Skip to content
zipcoin$ZC

Epoch 01 has not opened. Dates and the reward pool will be announced on @zipcoincash.

A program for zipcoin holders on Ethereum mainnet.

$ZC Holder Rewards Rewarding sustained ownership.

Hold more $ZC for longer and your share of each reward epoch grows. Ownership is measured across the whole epoch, not at a snapshot.

View methodology

Connect your wallet to view your Holder Score and reward allocation.

why holder rewards

Speaking spends it.
Holding keeps it.

$ZC is the currency from Snowmoon, shipped as an ERC-20 on Ethereum with a fixed supply of 1,000,000,000. There is no mint and no owner. Supply can only move one way.

It falls whenever zipcoins are burned. Every word in the book is paid for by burning zipcoins to 0x…dEaD, and every knock at a door burns. Half of the sales tax the treasury collects on every trade is kept for buybacks and burns.

A burn is a costly signal only because the coins are worth keeping. Holders are the other side of every burn: the people who keep $ZC while it is spent, zipped, traded and destroyed around them.

The book ranks words by burn, with time decay, so today's words rise over yesterday's. Holder Rewards is its counterpart. It ranks ownership by time, with accrual, so positions that stay rise.

Spent

Speak, knock, buybacks. Burned to 0x…dEaD, gone for good.

Kept

Held in an address, block after block, epoch after epoch. Counted by Holder Rewards.

Time cannot be raced.

Round one of the Trials opened on September 30. All four prizes were claimed within 28 minutes by one operator using two wallets, within the rules. Anything decided at a single moment goes to whoever is fastest at that moment. Holder Rewards has no moment to win: its clock runs for the whole epoch, and the only way to score is to hold.

How the Trials fell, on zipcoin.cash
  • 01

    Time, not timing

    Balances are measured at every block of an epoch. A purchase in the final hour counts for the final hour, and new coins start at the lowest Duration Weight.

  • 02

    Size, with diminishing returns

    More $ZC means more weight. Above the reference balance, four times the coins gives twice the weight, so no single address can take the pool by size alone.

  • 03

    Private by default

    No identity checks, no wallet clustering and no public balances. Holder Rewards reads only what Ethereum already shows, and your own figures are shown only to you.

how scoring works

Two things count, and they multiply.

How much $ZC an address holds across the epoch, and how long it has held it. Neither is enough on its own.

Holder Score = Balance Weight × Duration Weight

Balance Weight

Starts from your time-weighted balance: the average $ZC in your address across every block of the epoch. Holding 1,000,000 zc for half the epoch counts as 500,000.

Up to the reference balance of 1,000,000 zcproposed it counts one for one. Above it, it counts as the square root: 4,000,000 zc counts as 2,000,000, and 100,000,000 counts as 10,000,000.

Duration Weight

Every coin carries its own holding age. It starts at 1.00× when the coin arrives and rises evenly to 2.00× after 168 daysproposed, six epochs. Then it stops.

Your Duration Weight is the average across your coins and across the epoch. The cap means a long-held position is worth recognising, not compounding forever.

Illustrative score model

Proposed default parameters. Not live data. Does not estimate a reward.

4,000,000 zc
3 days
Held during the epoch
3 of 28 days
Time-weighted balance
428,571 zc
Balance Weight
428,571
Duration Weight
1.01×
Holder Score
432,398

A snapshot at close would count 4,000,000 zc. The Holder Score for this position is 432,398.

Balance Weight

Linear up to 1,000,000 zc, square root above it. Log scale.

Balance Weight against time-weighted balance, log scale. Linear up to 1,000,000 zc, square root above.
1K10K100K1M10M100M1K10K100K1M10M100Mreference balance

Duration Weight

Each coin starts at 1.00× and reaches 2.00× after 168 days. The bright segment is this position during the epoch.

Duration Weight against holding age. Rises from 1.00 to 2.00 over 168 days, then stays flat.
1.001.251.501.752.000d28d56d84d112d140d168d196d224d

What changes your score

Proportional, not punitive. Normal wallet management costs only what it actually changes.

Holding
Your balance counts at every block, and each coin's Duration Weight rises toward 2.00×.
Adding
New coins join at 1.00× and age from there. Coins you already hold keep their age. Adding never lowers a score.
Selling part
Coins leave in proportion from every age. Selling 10% lowers your balance by 10% and keeps the age of the rest.
Selling everything
Holding age resets. Coins bought later start again at 1.00×.
Buying just before close
Counts only for the time held. Coins bought one day before close count for one day of 28, at 1.00×.
Moving to another address
The receiving address starts the moved coins at 1.00×. Holding age does not travel between addresses.
Zipping
Zipped coins sit in the privacy pool, not in your address, so they are not counted. Unzipped coins arrive with no holding age.

ranking

Ranked by score, not by balance.

At the close of each epoch, eligible addresses are ordered by Holder Score. A smaller holder who stayed can rank above a larger wallet that arrived late.

Same epoch, three wallets

Illustrative score model, proposed parameters

Holder Scores of three illustrative wallets in one 28-day epoch
Wallet ARank 2Position 1,000,000 zcSix months, all epochDuration 2.00×
2,000,000
Wallet BRank 3Position 4,000,000 zcBought 3 days before closeDuration 1.01×
432,398
Wallet CRank 1Position 4,000,000 zcBought as the epoch openedDuration 1.08×
2,166,667

A outranks B with a quarter of the coins. B's purchase counts for three days of 28, at the lowest Duration Weight.

Size still matters. C holds four times A's coins for the whole epoch and edges ahead. What cannot be bought is time at the last block.

Percentile bands

Rank is relative. Bands are percentiles of Holder Score among eligible addresses, so they adjust as the holder population changes. There are no fixed token thresholds.

  1. Top 1%Highest 1% of Holder Scores
  2. Top 5%Above 1%, within the highest 5%
  3. Top 10%Above 5%, within the highest 10%
  4. Top 25%Above 10%, within the highest 25%
  5. EligibleAll other eligible addresses

Bands describe position only. They do not change allocation, which is always proportional to Holder Score, so there is no threshold to reach and no edge to sit just above.

Why one address cannot take the pool

Under a balance snapshot, the largest address takes its full proportional share. Under the Holder Score, weight above the reference balance grows with the square root, and no address can receive more than 5% of a pool (proposed). Large positions still lead. They do not dominate.

Share of the pool, by group of addresses

Hypothetical population of 1,000 addresses. Not zipcoin data.

View as table
Pool share by group under a balance snapshot and under the Holder Score
GroupBalance snapshotHolder Score
Largest address17.9%3.6%
Next 9 addresses30.1%13.4%
Next 90 addresses28.7%38.8%
Remaining 900 addresses23.2%44.2%

500,000,000 zc spread across 1,000 addresses on a Zipf curve, all with equal tenure, so only the Balance Weight differs. Real distributions will differ.

reward allocation

Your share is your score over everyone's.

Each epoch's pool is divided in proportion to Holder Score. No tiers, no multipliers on top, no discretion per address.

  1. Your Holder Score

    Balance Weight × Duration Weight

  2. divided by

    Total Holder Scores

    Every eligible address, same epoch

  3. multiplied by

    Epoch Reward Pool

    To be announced

  4. equals

    Your Allocation

    Paid for that epoch

Worked example

A Holder Score of 2,000,000 when all eligible scores total 400,000,000 is a 0.5% share of the epoch's pool, whatever its size.

Per-address cap

No address receives more than 5%proposed of a pool. Any excess is shared among the other eligible addresses in proportion to their scores.

Reward pool

Size: To be announced. Asset and source: To be announced. Published before each epoch opens.

reward epochs

Fixed periods. Same rules for every address.

Holder Rewards runs in reward epochs. Each one measures every address over the same block range, then closes, computes and publishes. Holding age carries from one epoch to the next.

Current epoch

Epoch 01
Status
Not yet open
Measurement period
To be announced
Epoch length
28 daysproposed
Reward pool
To be announced
Distribution
To be announced
  1. 01

    Announce

    Dates, reward pool, exclusion list and any parameter changes are published before the epoch opens.

  2. 02

    Measure

    Every eligible address is measured at every block, from the opening block to the closing block.

  3. 03

    Close and compute

    Holder Scores, ranks and allocations are computed with the published methodology version.

  4. 04

    Publish and distribute

    Aggregate results and a commitment to the allocation set are published, then allocations are distributed.

Your position

Not connected
$ZC balance
Connect to view
Time-weighted balance
Connect to view
Holding duration
Connect to view
Duration Weight
Connect to view
Holder Score
Connect to view
Rank
Connect to view
Percentile
Connect to view
Band
Connect to view
Epoch allocation
Connect to view
Epoch progress
Connect to view

Connect your wallet to view your Holder Score and reward allocation. Your figures are shown only to you.

methodology

Methodology.

The full specification, for anyone who wants to check the arithmetic. Version 0.1, draft. Values marked proposed are design defaults until confirmed for an epoch.

01 Data source

Scores are computed from Ethereum mainnet only: the Transfer events of the $ZC token (0x4E67…8722) and block timestamps. No off-chain data and no identity data. Each address's history is replayed from the token's launch, so holding age carries into the first epoch.

02 Holding age

An address holds its coins as lots, each stamped with the time it arrived.

  • Incoming transfer: a new lot with age 0.
  • Outgoing transfer: every lot is reduced by the same fraction, so the age mix of what remains is unchanged.
  • Balance reaches zero: all lots end. Later coins start at age 0.

Production implementations may bucket lots by day. The result differs by at most one day of age.

03 Duration Weight

A coin of age a carries tenure weight w(a), rising linearly and then capped:

w(a) = 1 + (W − 1) × min(a, T) ÷ T

T = 168 days        W = 2.00

The address's Duration Weight for the epoch is the mean tenure weight of its coins, weighted by balance and by time:

DW = ∫ Σᵢ bᵢ(t) · w(aᵢ(t)) dt  ÷  ∫ b(t) dt

Both integrals run over the epoch. DW is always between 1.00 and 2.00.

04 Time-weighted balance

TWAB = (1 ÷ L) × ∫ b(t) dt        L = 28 days

A balance changes only at transfers, so the integral is exact: the sum of balance × duration over the intervals between transfers. This is equivalent to sampling every block, and there is no single moment worth timing.

05 Balance Weight

BW = TWAB                 if TWAB <= K
BW = sqrt(TWAB × K)       if TWAB >  K

K = 1,000,000 zc

Why the knee rather than a plain square root. Any curve that bends applied per address rewards splitting: n wallets of B ÷ n score √n times one wallet of B under a pure square root, all the way down to the smallest eligible balance. With a linear segment, splitting below K changes nothing. Ordinary holders have no reason to split at all, and only positions above K can gain, by at most √(B ÷ K).

06 Holder Score

S = BW × DW

Adding coins never lowers S. Below K, S equals the integral of weighted balance divided by L, and new coins add to it. Above K, with D = TWAB × DW, S = √K × D ÷ √TWAB. Adding coins raises TWAB by some x and D by at least x, and the change in S then has the sign of (2·TWAB − D) + x, which is never negative because DW ≤ 2. This is why the Duration Weight cap is 2.00 and not higher. The reference implementation tests the property on randomised histories.

07 Eligibility

An address is eligible for an epoch when all of these hold:

  • It is not on the published exclusion list.
  • Its time-weighted balance is at least the eligibility floor: To be announced. The floor keeps distribution economical; it is not set to exclude holders.
  • It holds $ZC at the epoch's closing block.

08 Excluded addresses

Burn addresses
0x0000…dEaD and the zero address. Burned coins are gone.
zipcoin privacy pool
The $ZC pool 0x6d0e…a422 and its Entrypoint 0x7a8D…9193. Zipped coins belong to notes, not addresses.
zipcoin spending contracts
ZipBroadcaster, ZipDoorstep, the Tellers and ZipHearth. They hold nothing between calls.
Liquidity and trading contracts
The Uniswap v4 PoolManager holding the pool's liquidity, the launch hook, and any router or pool contract holding $ZC for traders.
Treasury, team and prizes
The treasury, team wallets and prize deposits. zipcoin's @zipcoinbook already marks team wallets.
Exchange wallets
Centralised exchange deposit and hot wallets, where they can be identified from public labels.
Other shared custody
Any contract that holds $ZC on behalf of many users. A smart-contract wallet controlled by one holder is eligible.

The full list, with addresses, is published before each epoch opens.

09 Allocation

shareᵢ      = Sᵢ ÷ Σ S
allocationᵢ = pool × shareᵢ

Per-address cap: 5%proposed of the pool. Shares above the cap are fixed at the cap and the excess is shared among the remaining addresses in proportion to their scores, repeating until none exceeds it. If every address is capped, the remainder carries into the next epoch's pool.

10 Ranking

Eligible addresses are ordered by S, highest first. Equal scores share a rank. An address in rank r of N is in the top r ÷ N. Bands (top 1%, 5%, 10%, 25%, eligible) are labels on that percentile and play no part in allocation.

11 Anti-gaming

Buying just before close
Time-weighted balance counts only the time held, and new coins start at 1.00×.
Flash loans and same-block round trips
Zero time held, so zero contribution.
One very large address
Balance Weight grows with the square root above 1,000,000 zc, and the per-address cap holds any one address to 5% of a pool.
Splitting across addresses
No gain below the reference balance. Above it, the gain is at most √(B ÷ K), costs the holding age of every moved coin, and needs the eligibility floor in every address. A split position can at most recover its pro-rata share.
Cycling coins between own addresses
Moved coins restart at 1.00× in the receiving address. It can only lower a score.
Wash trading and volume
Volume is not an input. Each trade also pays the 1% swap fee.
Parking coins in pool contracts
Pool and custody contracts are excluded, and their depositors are not credited.

Splitting is limited, not prevented. Preventing it would need identity checks or wallet clustering, and this program uses neither. The ceiling matters more than the gap: the most a splitter can reach is roughly what a plain pro-rata system would have paid anyway.

12 Privacy

  • Inputs are limited to what Ethereum already makes public: $ZC balances and transfers. Nothing is added to them.
  • No KYC, no sign-up, no email, no IP-based checks.
  • No wallet clustering. Linking addresses by funding source, timing or behaviour is the same analysis zipcoin's privacy pool exists to defeat. Addresses are scored independently.
  • Zipped coins are not counted. A note is designed so nobody can tell which address it belongs to. Crediting it would mean undoing that.
  • Public results are aggregates by band. No balances, no exact scores and no full addresses are published by this site. Rankings list only addresses whose holders opt in.

Under consideration for later versions, not part of v0.1: a zero-knowledge proof that a zipped note has existed for a given time, so private holders could take part without revealing which deposit is theirs.

13 Verification

At each close, the following are published:

  • The opening and closing block numbers.
  • The exclusion list, with addresses.
  • The methodology version and the scoring code.
  • The total eligible Holder Score and the number of eligible addresses.
  • A commitment to the full allocation set, such as a Merkle root.

Anyone can recompute every score from public chain data. The reference implementation ships with this site's source as src/lib/score.ts, with tests. In zipcoin's words about its own numbers: the chain is the receipt.

14 Parameters

Holder Rewards parameters and their status
ParameterValue
Epoch length, L28 daysproposed
Reference balance, K1,000,000 zcproposed
Tenure ramp, T168 daysproposed
Duration Weight cap, W2.00×proposed
Per-address cap5%proposed
Eligibility floorTo be announced
Reward poolTo be announced
Reward assetTo be announced
Epoch 01 datesTo be announced

15 Known limitations

  • Holding age belongs to an address. A holder who moves to a new wallet starts again.
  • Using the privacy pool lowers a public balance. That is the honest trade for not tracing notes.
  • Coins held on an exchange earn nothing, even when they belong to a long-term holder.
  • Splitting above the reference balance is limited, not prevented.
  • zipcoin's own contracts are unaudited, as its docs state. Holder Rewards adds no contract that holds user funds.

holder rankings

Results, without exposing holders.

Balances on Ethereum are public, but this site does not turn them into a lookup tool. Results are published as aggregates. Individual addresses appear only by choice, and your own position is shown only to you.

Score distribution by band

No epoch closed

Holder Score distribution by percentile band

Published when Epoch 01 closes.

Opt-in listing

Abbreviated addresses, no balances

Addresses whose holders chose to be listed, by rank

No epoch has closed. Addresses appear here only if their holders choose to be listed.

about zipcoin

Money that speaks, from Snowmoon.

In Snowmoon, Vitalik Buterin's novel, payments are anonymous, people burn zipcoins to make a message worth reading, and sales tax reaches the government in real time. zipcoin ships that currency on Ethereum. It is not affiliated with the author.

  • zip

    Put $ZC, or ETH, into a privacy pool as a note. The deposit is public. What the note does next is not.

  • unzip

    Spend a note to any address, or to a zk.money tag on Aztec, with a zero-knowledge proof built in your browser.

  • speak

    Burn zipcoins to publish a message that cannot be deleted. The bigger the burn, the louder.

  • knock

    Burn at someone's door, an ENS name or an address, and optionally leave a gift.

Supply
1,000,000,000, fixed
Mint
None
Owner
None
Burns
To 0x…dEaD, permanent
Sales tax
0.5% of every trade, to the treasury
Network
Ethereum mainnet, ERC-20

All four verbs spend or move coins. Holder Rewards asks nothing of a holder except to keep them, and sits beside the book rather than inside it.

faq

Questions, answered plainly.

What are $ZC Holder Rewards?

A recurring zipcoin program that shares a reward pool among addresses that hold $ZC over time. In each reward epoch, every eligible address receives a Holder Score, and the pool is divided in proportion to those scores.

What determines my Holder Score?

Two things, multiplied. Your Balance Weight comes from your time-weighted $ZC balance across the epoch. Your Duration Weight comes from how long your coins have been in your address.

Does holding longer improve my score?

Yes. Each coin's Duration Weight rises evenly from 1.00× when it arrives to 2.00× after 168 days (proposed), then stays there. The cap stops very old positions from compounding without limit.

Does holding more $ZC improve my score?

Yes. Up to the reference balance of 1,000,000 zc (proposed), weight grows one for one with balance. Above it, weight grows with the square root, so a larger position always scores more, but four times the coins gives twice the weight.

Why isn't the score based only on balance?

A balance at one moment says nothing about ownership over time, and it can be bought minutes before a snapshot. A purely linear balance also lets the largest address take most of the pool. Time-weighting and diminishing returns address both.

What happens if I sell?

Your balance falls, so your time-weighted balance falls from that point on. Coins leave in proportion from every age, so selling 10% keeps the holding age of the remaining 90%. Selling everything resets holding age.

Does buying just before an epoch closes help?

Very little. A position counts only for the time it is held during the epoch, and new coins start at the minimum Duration Weight. Coins bought one day before close count for one day out of 28.

Can I raise my score by splitting my balance across wallets?

Below the reference balance, splitting changes nothing, because weight is linear there. Above it, splitting can recover part of the square-root reduction, but moved coins restart at 1.00×, every address must meet the eligibility floor on its own, and a split position can at most recover the share a plain pro-rata system would have given it.

What is a reward epoch?

A fixed measurement period, proposed at 28 days. Every eligible address is measured over the same block range. At close, scores are computed, results are published and allocations are distributed.

How is my allocation calculated?

Your Holder Score, divided by the total Holder Score of all eligible addresses, multiplied by the epoch's reward pool. No single address can receive more than 5% (proposed) of a pool.

How large is the reward pool?

It has not been announced. The size, asset and source of each epoch's pool will be published before that epoch opens.

Can I see my reward before connecting my wallet?

No. Before connection the site shows only the methodology. After connection, your Holder Score, rank and allocation are shown to you alone.

Do zipped coins count?

No. Zipped $ZC sits in the privacy pool, and notes are designed so that nobody can tell which address they belong to. Counting them would mean undoing that. Holder Rewards measures public balances only.

Will my address or balance be shown publicly?

No balances and no exact scores are published. Public results are aggregates by band. An address appears in the rankings list only if its holder opts in, and then only in abbreviated form.

Are protocol wallets eligible?

No. The burn address, the zipcoin privacy pool and its contracts, liquidity pool contracts, the treasury, team wallets and identifiable exchange wallets are excluded. The exclusion list is published for every epoch.

Is Holder Rewards staking?

No. Nothing is locked, deposited or delegated, and there is no contract to approve. Your coins stay in your own address and you can move them at any time. There is no fixed rate: what each address receives depends on the pool and on every other holder's score.

Is zipcoin affiliated with Vitalik Buterin?

No. Snowmoon is his novel. zipcoin is an independent project built on Ethereum.

View your holder position.

Connect your wallet to view your Holder Score, rank and allocation. Shown to you, and nobody else.

Read the methodology