Overview
NEXUS-Zcash extends the NEXUS metaprotocol to Zcash, enabling full smart contract programmability and unified liquidity. Deploy the same WASM contracts on Zcash L1 as on Bitcoin and Dogecoin.Trustless Verification
NEXUS-Zcash is fully trustless - no federation, no multisig, no trusted third parties.How Trustlessness is Achieved
- Cryptographic Proofs: Every state transition is proven via Groth16 ZK-SNARKs
- On-Chain Verification: Proofs are verified directly on Zcash L1
- Economic Security: Provers post bonds that are slashed for invalid states
- Permissionless Challenges: Anyone can challenge invalid state transitions
- Self-Custody: Users always retain escape hatch to recover funds
Security Model
Cryptographic Soundness (Groth16)
NEXUS-Zcash leverages Zcash’s native Groth16 ZK-SNARK infrastructure for on-chain proof verification:- Groth16 proofs - Succinct proofs (~200 bytes) with fast verification
- Zcash’s Trusted Setup - Uses Zcash’s Powers of Tau ceremony (Sapling MPC)
- Native On-Chain Verification - Zcash nodes natively verify Groth16 proofs
- Efficient - Constant-size proofs regardless of computation complexity
Zcash Native Proof Verification
Unlike Bitcoin where proof verification requires BitVM2 bisection games, Zcash can natively verify Groth16 proofs on-chain. This is because Zcash already has built-in support for Groth16 verification (used for shielded transactions).Why Zcash’s Trusted Setup?
NEXUS-Zcash uses Zcash’s existing trusted setup from the Sapling MPC ceremony:By using Zcash’s existing trusted setup, NEXUS-Zcash inherits the security of the largest MPC ceremony ever conducted for a cryptocurrency.
Why Groth16 for Zcash?
Fraud Proofs
- Provers post bonds on Zcash L1
- State commitments via Sapling shielded notes (512-byte encrypted memos, not OP_RETURN)
- Invalid state transitions can be challenged
- Groth16 proofs verified directly by Zcash nodes
- Fraudulent provers lose bonds to challengers
Combined Model
Full WASM Smart Contracts
NEXUS-Zcash supports the complete WASM smart contract system - the same contracts that run on Bitcoin and Dogecoin run identically on Zcash.Contract Capabilities
Cross-Contract Calls (xcc)
Contracts can call other contracts seamlessly:Delegate Calls
Execute another contract’s code in the current contract’s storage context:Contract Deployment from Contracts
Deploy child contracts with deterministic addresses:Architecture
Key Features
Transparent Vaults (t-address)
NEXUS-Zcash currently supports transparent addresses (t-addr) only:Unified Liquidity (V2)
Cross-chain unified liquidity pools with BTC/ZEC/DOGE are planned for V2 via intent exchange:V1 supports ZEC deposits, withdrawals, and smart contracts. Unified liquidity with BTC/DOGE via intent exchange is coming in V2.
Supported Features
Deposit Flow
Withdrawal Flow
State Commitments via Sapling Notes
NEXUS-Zcash does not use OP_RETURN for state commits. Instead, it uses Zcash’s native Sapling shielded note system:Why Sapling Notes Instead of OP_RETURN?
Memo Format (512 bytes)
Each state commit memo carries:Nullifier Chain
Each commit references the nullifier of the previous Sapling state note, creating a cryptographically linked chain from genesis:Keys
To independently verify NEXUS state: obtain the public FVK, scan Zcash for notes with magic
NXS\x02 in their memos, and reconstruct the epoch chain.
Configuration
Cross-Chain Swaps (V2)
Cross-chain swaps between ZEC/BTC/DOGE will be available in V2 via intent exchange.ZEC → BTC (V2)
BTC → ZEC (V2)
Roadmap
V1 (Current)
- ✅ Transparent address (t-addr) vaults
- ✅ Full WASM smart contracts
- ✅ Cross-contract calls & delegate calls
- ✅ Groth16 proof verification
- ✅ ZEC deposits and withdrawals
- ✅ State commits via Sapling notes (nullifier-chained)
- ✅ Stealth addresses (ECDH, view tags, client-side scanning)
- ✅ Encrypted mempool (ChaCha20-Poly1305, MEV protection)
V2 (Planned)
- 🔄 Unified liquidity with BTC/DOGE via intent exchange
- 🔄 Shielded address (z-addr) vault deposits
- 🔄 Shielded withdrawals
- 🔄 Full Sapling privacy for DeFi transactions
Reorg Handling
NEXUS handles Zcash reorgs automatically:- Monitor for chain reorganizations
- Revert affected deposits/withdrawals
- Re-process transactions on new chain
- Maintain consistency with L1