The Zcash ArboretumThe Complete Arboretum PDF

6 What the numbers say

Theorem 5.2 compresses the security of Nakamoto consensus into one two-parameter function, and its qualitative lessons are all visible in Table 1 and Figure 3. This section states them precisely, then instantiates the one lesson that is specific to Zcash.

q r<10% r<1% r<0.1%
2% 1 2 3
5% 2 3 4
8% 2 3 5
10% 2 4 6
15% 3 6 9
20% 4 8 13
25% 5 12 20
30% 9 20 32
35% 15 36 58
40% 34 82 133
45% 135 331 539
Table 2: The least number of confirmations pushing r⁢(q,n) below three targets, computed by script. The growth is logarithmic in the inverse target risk but explosive in q: a 10% attacker is answered by 6 confirmations, a 45% attacker by 539, and at 50% by no number at all.
Proposition 6.1 (No finite count is final).

For every 0<q<p and every n, r⁢(q,n)≥2⁢qn>0.

Proof.

By Theorem 5.2, r=2⁢P⁢r⁢[An], and one way for the attacker to win the first-to-n race is to find the first n blocks outright, an event of probability qn. □

Proposition 6.2 (Divergence at the majority line).

Fix a target 0<ε<1. For 0<q<12, let nε⁢(q) be the least n with r⁢(q,n)<ε. Then nε⁢(q)→∞ as q↑12.

Proof.

First, nε⁢(q) exists. The event An that the attacker reaches n blocks first is the event that at least n of the first 2⁢n−1 block discoveries are the attacker’s. Since q<p, each such length-(2⁢n−1) sequence has probability at most qn⁢pn−1, and there are fewer than 22⁢n−1 sequences. Hence

r⁢(q,n)=2⁢P⁢r⁢[An]≤(4⁢p⁢q)np⟶0,

because 4⁢p⁢q<1.

For fixed n the function q↦r⁢(q,n) is a polynomial on [0,12], hence continuous, and r⁢(12,n)=1: at q=p each half of the race of Remark 5.3 has probability exactly 12 by Lemma 3.6 and symmetry. Given any N, for each 1≤n≤N there is a δn>0 with r⁢(q,n)>ε whenever q>12−δn. Taking δ=min1≤n≤N⁡δn>0 excludes every n≤N throughout that neighbourhood, so nε⁢(q)>N. Since N was arbitrary, the claimed divergence follows. □

Remark 6.3 (Nothing is special about six).

The paper (§5): “There is nothing special about the default, often-cited figure of 6 confirmations. It was chosen based on the assumption that an attacker is unlikely to amass more than 10% of the hashrate, and that a negligible risk of less than 0.1% is acceptable. Both these figures are arbitrary” — six confirmations are “overkill for casual attackers, and at the same time powerless against more dedicated attackers”. Table 2 is the honest replacement: pick the adversary you defend against and the risk you accept, and read off n; the pair (q,ε) is a policy, not a law of nature.

6.1 Zcash time: 25-second blocks

Corollary 4.7 says security is purchased in blocks. The wall-clock price is set by the target spacing: 25 seconds in ZIP-218. Since public discoveries arrive at rate p/T0, waiting for n confirmations takes n⁢T0/p seconds in expectation in this model. Three confirmations cost a nominal 75 seconds and ten cost 250 seconds when all hashpower publishes on the public chain. With a 10% withholding attacker, the expected wait is instead divided by 0.9.

For example, a nominal thirty-minute wait buys 72 confirmations at 25-second spacing, compared with three at Bitcoin’s 600-second spacing. The corresponding strict-overtake probabilities against a 10% attacker are approximately 9.35×10−34 and 1.712%, respectively; either count takes 30/0.9≈33.3 minutes in expectation under withholding. These are model calculations, not guarantees about either network.

The comparison holds q fixed. It contains no network and therefore does not price honest blocks racing one another during propagation. Quantifying that lost work requires a propagation distribution and mining topology. Moreover, a policy waiting for a fixed amount of accumulated miner reward asks a different question: decreasing the reward per block in proportion to the target spacing requires proportionally more blocks to reach that amount. Ignoring transaction fees (value paid for transaction inclusion) and rounding, the shorter spacing then cancels out of the mean wait. The monetary and fixed-hashrate models are not interchangeable.

Remark 6.4 (Where the model bends).

Three assumptions do not survive contact with the deployed chain; they determine how cautiously the calculations may be transferred to it. (i) Difficulty is not constant: Zcash retunes the target after every block (Section 8.2). The race is scored in work, not block counts, and q may be interpreted approximately as the attacker’s share of work production while the branches’ block weights remain close; once their difficulty schedules diverge, the equal-step random-walk formula is no longer exact. (ii) Hashrate is not constant: q in the theorems is whatever share the attacker sustains for the attack’s duration; the paper’s own caveat is that T0 re-enters only if the attacker cannot sustain his hashrate long enough, which it judges unlikely for a serious attacker. (iii) Propagation is not instantaneous: honest self-orphaning wastes honest work and thereby raises the attacker’s effective share; its size is not quantified here. A fourth gap is not the model’s: the attacker of this volume follows the protocol’s validity rules perfectly and attacks only the choice between valid histories. Attacks on the rules themselves are other volumes’ subjects.