Privacy Coins

Privacy Coins Roundup: Zcash's Ironwood Fork, Russia's New Ban and a Sector on Edge

2026-07-22

The privacy coin sector is bracing for one of its busiest stretches in months, with Zcash rushing to finish a major protocol overhaul just as Russia's parliament wrote a formal ban on privacy-preserving cryptocurrencies into law. The two developments, arriving within days of each other in late July, capture the tension defining the space: fast-moving cryptographic innovation running headlong into tightening global regulation.

Zcash's most pressing story is the Ironwood upgrade, a hard fork targeted for activation around July 28. The upgrade was fast-tracked after a critical bug in Zcash's Orchard shielded pool was disclosed on June 5, 2026, triggering a crash of more than 40% before developers patched it within days. A second flaw compounded the damage: a separate vulnerability tracked as CVE-2026-34202, carrying a severity score of 9.2, allowed a single malformed Orchard transaction to crash any reachable node, creating a denial-of-service risk and a consensus gap between Zcash's two node implementations, zcashd and Zebra. Both bugs were patched, but the episode rattled confidence in the network's core privacy mechanism.

Ironwood is designed to draw a line under the incident. Zcash will activate the Ironwood (NU6.3) network upgrade on July 28, 2026, permanently sealing the old, vulnerable Orchard pool and introducing a "turnstile" mechanism that forces all shielded coins to migrate through a checkpoint verifying legitimate supply and destroying any counterfeit ZEC. Zcash co-founder Zooko Wilcox has publicly confirmed that the July 28, 2026 Ironwood hard fork will freeze any potentially forged ZEC coins due to a past vulnerability in the Orchard pool. Developer Sean Bowe has been leading a parallel effort under "Project Tachyon" to mathematically prove the new pool's soundness; researchers say they are close to a formal mathematical proof that Ironwood cannot suffer the same counterfeiting-style vulnerability. The fork coincides with the retirement of Zcash's legacy software: the Zcash ecosystem completed its migration to Rust-based infrastructure as zcashd reached end of life on July 18, with Zebra becoming the only supported node implementation participating in the network. Markets have responded with cautious optimism — futures open interest has climbed toward $980 million, and early July saw ZEC lead a broader privacy-coin rebound alongside Monero and Bitcoin Cash after months of underperformance.

That rebound is now colliding with fresh regulatory friction. Russia's State Duma gave final approval on July 21 to its first comprehensive crypto law, "On Digital Currency and Digital Rights," which explicitly locks privacy coins out of the legal market. Under the bill, professional investors face no annual purchase cap, but even they cannot buy privacy coins — cryptocurrencies engineered to obscure transaction details such as Monero, Zcash and Dash. Eligible assets must also clear steep liquidity thresholds; lawyers tracking the bill say the practical effect for now is a cryptocurrency needing a market capitalization above 5 trillion rubles — roughly $65 billion — and at least five years of verified trading history on a licensed foreign exchange, narrowing the field to two: Bitcoin and Ethereum. Ordinary retail investors face a separate cap of roughly $3,800 a year in purchases. The law is expected to take effect September 1, 2026, once it clears the Federation Council and receives Putin's signature — a step lawmakers consider a formality.

Russia joins a growing list of jurisdictions squeezing privacy coins out of regulated markets rather than banning them outright. The Philippines' central bank moved first this summer, with new guidelines banning Virtual Asset Service Providers from listing or supporting anonymity-enhancing cryptocurrencies like Dash — a decision that pushed Dash's global adoption lead to tell Philippine Blockchain Week attendees the project is now prioritizing legal compliance and has prepared a formal legal opinion for regulators. That follows a pattern set by Japan and South Korea years earlier, and echoed by Coinbase's own delisting of Monero, Zcash, Dash and Horizen from its platform earlier this year on the grounds the assets "no longer meet our listing standards."

Monero, meanwhile, continues to absorb the fallout from that wave of exchange exits while pressing ahead on its biggest technical overhaul yet. Developers are advancing FCMP++, an upgrade intended to expand Monero's anonymity set from 16 outputs to more than 150 million across its full chain history, with an alpha stressnet already live. The July release of GUI/CLI v0.18.5.1, dubbed "Fluorine Fermi," delivered stability fixes and hardened the network's defenses against spy nodes attempting to de-anonymize transactions. Community trackers note that roughly 73 exchanges delisted XMR in 2025 alone, a trend that has pushed users toward decentralized swaps and self-custody rather than dampening development activity.

Taken together, the last two weeks underline a familiar split-screen for privacy coins: engineering teams racing to harden their protocols and repair trust after security scares, even as regulators in Moscow, Manila and beyond move to wall these assets off from licensed markets entirely. With Ironwood activating within days and Russia's law due in September, both storylines are set to reach milestones before the summer is out.


Source & further reading:

Sources