Back to Zcash Hub
Security update

Your Zcash Address Changed. Is It Still Yours? Verify It with Keystone

Open the receive screen in your Zcash wallet app, and you may notice something unexpected: today’s u1... address looks different from the one you saw last time.

You haven’t switched wallets or created a new account. So why has the address changed—and can you still use it to receive funds?

A different address does not necessarily mean something is wrong. A single Zcash account can generate multiple receiving addresses. But knowing that addresses can change is not the same as knowing that the address on your screen belongs to you. [2]

Keystone’s Verify Unified Address feature helps you answer that second question. Scan the address QR code with your hardware wallet to independently check whether it belongs to the wallet on your device.

A valid address is not necessarily your address.

Why Does Your Address Change?

It is easy to think of a wallet as having one permanent address. In Zcash, however, a single account can have multiple receiving addresses. Generating a new address does not require creating a new wallet. [2]

Wallet apps that support address rotation can display a fresh address for different receiving situations. This helps reduce the links that repeated use of the same address can create between activities, improving privacy. [3]

Two Unified Addresses that look completely different can therefore still belong to the same account.

You do not need to memorize every address. You do need to confirm that the one you are about to use belongs to your wallet.

One Unified Address, Multiple Ways to Receive ZEC

The u1... addresses discussed in this article are Zcash Unified Addresses, or UAs.

A Unified Address looks like one long string, but it can contain several ways to receive funds. These individual components are called receivers. Think of them as different receiving options packaged into one address. [1]

Transparent is a public way to receive funds, with related transaction information visible on the blockchain. Sapling and Orchard are two different privacy-preserving ways to transfer funds. [4][5]

So when someone says that a Unified Address “contains Sapling,” they simply mean that the address includes an option for receiving ZEC through Sapling. You do not need to create another wallet or understand the technology behind it.

Not every Unified Address contains all three options. The sender’s wallet must support Unified Addresses and be able to use a compatible receiver included in the address. It can then select a receiver according to the protocol’s rules. [1]

That is the benefit of a Unified Address: it brings different receiving options together, so users have fewer address types to choose between.

But it also means that checking just one component is not enough to confirm that the entire address belongs to you.

Keystone Checks More Than the Address Format

A wallet app can tell you that an address is valid. That alone does not answer the more important question: “Is this my address?”

Keystone provides an independent check on the hardware device. The verification flow described here checks whether the address belongs to Account 0—the Zcash account numbered 0 in the wallet currently selected on Keystone.

This is not a comparison between the new address and an old address saved on the device. Instead, Keystone uses the wallet information on the device to calculate and check the receiving information inside the address.

The process starts with the Orchard component. Keystone checks whether it belongs to the current account and identifies its position in that account’s address sequence. If the Unified Address also includes a supported Transparent component, Keystone checks that component as well.

This is why an address that has never appeared on the device before can still pass verification. Keystone checks whether the address comes from the current account—not whether it has seen that exact address before.

Four Verification Results at a Glance

A Unified Address can contain multiple receivers, and the verification flow described here does not support all of them equally. That is why the result is more specific than a simple pass or fail.

On-device message What it means
Zcash Address Verified All receiving information in the address matches the current Account 0. No components remain unverified.
Zcash Address Not Fully Verified Every component checked by the device matches, but the Sapling component has not been verified.
Zcash Address Not Verified The device has found at least one component that does not match the current Account 0.
Invalid QR Code The scanned content is not a supported input for this feature, so the device cannot proceed with the verification flow.

The two middle results are the easiest to confuse. They are not different degrees of failure. They describe two different findings.

Not Fully Verified Is Not the Same as Not Verified

Not Fully Verified: Part of the Address Is Still Unconfirmed

Imagine a Unified Address that contains Orchard, Transparent, and Sapling receiving information.

Keystone confirms that the Orchard and Transparent components match the current account. However, the verification flow described here does not check the Sapling component.

The device has found no mismatch in the components it checked, but it cannot make a claim about the part it did not check. It therefore displays Zcash Address Not Fully Verified.

Think of it as:

“Everything I checked matches, but there is still one part I have not confirmed.”

This does not mean the device has found a problem with the address. It also does not mean the entire address has passed verification. A match in the other components is not proof that the Sapling component belongs to the same account.

This limitation comes from the scope of Keystone’s verification feature. It does not mean that Sapling addresses are technically impossible to verify.

Not Verified: A Mismatch Has Been Found

Zcash Address Not Verified means the device has found an actual mismatch.

For example, the Orchard component may match the current account while the Transparent component does not. Or the Orchard component itself may not match the account.

The message means:

“At least one part of this address does not match the current account.”

When you see this result, do not use the address to receive funds into the current Keystone account until you have checked that the correct wallet, account, and hardware-wallet connection are selected in the wallet app.

The distinction is simple: Not Fully Verified means something remains unknown. Not Verified means something does not match.

Why Can a Transparent Address Show “Invalid QR Code”?

You might wonder: if Keystone can check the Transparent component inside a Unified Address, why might scanning a standalone t1... address produce Invalid QR Code?

Because this feature verifies Unified Addresses—not every type of Zcash address.

Within a Unified Address, Keystone can use the Orchard component to identify the address’s position in the account’s address sequence, then check the corresponding Transparent receiving information. A standalone Transparent address does not contain the Orchard component used by this process and falls outside the feature’s verification scope.

In this context, the message means:

“This content cannot be verified with this feature.”

It does not mean:

“This address is invalid on the Zcash network.”

A Transparent address can be valid and usable even though this particular Verify Unified Address feature cannot confirm its ownership. Again, this is a limitation of the feature’s scope—not a claim that Transparent addresses are technically impossible to verify.

How to Verify an Address on Keystone

The process takes three steps:

  1. Open the receive screen in your wallet app. Find the Zcash Unified Address you want to verify and display its QR code.
  2. Select Verify Unified Address on Keystone. Scan the address QR code with the hardware device.
  3. Read the result on the device. Check whether the entire address was verified, a component remains unverified, a mismatch was found, or the input is unsupported.

If you see Not Fully Verified, do not treat it as a complete verification. Ask the wallet provider or Keystone Support how to confirm ownership of the unverified component and whether it is supported.

If you see Invalid QR Code, first check that you are scanning a Unified Address QR code supported by this feature. The message alone does not establish that your wallet or address is faulty.

The verification scope described in this article is Account 0 of the wallet currently selected on Keystone. Supported capabilities and on-device messages depend on the firmware version you are using.

Addresses Can Change. Verification Still Matters.

Unified Addresses make Zcash’s different receiving options easier to use. Address rotation allows the same account to use more than one address. [1][3]

Keystone’s address verification feature adds an independent check on the hardware device.

You do not need to memorize the underlying protocols. What matters is understanding what the device has confirmed—and what it has not.

A new address is not automatically a cause for concern. But before using it as your receiving address, verify that it belongs to your wallet.

References

These official resources explain Zcash’s address mechanisms. They do not imply that Keystone implements every feature described in them.

  1. ZIP 316: Unified Addresses and Unified Viewing Keys — How Unified Addresses are structured and how wallets select a receiver.
  2. ZIP 32: Shielded Hierarchical Deterministic Wallets — How a single account can generate multiple receiving addresses.
  3. ZIP 315: Best Practices for Wallet Implementations — Address rotation and related privacy considerations.
  4. Zcash Documentation: Addresses and Value Pools — An introduction to Transparent and Sapling addresses.
  5. ZIP 224: Orchard Shielded Protocol — The design and background of Orchard.
← Back to all updates Open the permanent page → 中文