Privacy Coins Security

Zcash Seals the Orchard: How a Counterfeiting Bomb Got Defused

2026-07-29

Zcash just activated its Ironwood network upgrade at block 3,428,143, and it's worth understanding why. Two months earlier, someone discovered that the entire Orchard shielded pool—holding about 3.66 million ZEC—had been sitting on a critical counterfeiting vulnerability since May 2022. Four years. Undetected.

On May 29, 2026, Taylor Hornby found it. The vulnerability was bad enough that Hornby and Opus 4.8 wrote a complete exploit that, when tested locally, generated unlimited undetectable counterfeit ZEC. Let that sink in: if someone had exploited this before discovery, there would have been no way to prove it ever happened. Permanent uncertainty about the money supply. That's existential for a privacy coin.

The market figured it out immediately. Zcash dropped from $635 to $309 in a day. Panic. But here's where Zcash's response gets clever.

Instead of nuking Orchard entirely, the Ironwood upgrade implements a turnstile mechanism. Simple idea, elegant execution: no more ZEC can leave the old pool than was legitimately deposited. Any surplus—including any counterfeit coins that might exist—stays locked forever. Honest users migrate to a new formally verified shielded pool while the compromised one becomes read-only for withdrawals. The counterfeits, if they exist, become permanently trapped.

The new pool includes patched zero-knowledge circuits and quantum-recoverable notes under ZIP 2005, giving users a theoretical recovery path if quantum computing eventually breaks current cryptography. Multiple audits and formal circuit verification happened before activation. This wasn't a quick patch job.

The ecosystem coordinated properly. Shielded Labs, Project Tachyon, Valar Group, the Zcash Foundation, and wallet provider Zodl all aligned on the upgrade. The market liked it—Zcash recovered roughly $2.5 billion in market value by early June.

Then privacy advocates raised something obvious: migrating money out of the old pool is visible on chain. Anyone sees the amount. Your wallet talks to a server, which sees your IP. Connect those dots and someone ties your balance to you. Not ideal for a privacy coin. Zcash founder Zooko Wilcox recommended users route through Tor or Nym before migrating. The irony is loud.

Worth noting: no evidence has surfaced that the Orchard bug was actually exploited. But the upgrade's design means users can verify this claim as migration proceeds. The turnstile does the accounting.

This is security incident response done right. A catastrophic vulnerability gets found, the ecosystem mobilises, and a technically sound solution emerges. Not perfect—privacy leakage during migration is real—but a lot better than the alternative.


Source & further reading:

Sources