The Zcash ArboretumConsensus Guide PDF

1 Scope, sources, and the two double-spends

The protocol layers above this one take a working ledger for granted. This volume documents the mechanism that selects that ledger: Nakamoto consensus — proof of work, the most-work rule, and the probabilistic finality they purchase. The treatment is quantitative throughout. Its spine is Meni Rosenfeld’s Analysis of hashrate-based double-spending (11 December 2012; latest version 12 February 2014; arXiv:1402.2009), which gives an exact counterpart to the approximate analysis in Satoshi Nakamoto’s whitepaper; we reprove its results in full, recompute its tables by script, and instantiate its conclusions for the proposed NU7 parameters.

Two distinct attacks are both called “double-spending”, and this volume treats exactly one of them. Two spends of the same shielded note reveal the same nullifier, and the protocol specification’s §“Nullifier Sets” forbids a repeated nullifier within a transaction or valid block chain; such a same-chain attempt is therefore invalid under the consensus rules. What consensus must prevent is the chain-level attack: paying a merchant on the chain everyone sees, then replacing that chain wholesale with another in which the payment never happened. No zero-knowledge proof (Crypto Guide, §“Interactive proofs, zero knowledge, and SNARKs”) rules this out; under the model developed here, the proof-of-work race gives the attack its probabilistic bound.

The quantitative argument assumes the Math Guide’s probability section (§“Probability, asymptotics, and computation”), which constructs probability from its definition — finite spaces, conditioning, independence, random variables, expectation — and extends it to the three rungs used here: countable additivity, continuity along monotone events, and density-defined laws (§“Beyond finite spaces: countable additivity, limits, and densities”). The block and anchor vocabulary uses the Crypto Guide’s hash and commitment sections. On that base, Section 3 constructs the race-specific instruments no lower volume owns — memoryless clocks, random walks, the negative binomial law; the algebra used is elementary. Readers wanting only the results can read Sections 2, 6, and 8 and take the theorems on faith.

1.1 Sources and their standing

Rosenfeld’s analysis supplies the probability and economic model, not consensus rules; its two printed tables are reproduced by exact arithmetic before instantiating the model here. The protocol specification and the relevant ZIPs define the protocol.

This volume targets the draft NU7 rules as of 23 September 2026: ZIP-259 selects ZIP-218, ZIP-237, and ZIP-2003. Activation heights remain unassigned, and some proposed limits and issuance rules are incomplete. These boundaries are stated where they affect a calculation; no unassigned constant is treated as a deployed rule.

Remark 1.1 (The paper’s own condition).

The arXiv v1 PDF of the paper is lightly broken: it contains exactly two citations, both rendered as “[?]” (in the abstract and in §1), and no References section at all. Both plainly intend the Nakamoto whitepaper, and we read them so. The paper numbers only two of its displayed equations — its equation (1) is our Theorem 5.2, its equation (2) our equation (3) — and sets its two model assumptions as a bare numbered list; the Assumption environments of Section 4 are ours.