Privacy Coins Security

Zcash Seals Off the Buggy Pool: $1.7B Orchard Locked, Ironwood Rolls Out

2026-07-29

Zcash just flipped the switch on Ironwood (NU6.3), and with it came a hard truth: the privacy coin world nearly had a disaster on its hands. The old Orchard pool—stuffed with 3.66 million ZEC worth about $1.7 billion—is now sealed tight. A new one starts from zero. Block height 3,428,143, July 28. That's when everything changed.

Here's what happened. Four years. That's how long a critical counterfeiting bug sat in Orchard completely undetected. It launched in May 2022, and security researcher Taylor Hornby found it during a Shielded Labs audit on May 29. The flaw was real, exploitable, and lethal: someone could have generated unlimited counterfeit ZEC inside Orchard without leaving a trace. Multiple audits had missed it entirely.

The market noticed. ZEC tanked roughly 38% after the disclosure. Panic made sense on paper. But here's the interesting bit: no one actually exploited it. CoinDesk Research looked at the evidence in July and found nothing. If counterfeiters had struck, they'd have needed to move coins out eventually—and outflows would show. Instead, Orchard's balance climbed steadily for four years, even when selling counterfeit coins would have been profitable. The coins just weren't there.

So Zcash built a turnstile. It's not flashy, but it's clever: an accounting rule that sits at Orchard's boundary and locks down a simple principle. Total withdrawals cannot exceed total verifiable deposits. Ever. A counterfeiter's trapped either way—leave fake coins in the pool forever, or try to move them and get caught. It's elegant in its restraint.

Ironwood opened with a clean slate. Zero ZEC. Every single coin has to be manually migrated across by its owner. As of press time, only 1,500 ZEC had moved over. That's barely a start. How fast the migration happens depends entirely on voluntary participation, and that pace will determine when Zcash truly leaves the vulnerability in the rearview.

The upgrade adds two more layers. The circuit design now includes quantum-resilient recovery records—meaning even if quantum computers eventually break today's cryptography, coin ownership remains provable. That follows ZIP 2005 specs and is live from block one. Not bad.

Beyond that, Shielded Labs and Project Tachyon are pursuing something more ambitious: a machine-checkable mathematical proof that Ironwood's circuit has zero under-constrained vulnerabilities. Zooko Wilcox-O'Hearn said in July they're "on the verge" of actually proving it. If they pull that off, we're looking at something genuinely new in crypto—not just "we hope we got it right," but "we proved it mathematically."

The real tension here is this: privacy coins can't rely on transparent ledgers to catch counterfeiting. Everyone can see Bitcoin's supply on chain. Monero can't do that—the whole point is secrecy. So Zcash had to invent a new solution: let users verify supply without revealing transaction details. The turnstile does exactly that.

Months of uncertainty led to this moment. The emergency patch landed in June, but Ironwood is the actual closure—the community's way of saying we've learned something, and we're moving on. Whether people actually migrate their coins fast enough is the open question now.


Source & further reading:

Sources