Zcash activated its Ironwood upgrade at block 3,428,143 on Tuesday, permanently sealing the Orchard shielded pool that held approximately 3.66 million ZEC — roughly $1.7 billion at current prices — and opening a new private pool that started with zero coins.
The upgrade, formally designated NU6.3, represents one of the most consequential changes in Zcash's decade-long history. It was driven by the discovery of a previously undetected bug in Orchard's proof circuit that could have allowed the creation of counterfeit ZEC without leaving any on-chain trace.
The Bug That Went Unnoticed for Four Years
On May 29, Shielded Labs researcher Taylor Hornby discovered that Orchard's zero-knowledge proof circuit contained a flaw that would let an attacker mint counterfeit tokens. The vulnerability had been live since Orchard launched in May 2022 — four years during which an unknown quantity of fraudulent coins could theoretically have been created.
Evidence strongly suggests the bug was never exploited. Orchard's balance grew steadily throughout the four-year window, including through last year's price rally when cashing out counterfeit coins would have been most profitable. If someone had minted fake ZEC, the obvious move would have been to withdraw and sell it, which would have shown up as funds leaving the pool. That never happened.
But certainty is impossible in a system designed to hide information. A zero-knowledge proof reveals nothing beyond the validity of the transaction it verifies. The chain holds no record of whether any specific Orchard transaction actually moved real coins. Nobody can prove counterfeit coins were never created.
The Turnstile Solution
Ironwood's answer to this fundamental uncertainty is architectural. The new pool begins empty. Every coin must be moved across by its owner, and the only route out of Orchard is a turnstile — an accounting rule at the pool's boundary that caps total withdrawals at the amount verifiably deposited.
Shielded pools are the private side of Zcash, where transaction amounts and participant identities are hidden. A zero-knowledge proof provides evidence that deposited amounts are reflected in the public supply without revealing the specifics. Because money crossing between pools is public even when internal transactions are not, the network knows precisely how much ZEC entered Orchard and will not release more than that amount.
Any counterfeit coins sitting inside Orchard are now permanently trapped. The pool is sealed. Nothing can be added, and withdrawals are capped at verified deposits. As of activation, approximately 1,500 ZEC had already migrated to the new pool.
Quantum Resilience and Formal Verification
Ironwood launched with two protections Orchard never had. First, the record each coin leaves on the chain is built to remain recoverable even if quantum computers eventually break the cryptography currently securing it — a property specified under ZIP 2005 and active from the first block.
Second, the pool's proof circuit is undergoing formal verification, a rigorous mathematical process that proves software behaves correctly in every possible case rather than only in the scenarios a tester thought to examine. The aim is to eliminate the entire class of bugs that broke Orchard — the kind that can sit undetected for years in code that appears to work perfectly.
ZEC traded near $463 ahead of the switch, down 8% on the day and 15% over the week, though the token remains up roughly tenfold over the past year.
What to Watch
The critical metric from here is migration speed. The 3.66 million ZEC currently locked in Orchard will not move to the new pool automatically. Migration is voluntary and user-driven, and until it happens, the bulk of Zcash's private supply sits in a sealed pool that nobody can add to and that will only release verified funds.
How quickly users move their assets — and whether the formal verification process delivers on its promise of ruling out another Orchard-scale bug — will determine whether Ironwood succeeds at what it was designed to do: restoring trust in a privacy system that came uncomfortably close to a catastrophic failure.