Zcash (ZEC) sustainability report

NameBlockNodes SAS
Relevant legal entity identifier969500PZJWT3TD1SUI59
Name of the crypto-assetZcash
Beginning of the period to which the disclosure relates2025-09-27
End of the period to which the disclosure relates2026-09-27
Energy consumption322297378.57292 kWh/a
Renewable energy consumption23.6946977292 %
Energy intensity11.20386 kWh
Scope 1 DLT GHG emission - Controlled0.00000 tCO2e
Scope 2 DLT GHG emission - Purchased128205.47126 tCO2e
GHG intensity4.62701 kgCO2e

Consensus Mechanism

Zcash is present on the following networks: Zcash.

Zcash secures its ledger with proof of work, inherited in outline from the design it was forked from and modified in two significant respects. The hash algorithm is memory-hard, chosen originally in the hope that memory requirements would keep block production accessible to general-purpose hardware; in practice purpose-built machines were developed for it and now perform the bulk of the work. Miners compete to find a block, the chain with the greatest accumulated work is the one nodes follow, and settlement is probabilistic, strengthening as blocks accumulate on top. The block subsidy halves on a fixed schedule.

The distinctive element is not the consensus rule but what the ledger can express. Alongside transparent transactions the protocol supports shielded ones, in which the sender, recipient and amount are hidden and validity is demonstrated by a zero-knowledge proof. The consensus-relevant point is where that proof is produced: the user's own wallet constructs it before broadcasting, and validators merely verify it, which is fast. A shielded transaction therefore imposes no additional work on the network's consensus process compared with a transparent one, and the privacy feature does not make the chain more expensive to secure.

Successive network upgrades have revised the shielded machinery and the funding arrangements. A 2026 upgrade responded to a disclosed flaw in one of the shielded pools by tightening a consensus rule on proof size, and the affected pool was subsequently replaced. Governance proceeds through a proposal process that in practice requires broad agreement among those who maintain node implementations, since a change only takes effect if the nodes adopt it.

A design that would add a stake-based finality layer on top of mining is under active development by an organization separate from the protocol's original developers. It is important to state what it is and is not: it would keep proof-of-work block production, with stake participants marking already-mined blocks as final rather than replacing miners. As of this writing it has no activation height and no scheduled deployment, and the network runs entirely on proof of work.

Incentive Mechanisms and Applicable Fees

Zcash is present on the following networks: Zcash.

Miners receive a block subsidy plus transaction fees. The subsidy follows a fixed halving schedule toward a capped total supply, so mining revenue declines in steps over time and the network's security budget increasingly depends on fees. A defined portion of the block subsidy is directed away from miners to fund protocol development and ecosystem grants, allocated through a governance process that determines the recipients and the split; this arrangement has been renewed and restructured at successive upgrades rather than being permanent. Consensus rules require the subsidy and fees to be collected in the block's coinbase transaction, which makes the allocation auditable from the chain itself rather than resting on voluntary compliance.

Users pay a transaction fee that is deliberately simple and low. The fee structure charges according to the number of inputs and outputs a transaction carries rather than treating all transactions alike, which prices the burden a transaction places on the network in proportion to its actual size and complexity. There is no separate metering for privacy: a shielded transaction pays on the same basis as a transparent one, because the expensive part of privacy is borne by the sender's own hardware when constructing the proof, not by the network that verifies it. There are no storage rents or recurring charges on holdings.

Because the network is proof of work, there is no staking, no delegation, no bonded capital, no commission and no unbonding period. There is correspondingly no slashing: nothing is confiscated from a participant under any circumstance, and a miner who produces an invalid block simply has it rejected by every node, losing the effort spent on it. Should the finality layer under development eventually activate, it would introduce stake-based participation alongside mining and its own penalty rules, and prototyping of such a mechanism is reported to be underway; none of it is in effect, and the incentive structure in operation today is the mining reward and the fee market alone.

Energy consumption sources and methodologies

Zcash is present on the following networks: Zcash.

Consumption is modeled from the top down, as it must be for proof of work, since the participants cannot be counted but the work they collectively perform is public. Network difficulty gives the aggregate computational effort expended, and the model works backward from that to the hardware plausibly producing it and the power that hardware draws.

The memory-hard algorithm shapes the fleet composition. Although the design intended to resist specialization, purpose-built machines were eventually built for it, and the fleet today is understood as a mixture of that specialized hardware and a residual tail of general-purpose equipment, each class with its own efficiency. A profitability screen selects which of them can plausibly be running: revenue over the period is set against operating cost at representative electricity prices, and equipment that could not cover its power bill is assumed to have been switched off. The resulting weighted mix is scaled to account for the observed aggregate work, its power draw summed, and an allowance added for the cooling and power-conversion overhead of the facilities involved.

Two features of this particular network are worth stating because they bear directly on the accounting boundary. First, the network shares no merge-mining arrangement with another chain, so none of its work is jointly produced with or attributable to a second ledger. Second, the substantial computation involved in producing shielded transactions happens on users' own devices, outside any boundary a network-level estimate can reach, and is therefore excluded; the figure covers mining and node operation, not the wallets that build proofs.

The usual limitations apply. Hardware composition is inferred rather than observed, the profitability screen rests on an assumed electricity price that differs widely between operations, and facility overhead is a broad uniform assumption. Where evidence is weak the conservative assumption is preferred, which is more likely to overstate than understate the total, and estimates are revised as the hardware population and the economics behind it shift.

Key energy sources and methodologies

Zcash is present on the following networks: Zcash.

The geographic distribution of mining capacity cannot be observed directly, because miners have no incentive to identify themselves. The estimate is assembled from indirect evidence: the mining pools through which most work is routed expose partial information about where the work reaching them comes from, and the topology of the nodes relaying blocks gives a second, imperfect view. Together these yield a distribution across countries and regions that is treated as a sample extended to the unobserved remainder, not as a complete census.

Each region is matched to published statistics on how its electricity is generated, and the renewable share reported is the average of those figures weighted by the consumption attributed to each region. A caveat particular to this network deserves emphasis: it is a comparatively small proof-of-work network whose hardware overlaps imperfectly with that of larger ones, and where a distribution cannot be observed with confidence, the distribution of a structurally comparable network is substituted. That substitution assumes miners of this chain site themselves for the same reasons and in the same places as miners of the comparison network, which is plausible but unverified, and it is the single largest source of uncertainty in this figure.

Mining capacity is also mobile in a way most computing loads are not, since the equipment is fungible and the economics are dominated by electricity price, so the fleet migrates toward cheap power and the distribution can change materially within a reporting period. Grid statistics are annual and regional, concealing seasonal variation that matters where capacity follows seasonal surpluses.

Energy intensity per transaction is period consumption divided by transactions settled. For proof of work this must be read as an accounting average rather than a marginal cost: consumption is set by mining revenue and difficulty and does not respond to transaction volume, so one additional transfer causes essentially no additional energy, and the intensity figure falls when usage rises even though nothing about the network's energy use has changed. Source data is processed by Our World in Data from Ember and the Energy Institute's Statistical Review of World Energy: Share of electricity generated by renewables.

Key GHG sources and methodologies

Zcash is present on the following networks: Zcash.

Emissions are derived by applying a carbon intensity to the electricity attributed to each mining region, reusing the regional distribution established for the renewable share and the consumption figure derived from difficulty and hardware economics, then summing across regions. The boundary covers operational electricity only. Hardware manufacture is excluded, which understates the full lifecycle burden of proof-of-work mining in particular, since specialized machines are replaced on short cycles and their embodied emissions are proportionally larger than those of long-lived general-purpose servers. That exclusion is a property of the boundary, stated here rather than defended.

Scope 1 captures emissions from sources the operators directly control, principally on-site combustion. For mining drawing from public grids this is negligible, though the sector includes operations sited to consume gas at production facilities, where combustion is under the operator's control and would properly belong in scope 1. Any such capacity within the modeled fleet is treated as a minor component and is not modeled in detail, which is an acknowledged limitation.

Scope 2 captures emissions embodied in purchased electricity and constitutes almost the entire footprint.

Greenhouse gas intensity per transaction is period emissions divided by transactions settled over the period, and inherits the caveat attached to energy intensity: the numerator is driven by mining economics rather than usage, making the quotient an average rather than the emissions attributable to one more transfer. Uncertainty compounds through the calculation, and for this network it is larger than for the biggest proof-of-work chains, because the geographic distribution rests partly on a substituted distribution from a comparable network rather than on direct observation, and an error there propagates straight into the intensity applied. Figures are restated each period as observation improves. Carbon intensity data is processed by Our World in Data from Ember and the Energy Institute's Statistical Review of World Energy, and is made available under a Creative Commons BY 4.0 license: Carbon intensity of electricity generation.