Zcash Seals the Broken Pool: How Ironwood Fixes Four Years of Counterfeit Risk
2026-07-29Zcash just activated Ironwood, which means they've locked down the Orchard shielded pool and opened a fresh one. But this wasn't routine maintenance. Back in May 2026, Taylor Hornby found something genuinely terrifying: a vulnerability that let you mint unlimited, undetectable counterfeit ZEC. And it had been sitting there since May 2022.
Four years. That's the part that kills you. A zero-knowledge proof reveals nothing except that a transaction verified correctly, so the blockchain has no record of whether anyone actually minted counterfeit coins during those four years. No way to prove they didn't. A patch stops the bleeding, but it doesn't erase the wound or prove no damage was done. The market knew it—ZEC dropped 38%, from around $635 to $309 intraday, before stumbling back to $330.
This is where Ironwood gets clever. Zcash founder Zooko Wilcox proposed something that doesn't require proving counterfeit coins never existed. Instead, it contains them. The upgrade introduces a "turnstile" accounting system. Money moving into or out of a shielded pool is public, even when the transactions inside are private. So the network knows exactly how much ZEC went into Orchard. Ironwood won't release more than that. If counterfeit coins are lurking in the old pool, they're trapped there permanently. Problem solved through architecture, not archaeology.
The technical stack got upgraded too. The new pool's proof circuit—the code that validates every private transaction—underwent formal verification. That means mathematicians proved it works correctly in every possible case, not just the ones developers thought to test. Ironwood reuses the fixed Orchard circuit and Halo 2 proof system with minor tweaks, but now you've got mathematical certainty rather than just hopeful testing. The new pool also stays quantum-resistant by design. ZIP 2005 specified this from block one: every coin leaves a recovery record in case quantum computers eventually crack today's cryptography.
The schedule was insane. Fourteen ZODL engineers produced 82% of the merged changes to Zcash's protocol and wallet repos. Fifty-one developers total, writing code across 1,391 pull requests in 60 days straight. No breaks.
There's one wrinkle. On 28 July, when you migrate your shielded ZEC, your IP address can link to your balance. The Zcash team recommends using Tor or NymVPN during migration to plug that network-layer leak. It's temporary, but real.
What matters now is whether this actually works. Wallets, exchanges, and users need to move their Orchard balances without tripping up, and privacy needs to hold throughout. The broader test is harder: can formal methods and public turnstile accounting restore confidence in private digital money without gutting the secrecy they're meant to protect? Zcash just proved the plumbing works. Other projects building privacy into zero-knowledge systems are watching.
Source & further reading:
- Ark Invest buys $12 million in SpaceX as it trims Block, Bullish and Robinhood holdings — The Block
- Live updates: Bitcoin clears $64,000 in Asia hours ahead of Fed decision — CoinDesk
- Company behind AI trade that caused $60 million crypto liquidations to cover all losses — CoinDesk
- Citadel bets on a Fed rate hike Wednesday as bitcoin analysts call a hold. Someone will be wrong. — CoinDesk
- Bitcoin rises toward $64,000 as Korea's record chip crash leaves crypto untouched — CoinDesk
Sources
- Ark Invest buys $12 million in SpaceX as it trims Block, Bullish and Robinhood holdings
- Live updates: Bitcoin clears $64,000 in Asia hours ahead of Fed decision
- Company behind AI trade that caused $60 million crypto liquidations to cover all losses
- Citadel bets on a Fed rate hike Wednesday as bitcoin analysts call a hold. Someone will be wrong.
- Bitcoin rises toward $64,000 as Korea's record chip crash leaves crypto untouched