Each release contains a ./doc/security-warnings.md document describing security issues known to affect that release. You can find the most recent version of this document here. Zcash has been subjected to formal third-party security reviews. Audit reviews can be found in the Zcash Foundation and Electric Coin Company blogs.
The Zcash protocol has a system to issue security alerts. These will be sent to all nodes. In the event the Electric Coin Company website is down or hacked, please also check these Twitter/X handles: @ElectricCoinCo, @zooko.
Contact [email protected] (security.asc) to submit security vulnerabilities or for sensitive discussions with our security team. The security disclosures process can be found here.Â
Key fingerprint = AF85 0445 546C 18B7 86F9 2C62 88FB 8B86 D8B5 A68C
Below are keys we use to sign the software in our package repository.
Zcash Master Signing Key:Â zcash.asc
Key fingerprint = 3FE6 3B67 F85E A808 DE9B 880E 6DEF 3BAF 2727 66C0
Key fingerprint = AF85 0445 546C 18B7 86F9 2C62 88FB 8B86 D8B5 A68C
Developer Public Keys
Key fingerprint = 01A2 20DF 0EA9 A42C 4EAEÂ 6B1D ED41 7FBE 79C9 9E8C
Key fingerprint = 3D6A 08E9 1262 3E9A 00B2Â 1BDC 067F 4920 98CF 2762
Key fingerprint = 0395 DE0A 5027 BE0C 1F5A FB03 9568 4257 D8F8 B031
Key fingerprint = 2253 E2A1 EEB4 0E2A 3D22Â EB1D 0EC5 1FCD A94F B53E