Zcash Plugs the Infinity Bug With Ironwood—How to Fix Privacy Without Breaking Trust
2026-07-29Zcash started as Bitcoin's fix-it project. Bitcoin's transparent ledger felt too exposed for some people, so in October 2016 the Electric Coin Company launched Zcash with zero-knowledge proofs—zk-SNARKs, to be precise—that let you prove a transaction was legit without spilling the sender, recipient, or amount. You could go full transparent if you wanted. Or fully private. That flexibility made Zcash easier for regulated exchanges to stomach than Monero, which most institutions won't touch.
The launch itself involved a weird bit of cryptographic theatre. Six participants each generated and destroyed part of a private key—a "trusted setup ceremony"—to ensure nobody could counterfeit ZEC. In April 2022, the mystery sixth participant was revealed. Edward Snowden. The NSA whistleblower had quietly helped launch Zcash as a public good, because he believed in privacy.
Fast forward to May 2026. Researcher Taylor Hornby found an "infinity" bug in Orchard, Zcash's shielded pool. This wasn't a small thing. It could theoretically have let someone mint undetectable counterfeit coins. The vulnerability had been sitting there since Orchard activated in May 2022—four years of potential exposure. ECC patched it in June, but here's where privacy bites back: because Orchard transactions are private, there was no cryptographic way to prove whether anyone had exploited the bug before the fix dropped. The market didn't wait for reassurance. ZEC tanked 50% in a day—from $602 to $299.
This exposed the core tension in privacy coins. Privacy guarantees prevent observation from outside. They also prevent the network from proving counterfeit coins don't exist. Zcash had built something that was bulletproof on privacy but helpless on auditability. You couldn't have both. Or so everyone thought.
Zooko Wilcox proposed Ironwood as the answer. Instead of junking privacy altogether, Ironwood replaces Orchard with a new shielded pool plus a "turnstile" accounting system. The turnstile is the clever bit—it prevents more ZEC from leaving the old pool than can be verifiably proven was deposited. You get privacy and cryptographic proof that the supply wasn't secretly inflated. On July 28, the NU6.3 upgrade went live at block height 3,428,143.
What Ironwood actually does: it introduces quantum-resistant transaction records, formally verified cryptography, and—here's the kicker—a machine-checked mathematical proof made of more than 2,700 theorems confirming the upgrade can't create undetectable counterfeits under its design assumptions. The Orchard pool, which held roughly 3.7 million ZEC worth about $1.7 billion, is now restricted to withdrawals only. New shielded payments go into Ironwood. The upgrade pulled in talent from Zcash Open Development Lab, Project Tachyon, Valar Group, the Zcash Foundation, and Shielded Labs—a rare unified push across the ecosystem.
Whether Ironwood actually threads the needle between privacy and regulatory acceptability is still an open question. Privacy advocates will watch for any compromise on anonymity. Regulators will watch to see if "verifiable supply" is really verifiable. Zcash is attempting something that's historically forced developers to choose—you picked privacy or you picked auditability, not both. This time they're trying to have it all. The activation marks a significant shift in how privacy blockchains handle trust.
Source & further reading:
- SoFi crypto transaction revenue grows 10% to $134 million in Q2 — The Block
- The traditional 9-to-5 banking day is officially dying, says Morgan Stanley execs — CoinDesk
- Stablecoin firm Brale says new protocol can remove a major hurdle to scaling custom tokens — CoinDesk
- Coinbase hit by spot trading slump: Wall Street trims expectations ahead of earnings — CoinDesk
- Crypto Long & Short: What this year's $972 million crypto hacks actually tell us about security — CoinDesk
- What is Zcash (ZEC)? The Privacy Coin Using Zero-Knowledge Proofs — Decrypt
- Zcash Ironwood Upgrade: What ZEC Holders Need to Know? — Bitrue
- Zcash Activates Ironwood Upgrade After Counterfeiting Scare — Decrypt
- Ironwood Goes Live as Zcash Locks Down Orchard and Forces a $1.8B Migration — Bitcoin.com News
- Zcash Ironwood upgrade Secures Network with Verified Shielded Pool — Cryptonomist
- Edward Snowden Helped Create Zcash Privacy Coin — Decrypt
- Zcash activates Ironwood upgrade, launching new shielded pool after Orchard vulnerability — The Block
- Zcash Ironwood Launches Tuesday: Supply-Verification Checkpoint Closes Four-Year Flaw — Tech Times
Sources
- SoFi crypto transaction revenue grows 10% to $134 million in Q2
- The traditional 9-to-5 banking day is officially dying, says Morgan Stanley execs
- Stablecoin firm Brale says new protocol can remove a major hurdle to scaling custom tokens
- Coinbase hit by spot trading slump: Wall Street trims expectations ahead of earnings
- Crypto Long & Short: What this year's $972 million crypto hacks actually tell us about security
- What is Zcash (ZEC)? The Privacy Coin Using Zero-Knowledge Proofs
- Zcash Ironwood Upgrade: What ZEC Holders Need to Know?
- Zcash Activates Ironwood Upgrade After Counterfeiting Scare
- Ironwood Goes Live as Zcash Locks Down Orchard and Forces a $1.8B Migration
- Zcash Ironwood upgrade Secures Network with Verified Shielded Pool
- Edward Snowden Helped Create Zcash Privacy Coin
- Zcash activates Ironwood upgrade, launching new shielded pool after Orchard vulnerability
- Zcash Ironwood Launches Tuesday: Supply-Verification Checkpoint Closes Four-Year Flaw