Theorem 5.2 compresses the security of Nakamoto consensus into one two-parameter function, and its qualitative lessons are all visible in Table 1 and Figure 3. This section states them precisely, then instantiates the one lesson that is specific to Zcash.
For every and every , .
By Theorem 5.2, , and one way for the attacker to win the first-to- race is to find the first blocks outright, an event of probability . □
Fix a target . For , let be the least with . Then as .
First, exists. The event that the attacker reaches blocks first is the event that at least of the first block discoveries are the attacker’s. Since , each such length- sequence has probability at most , and there are fewer than sequences. Hence
because .
For fixed the function is a polynomial on , hence continuous, and : at each half of the race of Remark 5.3 has probability exactly by Lemma 3.6 and symmetry. Given any , for each there is a with whenever . Taking excludes every throughout that neighbourhood, so . Since was arbitrary, the claimed divergence follows. □
The paper (§5): “There is nothing special about the default, often-cited figure of 6 confirmations. It was chosen based on the assumption that an attacker is unlikely to amass more than 10% of the hashrate, and that a negligible risk of less than 0.1% is acceptable. Both these figures are arbitrary” — six confirmations are “overkill for casual attackers, and at the same time powerless against more dedicated attackers”. Table 2 is the honest replacement: pick the adversary you defend against and the risk you accept, and read off ; the pair is a policy, not a law of nature.
Corollary 4.7 says security is purchased in blocks. The wall-clock price is set by the target spacing: seconds in ZIP-218. Since public discoveries arrive at rate , waiting for confirmations takes seconds in expectation in this model. Three confirmations cost a nominal seconds and ten cost seconds when all hashpower publishes on the public chain. With a withholding attacker, the expected wait is instead divided by .
For example, a nominal thirty-minute wait buys confirmations at -second spacing, compared with three at Bitcoin’s -second spacing. The corresponding strict-overtake probabilities against a attacker are approximately and , respectively; either count takes minutes in expectation under withholding. These are model calculations, not guarantees about either network.
The comparison holds fixed. It contains no network and therefore does not price honest blocks racing one another during propagation. Quantifying that lost work requires a propagation distribution and mining topology. Moreover, a policy waiting for a fixed amount of accumulated miner reward asks a different question: decreasing the reward per block in proportion to the target spacing requires proportionally more blocks to reach that amount. Ignoring transaction fees (value paid for transaction inclusion) and rounding, the shorter spacing then cancels out of the mean wait. The monetary and fixed-hashrate models are not interchangeable.
Three assumptions do not survive contact with the deployed chain; they determine how cautiously the calculations may be transferred to it. (i) Difficulty is not constant: Zcash retunes the target after every block (Section 8.2). The race is scored in work, not block counts, and may be interpreted approximately as the attacker’s share of work production while the branches’ block weights remain close; once their difficulty schedules diverge, the equal-step random-walk formula is no longer exact. (ii) Hashrate is not constant: in the theorems is whatever share the attacker sustains for the attack’s duration; the paper’s own caveat is that re-enters only if the attacker cannot sustain his hashrate long enough, which it judges unlikely for a serious attacker. (iii) Propagation is not instantaneous: honest self-orphaning wastes honest work and thereby raises the attacker’s effective share; its size is not quantified here. A fourth gap is not the model’s: the attacker of this volume follows the protocol’s validity rules perfectly and attacks only the choice between valid histories. Attacks on the rules themselves are other volumes’ subjects.