HomeCryptoZcash Ironwood upgrade: a 2,700-theorem proof blocks counterfeit ZEC

Zcash Ironwood upgrade: a 2,700-theorem proof blocks counterfeit ZEC

A theoretical flaw in one of Zcash’s most important privacy mechanisms pushed its developers into what some described as a wartime-mode sprint. The result is the Zcash Ironwood upgrade, a formally verified replacement shielded pool that activated at block height 3,428,143 as part of the NU6.3 network upgrade — and one of the most consequential security overhauls in the network’s history.

Key takeaways

  • The Zcash Ironwood upgrade activated at block height 3,428,143 via the NU6.3 hard fork, replacing the vulnerable Orchard shielded pool with a formally verified alternative.
  • Researcher Taylor Hornby discovered an “infinity” bug in Orchard in late May that could theoretically have allowed undetectable counterfeit ZEC creation.
  • A machine-checked mathematical proof consisting of more than 2,700 theorems confirms Ironwood cannot create undetectable counterfeit ZEC under its design assumptions.
  • Roughly 40,207 ZEC have migrated to Ironwood so far, while approximately 3.6 million ZEC remain in Orchard, which is now restricted to withdrawals only.
  • The upgrade makes Zebra the required node implementation, ending support for the older zcashd software.

What forced Zcash’s hand

The story begins in late May, when Taylor Hornby, a researcher at Shielded Labs, discovered what the Zcash community would come to call the Orchard “infinity” bug — a flaw deep inside Orchard’s zero-knowledge circuit that posed a theoretical risk of minting counterfeit ZEC without leaving any publicly detectable trace. No evidence emerged that the vulnerability had ever been exploited, but the mere possibility was damaging enough: ZEC lost more than half its value after the disclosure became public.

Emergency patches deployed in early June temporarily disabled Orchard, and a corrected circuit arrived through the NU6.2 hard fork within five days. But patching the circuit alone was not enough. Because of how Zcash’s privacy model works, developers said it was mathematically impossible to prove with certainty that hidden inflation had never occurred inside the old pool. That constraint made a full replacement — not just a fix — the only route to restoring verifiable supply integrity.

From patch to full replacement in 60 days

The decision to scrap and rebuild rather than patch and move on was the defining strategic call. Shielded Labs co-founder Zooko Wilcox initially proposed replacing Orchard outright, and what followed was roughly 60 days of coordinated development across Shielded Labs, the Zcash Open Development Lab (ZODL), Project Tachyon, Valar Group, and the Zcash Foundation.

ZODL Executive Director Josh Swihart stated that engineers from his organization contributed 82% of the merged changes across Zcash’s protocol and wallet repositories during the replacement effort. Shielded Labs Executive Director Jason McGee had flagged that infrastructure operators — exchanges, wallet providers, mining pools — were simultaneously switching from zcashd to the new Z3 software stack while also preparing for Ironwood, though no delay was ultimately called.

How Ironwood reshapes Zcash’s security model

Ironwood is not simply a patched version of Orchard. It introduces an entirely separate accounting system with its own note commitment tree, nullifier set, and chain value pool, allowing any node to track the new shielded pool independently from everything that came before it.

The upgrade also installs a public accounting checkpoint — described by the project as a turnstile. Funds can leave Orchard through that turnstile, but the mechanism mathematically prevents more value from exiting than legitimately entered the older pool. The intended effect is straightforward: any hypothetical counterfeit coins minted inside Orchard before or during the vulnerability window would be trapped there permanently, unable to contaminate Ironwood’s supply accounting.

Quantum-recoverable notes and future-proofing

Alongside the supply safeguards, the new pool incorporates ZIP 2005 quantum-recoverable notes. The feature does not make Zcash transactions quantum secure today — a separate recovery protocol would still need to be designed and activated in the future — but it establishes the cryptographic foundation for such a mechanism if advances in quantum computing eventually weaken current protections.

The NU6.3 upgrade also closes out a long-planned transition by making Zebra the required node implementation, ending support for the older zcashd software across the network.

Formal verification: the 2,700-theorem guarantee

The most technically distinctive element of Ironwood’s launch is the machine-checked mathematical proof completed by Project Tachyon alongside Zcash developers. Written in the Lean programming language, the proof consists of more than 2,700 theorems developed over more than a month by three teams of researchers and cryptographers — and it formally verifies that Ironwood cannot create undetectable counterfeit ZEC under its stated design assumptions.

The proof covers the components required for balance integrity: Ironwood’s zero-knowledge proof system, its circuit rules, and ledger-level accounting. Zcash co-founder Sean Bowe described the effort in pointed terms: “A cross-team collaboration has just changed Zcash’s history forever, eliminating all sources of undetectable counterfeiting bugs from the new Ironwood protocol.”

One important boundary to understand: the formal verification covers balance integrity but does not extend to Ironwood’s separate privacy guarantees. Supply soundness and transactional privacy are distinct properties, and the proof addresses only the former.

Migration status and what happens to Orchard

Orchard is now in an exit-only phase. The pool no longer accepts new shielded activity, but users can still withdraw funds at their own discretion. According to Zcash’s migration tracker, roughly 40,207 ZEC have already moved into Ironwood since activation. The much larger figure — approximately 3.6 million ZEC — remains inside Orchard awaiting migration, representing the bulk of what was once the network’s primary privacy pool.

At its peak, Orchard accounted for nearly 88% of Zcash’s shielded token supply, according to data from The Block, with the older Sapling and Sprout pools making up the remainder. The scale of that legacy position means migration will take time, and the transition’s pace will likely become one of the clearer signals of how much confidence users have restored in Zcash’s privacy infrastructure after the vulnerability scare.

With the turnstile in place and formal verification underpinning the new pool’s supply model, the engineering work is done. The remaining question is how quickly the broader Zcash ecosystem closes the gap between the 40,000 ZEC that have already moved and the 3.6 million still waiting on the other side of it.

FAQ

What is the Zcash Ironwood upgrade?

Ironwood is a Zcash network upgrade that replaced the vulnerable Orchard shielded pool with a formally verified shielded pool, enhancing supply security and maintaining privacy. It activated at block height 3,428,143 as part of the NU6.3 hard fork.

Why was the Ironwood upgrade necessary?

The upgrade was needed because an “infinity” bug discovered in the Orchard pool in late May posed a theoretical risk of undetectable counterfeit ZEC creation. Because Zcash’s privacy model made it impossible to prove the bug was never exploited, developers replaced Orchard entirely rather than relying solely on a patch.

Can Ironwood still create counterfeit ZEC?

According to a machine-checked mathematical proof completed by Project Tachyon and Zcash developers — consisting of more than 2,700 theorems written in Lean — Ironwood cannot create undetectable counterfeit ZEC under its design assumptions. The proof covers balance integrity but does not extend to Ironwood’s separate privacy guarantees.

What happens to funds still in the Orchard pool?

Orchard has entered an exit-only phase. Users can still withdraw funds from it, but the pool no longer accepts new shielded transactions. Approximately 3.6 million ZEC remain in Orchard awaiting migration to Ironwood, while about 40,207 ZEC have already moved across.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Stefania Stimolo
Stefania Stimolo
Graduated in Marketing and Communication, Stefania is an explorer of innovative opportunities. She started out as a Sales Assistant for e-commerce, and in 2016 she began to develop a passion for the digital world, initially in the Network Marketing sector, where she discovered and became passionate about the ideals behind Bitcoin and Blockchain technology, which lead her to work as a copywriter and translator for ICO projects and blogs, and organize introductory courses.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST