Zcash Ironwood upgrade goes live after counterfeiting scare
Zcash activated Ironwood to isolate its old private pool after a flaw raised doubts about whether counterfeit ZEC existed.
By Sofia Marchetti · Columnist
· 3 min read
Zcash has activated the Zcash Ironwood upgrade, a network change meant to contain any counterfeit ZEC that may have been created through a previously disclosed flaw. For investors, the key issue is supply trust: if a cryptocurrency’s supply cannot be verified, its price can come under pressure fast.
The upgrade replaces Zcash’s Orchard shielded pool, the privacy-preserving system used to hide transaction details, with a new private pool. According to Decrypt, Orchard holds about 3.7 million ZEC, valued at roughly $1.7 billion.
Zcash is built around shielded transactions, which conceal information such as amounts and addresses. That privacy is the product’s core feature, but it also made the recent vulnerability harder to resolve because observers could not prove whether the bug had been used.
What is the Zcash Ironwood upgrade?
Ironwood is a Zcash network upgrade that moves users out of the Orchard shielded pool and into a new shielded pool. It also adds accounting rules intended to stop more ZEC from exiting the retired pool than can be verified as having entered it.
Zcash founder Zooko Wilcox proposed a “turnstile” system for the migration, according to Decrypt. In plain terms, the turnstile acts like a supply checkpoint: valid coins can move through, while any coins that cannot be accounted for would remain stuck in the old pool.
That design is meant to preserve privacy while addressing the supply question created by the Orchard bug. If counterfeit ZEC exists, Ironwood is intended to keep those coins from reaching circulation.
How did Zcash get here?
The problem began with a vulnerability discovered in May by security researcher Taylor Hornby, who used Anthropic’s Claude Opus 4.8, according to Decrypt. The flaw had existed for four years and could have allowed an attacker to create fake ZEC inside Orchard.
Developers released an emergency patch in June. Because shielded transactions hide transaction data by design, the Zcash community still could not confirm whether anyone had exploited the vulnerability before the patch.
That uncertainty hit the market. Decrypt reported that ZEC fell 38% as investors weighed whether the token’s circulating supply could be trusted. After Ironwood was proposed, Zcash recovered about $2.5 billion in market value in early June, according to Decrypt.
Decrypt reported that ZEC recently traded around $464, with its market capitalization just under $8 billion. Price moves around security upgrades can reflect both technical risk and investor confidence, especially for privacy coins where outsiders cannot inspect every transaction in the same way they can on fully transparent blockchains.
What else changes with Ironwood?
Ironwood also brings quantum-resistant transaction records and a formally verified proof circuit, according to Decrypt. Quantum-resistant records are designed to reduce future risk from more powerful computers, while formal verification means developers used mathematical methods to check that critical cryptographic code behaves as intended.
The migration has drawn criticism from privacy infrastructure provider Nym. In a Monday blog post, Nym said normal shielded ZEC transactions do not reveal transaction amounts to a wallet server, but Ironwood changes the risk profile during the move to the new pool.
Nym said users who migrate without extra protections could expose information that links an IP address to a wallet balance. The concern is temporary and tied to the required migration, but it shows the tradeoff Zcash is trying to manage: fixing a supply-confidence problem without weakening the privacy that gives the network its identity.
This story draws on original reporting from Decrypt.