably make Zcash better, there is an enormous reserve of ZEC here, and you are allowed to ask its owners to pay you. No VC introduction required. No employment interview at the blessed corporation. No need to convince the five people currently sitting on a committee that you fit their vision.
Own a little ZEC. Put up a little earnest money. Make your case. Build something. Explain it. Petition coinholders. Get funded. Do great work. Come back. Get funded again.
That is extraordinarily powerful.
We could see thousands of extremely talented people earning a living working for Zcash. We want independent cryptographers competing to make our proving systems better. Independent teams competing to build the best wallet. People obsessing over sync performance. People building merchant systems. Designers making privacy understandable to normal humans. Researchers attacking quantum migration. Engineers experimenting with scalability. People building payment rails for AI agents. Hardware people (who's working on the zPhone, btw?). Markets people. Security people. Documentation folks. Educators. Artists. Local communities.
Things no one has thought of yet.
The Dev Fund can turn Zcash itself into an economic engine for producing Zcash improvements.
This is better than surrendering the ecosystem to VC
There is another path. We can decide protocol funding is somehow impure. Stop doing it. Then every serious Zcash project goes looking for venture capital.
And what happens?
The people with large pools of traditional capital determine what gets built. They demand equity. They demand tokens. They demand control. They demand returns. Suddenly we eliminated the allegedly dangerous "tax" on Zcash issuance only to make the ecosystem dependent on traditional concentrations of capital. That seems backward.
VC has a role. Private businesses have a role. Equity has a role.
But public infrastructure is different. Cryptographic research is different. Open-source wallets are different. Protocol maintenance is different. Documentation is different. Security work is different.
Some of the most valuable things for Zcash will never make sense as venture-backed companies. The Dev Fund lets Zcash finance public goods without pretending every public good needs a cap table.
The anti-Dev-Fund argument mistakes thrift for starvation
We absolutely should be thrifty. That is why we want a lockbox, proposal friction, small tranches, independent renewals, affirmative voting, circuit breakers against capture.
That is why the default state should always be: Funds remain untouched.
But thrift is not the same as starvation. It would be incredibly shortsighted to look at Zcash today and conclude that the important work is basically finished. We are entering an era of extraordinarily rapid technological change. AI is changing software development and the nature of economic agents. Quantum computing forces cryptographic systems to think decades ahead. Zero-knowledge cryptography itself continues advancing. Scalability remains an open frontier. Privacy remains difficult. Usability remains difficult.
Global private electronic cash remains an unsolved problem.
We haven't finished Zcash. We're barely getting started.
No sacred organizations
We don't want Digital Currency Group, Gemini, venture capital, miners, ECC, the Zcash Foundation, Free2Z, five whales, or some new organization we invent in 2027 to control Zcash. All of these people and organizations can contribute, make proposals, persuade coinholders, and receive funding. None of them should have a permanent claim on protocol issuance.
Fund people generously. Entitle nobody.
The current experiment is already pointing this way
This isn't a proposal to discard what Zcash has built. Quite the opposite. The lockbox introduced deferred funding, coinholder-directed grants gave holders a direct role, and real votes have begun exposing both the strengths and weaknesses of these mechanisms.
That is exactly how governance should evolve. If a voting mechanism proves weak, improve it. If proposal volume becomes overwhelming, add economic friction. If participation is too low, experiment with delegation. If whale capture becomes a serious threat, add safeguards. If an emergency veto itself becomes a source of capture, constrain it or remove it.
We should not expect to write the perfect constitution once. We should build, observe, fix, and iterate.
Where we should go next
We can move to the entire Dev Fund accumulating into a common reserve, with no organization receiving an automatic percentage.
The reserve should be difficult to drain but reasonably easy for someone with genuine Zcash stake to petition. Proposal submission should require modest economic friction: proof of ZEC ownership, a bond, escrowed earnest money, or some similar anti-spam mechanism. Ordinary asks should be capped at a small fraction of the reserve, perhaps around one one-thousandth, and funding should generally occur in short, independently authorized tranches. Large projects can still receive large amounts, but they should earn continued support over time rather than receive enormous irrevocable grants upfront.
Voting should be private, coin-weighted, and auditable. If participation or approval thresholds are not met, the money stays put. Representatives and expert councils may have a role, but their authority should be bounded, revocable, and ultimately derived from coinholder governance.
We might also leave room for an emergency safeguard against an obvious treasury attack. A large, independently constituted body might have a narrowly defined supermajority veto - a circuit breaker, not a spending authority. Maybe we ultimately need such a mechanism; maybe we don't. The point is to preserve room to adapt as we learn.
Above all, the money belongs to Zcash. Not to ECC, ZF, ZCG, a board, a committee, miners, whales, developers, or me. The reserve exists so that ZEC holders can continuously hire the world to make Zcash better.
Build forever
Bitcoin's strength is (and perhaps its eventual downfall will be) resistance to change. Zcash has a different potential strength: the capacity to improve forever.
Privacy technology can not stop. Cryptography can not stop. Wallets, scalability, governance, and developer infrastructure should keep improving as new problems and opportunities emerge. Zcash should remain capable of attracting the best people in the world to work on private electronic money, and that requires resources.
So, the way forward is obvious to us. Keep the Dev Fund. Make it enormous. Let unused funds accumulate into a substantial reserve. Make proposals open but not free to spam. Require some skin in the game. Keep individual asks small, grants granular. Put more meaningful decisions on-chain while building safeguards against capture.
Then invite the entire world to compete to make Zcash better.
A huge Dev Fund with no hereditary beneficiaries will be one of Zcash's greatest competitive advantages.
Fund development forever. Entitle nobody.

