Founders & Origins8 min readZcash (ZEC)

Zcash’s Sixth Participant Was Edward Snowden

In April 2022, Edward Snowden was revealed as John Dobbertin, the mysterious sixth participant in Zcash’s 2016 trusted setup. His unmasking revisited a fundamental cryptographic question: why did six people have to destroy secret parameters to make a private currency trustworthy?

Zcash’s Sixth Participant Was Edward Snowden

3-Minute Fast Briefing

  • The ParadoxZcash's 2016 launch relied on a six-party 'Ceremony': as long as at least one participant honestly deleted their private key shard, the combined 'toxic waste' key — capable only of counterfeiting ZEC, never stealing coins or breaching privacy — could never be reconstructed.
  • The Turning PointWhile five participant identities were made public within days, the sixth, 'John Dobbertin,' remained secret until April 27, 2022, when Zcash Media revealed — and Edward Snowden confirmed — his participation.
  • The LegacyOn May 31, 2022, Network Upgrade 5 activated the Halo-based Orchard pool, eliminating trusted-setup requirements for Zcash's then-new shielded pool while legacy pools retained their original parameters.

Chronological Timeline

October 23, 2016The Ceremony concludes

The six-party parameter generation ends; 'Moses Spears' is revealed as Derek Hinch of NCC Group, which had secretly run an audited compute node.

October 26, 2016Zooko explains the design

Zooko Wilcox publishes The Design of the Ceremony, explaining the secret setup material, the multiparty computation and the computers.

October 27, 2016Peter Todd steps forward

The skeptic witness 'Fabrice Renault' reveals himself as Bitcoin Core developer Peter Todd.

September 21, 2017The audit lands

ECC publishes NCC Group's ceremony audit: no fatal vulnerabilities found, though audits cannot prove the absence of compromise.

April 27, 2022John Dobbertin unmasked

Zcash Media confirms Edward Snowden was the sixth participant, validated by Snowden himself in an interview.

May 31, 2022NU5 activates with Halo

Network Upgrade 5 brings the Halo-powered Orchard pool to mainnet, ending reliance on setup ceremonies for Zcash's then-new shielded pool.

The sixth name

On April 27, 2022, Zcash Media, a division of the production house 37 Laines, issued a press release confirming that Edward Snowden — the NSA whistleblower and privacy advocate — was 'John Dobbertin,' the pseudonymous participant in Zcash's 2016 trusted setup process. The release stated the revelation had been validated by Snowden himself, in an exclusive interview conducted for the short video 'The End of Zcash's Trusted Setup: Who is John Dobbertin?'[3]

For anyone who had followed Zcash from the beginning, the name was the final piece of a six-year-old puzzle. Five of the six ceremony participants had been identified within days of the event itself; only Dobbertin remained a question mark. Zooko Wilcox, CEO of the Electric Coin Company — the company that launched Zcash — explained in the release that he had personally recruited Snowden: the setup split key generation among six participants precisely so that a single trustworthy participant, destroying a single key, would be enough to prevent reconstruction of the secret setup material that could enable counterfeiting.[3]

The announcement also looked ahead to Network Upgrade 5 and Halo, the technology intended to remove the need for a trusted setup in Zcash’s new shielded pool. The juxtaposition gave the reveal its historical weight: the public learned a participant’s name as the project prepared to move beyond that kind of ceremony. It did not mean that disclosing Snowden’s identity itself changed the security of existing funds.[3]

A key that must never exist

When Zcash launched in 2016, its private 'Sprout' transactions relied on SNARK public parameters — shared mathematical objects used to construct and verify zero-knowledge proofs. In a 2016 design post, Zooko Wilcox offered the clearest possible framing: generating them was basically equivalent to generating a public/private keypair, keeping the public key, and destroying the private key. Every user would rely on the public half; the private half had to die.[1]

That private half was nicknamed the 'toxic waste,' and the name was precise about the danger. Anyone who obtained it could create counterfeit Zcash — and, importantly, nothing else. The design post is explicit that this was the only harm it could cause: the holder could not violate anyone's privacy or steal other people's coins. Wilcox's own analogy came from chemistry: a set of factory byproducts, each individually harmless, that form a dangerous substance only if all of them are ever allowed to mix. The protocol's entire goal was to keep the byproducts separated until they were destroyed, so the toxic waste never came into existence at all.[1]

Wilcox was careful, even in 2016, not to oversell what destruction would guarantee. Destroying the private key did not make counterfeiting impossible in some absolute sense — as he noted, every currency technology ever made has been vulnerable to counterfeiting, and Bitcoin itself once shipped a bug that briefly allowed someone to create 184 billion BTC. His deeper warning has aged strikingly well: any system that shields transaction amounts risks losing the ability to detect counterfeiting. The key had to be destroyed because it was one path to fake money — not the only conceivable one.[1]

Six stations and a chain of secrets

The defense was structural. Zcash used a Multi-Party Computation: six participants, in separate geographic locations, each generated one shard of the parameters using a corresponding private key shard, combined the public pieces, and then deleted their private shard. The arithmetic of the scheme made one honest participant sufficient — as long as at least one participant successfully deleted their shard, reconstructing the toxic waste became impossible. For this setup-secret threat, an attacker would need every participant’s secret contribution. That condition did not rule out unrelated implementation flaws.[1]

Three identities were known from the start: Andrew Miller, a computer scientist and Zcash technical advisor; Peter Van Valkenburgh; and Zooko Wilcox himself. The other three were introduced under invented names — 'Moses Spears,' 'Fabrice Renault,' and 'John Dobbertin' — a layer of protection against anyone eavesdropping on communications or subverting a witness. At the ceremony's end on October 23, 2016, Moses Spears was revealed as Derek Hinch of NCC Group, which Zooko had secretly hired to protect and forensically monitor one compute node; four days later, Peter Todd, a vocal skeptic of the whole design, revealed he had been Fabrice Renault — invited, Zooko wrote, to give the ceremony's sharpest critic the best seat in the house.[1]

Wilcox’s design record describes how the participants tried to keep those secret contributions beyond an attacker’s reach. Each private key shard existed only on a newly purchased, computer — physically disconnected from all networks, with its wifi and bluetooth radios removed before it was ever powered on. Messages between the stations were burned to optical discs and carried by hand across the , creating an append-only evidence trail of exactly what was passed. Peter Todd's approach was his own: buy a new computer from a random store, use it, and completely destroy it a couple of days later. The procedure made even moving a message between computers part of the security problem.[1]

The ceremony even had a hidden auditor. On September 21, 2017, ECC published the results of NCC Group's forensic review of its own station: attack tests on a redundant test node found that only a DMA attack succeeded, and only partially, while NCC's expert opinion was that its compute node was not compromised during the event. ECC's framing of the audit was notably honest — no fatal vulnerabilities were found, but audits and forensics cannot prove the absence of compromise. The real first line of defense was never the audit; it was the design that made one honest deletion enough.[2]

What the secret could not do

Public imagination tends to merge every crypto catastrophe into one: keys get stolen, wallets get drained, privacy gets breached. The ceremony's secret was stranger and narrower than all of that. It was not a master password to anyone's wallet, and it was not a surveillance backdoor. The design post distinguished counterfeiting from direct theft and loss of transaction privacy: the toxic waste, if it had ever been assembled, would have functioned like a counterfeit mint's master plate: the power to print fake notes, not the power to open other people's safe-deposit boxes or read their mail.[1]

That narrowness explains both the ceremony's elaborate precautions and the specific relief of its outcome. A stolen wallet key harms one person; an assembled toxic waste key would have silently undermined the currency's foundation — the guarantee that no one can spend money they never had. Six participants were asked to jointly create that power and then reliably destroy their pieces of it, knowing that a single honest destruction among them would suffice. Snowden, in other words, was not guarding anyone's coins. He was guarding the mint itself.[1]

The end of ceremonies

The 2016 ceremony was not Zcash’s last. Sapling required another setup process in 2018, with ECC reporting more than a hundred participants. Spreading participation more widely reduced reliance on any particular person, but it retained the need to generate and dispose of secret setup material. The next research direction was to remove that requirement for a new proving system.[4]

The way out came from research. In 2019, ECC's Sean Bowe, Jack Grigg, and Daira Hopwood authored the Halo paper, introducing a technique for practical, scalable, trustless proving systems. When Network Upgrade 5 activated on mainnet on May 31, 2022, it shipped Orchard — a shielded pool built on Halo 2 that requires no setup ceremony at all. For Orchard, users no longer had to rely on a ceremony participant deleting setup secrets. The change removed that particular trust requirement; it did not make the software immune to bugs or replace the rules of every legacy pool.[4]

The two events came weeks apart: Snowden’s identity was disclosed on April 27, and NU5 activated on May 31, 2022. One completed the public list of the original participants; the other introduced a pool that did not need their kind of setup. That was one stage of the protocol’s history, not its final form. As of September 9, 2026, Zcash’s official record confirms that Ironwood activated on July 28, 2026, and the original Orchard pool is restricted to withdrawals under NU6.3. NU5 had not erased the separate rules of legacy pools. Snowden’s name gives this history a memorable face, but the question reaches beyond him: how much must a currency ask its users to trust the people who helped build it?[3][4][5]

Connected Lore & Universe

Connected Stories in this Universe

Explore the chain reaction of historical breakthroughs, blunders, and legends.

Sources & References

  1. [1]Source 1: The Design of the CeremonyElectric Coin Company (Internet Archive; live URL returns 404) · 2016-10-26Accessed 2026-09-09
  2. [2]Source 2: Ceremony Audit ResultsElectric Coin Company (Internet Archive; live URL returns 404) · 2017-09-21Accessed 2026-09-09
  3. [3]Source 3: Edward Snowden revealed as John Dobbertin (press release)37 Laines / Zcash Media via PRNewswire · 2022-04-27Accessed 2026-09-09
  4. [4]Source 4: NU5 activates on mainnet, eliminating trusted setup and launching a new era for ZcashElectric Coin Company · 2022-05-31Accessed 2026-09-09
  5. [5]Source 5: NU6.3: Ironwood activation and Orchard restrictionsZcashAccessed 2026-09-09