While the debate over “bunker mode” and the roughly 6 million bitcoins sitting behind exposed public keys preoccupies the crypto sphere, engineers at Zakura are putting forward an approach for Zcash. In a post signed by Roman Akhtariev, the team describes applying a technique called PIR, for Private Information Retrieval, to Zcash’s transparent addresses. According to Journal du Coin, which reported on the post on October 9, 2026, the goal is to let a wallet monitor its addresses without ever revealing to the server which ones it is checking.

A transparent address hides its key until it is spent

The starting point is the structure of Zcash’s transparent addresses. According to the article, such an address does not contain the public key itself, but its hash. The address and its history remain public on the blockchain, while the public key stays hidden. It only appears on-chain at the moment of spending, since it then accompanies the signature.

This is where the risk in question lies: in the event of a cryptographic breakthrough, an exposed key means funds living on borrowed time, Journal du Coin sums up. The article presents this risk as a scenario, not as an established fact.

Address rotation and its blind spot

The countermeasure described comes down to one word: rotation. With each transaction, the wallet generates a new address, and any change is sent to a fresh address whose key remains behind a hash. No new secret phrase (seed) is needed, because standard derivation produces a tree of key pairs from a single phrase. Spending from an address A thus reveals only A’s public key.

The article does, however, point to a blind spot: the extended public key, which makes it possible to derive all of an account’s receiving and change keys. According to Journal du Coin, an attacker who obtained it along with a single transparent private key could work back to the root key, then derive all the others.

The problem being addressed: what the server sees

Generating addresses is not enough; they also have to be monitored in order to receive payments. Yet a conventional light wallet queries its RPC server with readable addresses. “Show me the transactions for A, then B, then C,” as the post quoted by Journal du Coin puts it. The server sees each address and can link these requests to the same client; encrypting the connection changes nothing, since the server reads the content of the requests.

The consequence: addresses that are independent on-chain end up associated through the way they are checked. It is a metadata leak that the blockchain itself does not show.

What PIR does, according to the published description

PIR consists of retrieving a record from a database without the server knowing which one. The article does not detail the cryptographic mechanism that makes this possible; it does, however, describe the organisation chosen for Zcash:

  • confirmed transparent activity is split into block ranges, each served by a shard;
  • since PIR retrieves records by position, the wallet locally hashes the address’s payment script, which gives it candidate positions in the shard’s directory, which it then retrieves privately;
  • each shard publishes a public activity filter, which the wallet downloads to test its addresses locally, without sending anything to the server;
  • only when there is a possible match does the wallet send a private query.

According to the article, a range of 10,000 distinct payment scripts fits into about 15 KB of filters. The retrieved records describe confirmed receipts and spends; short histories fit into the first response, while longer ones continue across additional pages, which are also retrieved privately. The same path is used for restoring from the secret phrase, when an old address with a zero balance needs to recover its history.

What is available and what remains announced

According to Journal du Coin, the transparent PIR component is arriving this week in Vizor, as an experimental deployment that can be enabled via the “Private queries” option in the settings. The component is therefore presented as experimental.

What comes next is still at the announcement stage: fully post-quantum transparent pools are planned for January. The article does not specify how they will work; their timeline remains to be verified.

What the technique protects, and what it does not

Two protections need to be distinguished. According to the post as reported by Journal du Coin, rotation reduces key exposure in the face of a potential breakthrough, while PIR reduces the information available for profiling and targeting. These are two different risks, addressed by two complementary remedies. In other words, according to this description, PIR concerns what the server can learn from queries, not key exposure.

The limitations are also acknowledged. Transparent transactions remain public on-chain, and PIR does nothing to change that reality. Finally, the article notes that knowing several addresses belong to the same wallet does not, for all that, reveal their hidden keys.

Sources