VERSE PRESS

Crypto News, Global First.

Zcash Activates Ironwood Upgrade, Sealing Off $1.7 Billion Pool That Harbored a Four-Year Vulnerability

A new shielded pool went live on the Zcash network Monday after developers permanently closed its predecessor, which had harbored an undetected counterfeiting flaw since 2022.

|

At block 3,428,143, reached around 13:00 UTC on July 28, 2026, Zcash activated its Ironwood network upgrade (NU6.3). The upgrade sealed the Orchard shielded pool, which held approximately 3.66 million ZEC (worth roughly $1.7 billion at current prices) and had contained a critical flaw capable of producing undetectable counterfeit coins. No evidence of exploitation was found on-chain, and the Zcash Foundation confirmed that no user privacy was compromised, though the vulnerability's nature means cryptography alone cannot establish that with absolute certainty. Ironwood replaces Orchard with a new pool and introduces a public accounting checkpoint designed to prevent any hypothetical counterfeit coins from crossing over.

How the Bug Was Found and What It Could Do

Shielded Labs, a nonprofit Zcash developer organization, hired security engineer Taylor Hornby in April 2026 with a specific mandate: find protocol-level flaws before bad actors could. On May 29, working with Anthropic's Claude Opus 4.8 AI model, Hornby identified what has since been called the "infinity bug."

The flaw sat inside Orchard's Action proof circuit, a core piece of the cryptographic machinery that validates shielded transactions. A missing constraint in the circuit, present since Orchard launched in May 2022, would have allowed an attacker to mint unlimited ZEC inside the shielded pool without any detectable on-chain trace.

Hornby built a working exploit in a local test environment to confirm the finding. Project Tachyon, a Zcash-affiliated research group, classified the vulnerability as a "specification-level undetectable counterfeiting bug," the most severe category in their taxonomy. Shielded Labs noted in its June disclosure that "[The bug] had evaded years of scrutiny by experienced cryptographers and only surfaced with cutting-edge AI tools and highly skilled researchers." The organization also offered a direct public assessment of the timeline: "We think he [Taylor Hornby] probably succeeded" in finding the vulnerability before bad actors did.

The Emergency Response and What Ironwood Changes

Developers moved quickly after the disclosure. An emergency soft fork in early June temporarily disabled Orchard pool transactions. A mid-June hard fork added circuit-level security measures. The Zcash Foundation then published its technical roadmap for the Ironwood upgrade in early-to-mid July (July 10–16), with an original activation target of July 21 that was pushed back one week for additional testing.

Ironwood reuses Orchard's Action circuit and Halo2 proof system but rebuilds the state layer from scratch: a new note commitment tree, nullifier set, chain value pool, and chain-history metadata.

The critical addition is the turnstile, a public accounting checkpoint at the boundary between the old Orchard pool and the new Ironwood pool. Any ZEC moving from Orchard to Ironwood must pass through this checkpoint, and the total amount withdrawable is capped at the verifiably deposited amount. The practical effect is that any counterfeit coins hypothetically created inside Orchard are permanently stranded there. As CoinDesk summarized the logic: "Any counterfeit coins sitting inside [the Orchard pool] are stuck there."

Two additional security measures accompany the new pool. Note commitments are structured to remain recoverable if quantum computing eventually breaks current cryptographic assumptions (ZIP 2005). Project Tachyon is also conducting formal algebraic verification of the Ironwood circuit, a more rigorous process than standard security audits, intended to capture both circuit errors and flaws in the underlying proof protocol.

What Operators and Developers Need to Do Now

All node operators must run Zebra 6.0.0, the Zcash Foundation's updated reference software, to remain in consensus with the upgraded network. The state database format bumped to version 28.0.0 with an in-place migration that avoids a full node resync. Wallet software is expected to handle the Orchard-to-Ironwood migration automatically for most end users, but developers building on Zcash APIs should review updated RPC endpoints including z_gettreestate, z_getsubtreesbyindex, and getblock.

Ledger hardware wallet support for Ironwood transactions is confirmed, following the merge of PR #32 in the LedgerHQ/ledger-zcash-utils repository.

The upgrade is especially time-sensitive for infrastructure operators in Africa. Obscura Labs, a Zcash-focused organization registered in Nigeria in June 2026, runs DNS seeders, Zebra nodes, and public RPC endpoints across African markets. All of that infrastructure requires the Zebra 6.0.0 upgrade to stay synchronized with the network. The broader African Zcash community is expanding, with regional chapters in East Africa, Kenya, Nigeria, and a newly launched Pretoria group that held its first event this month. A community organizer with Zcash South Africa wrote on the Zcash Community Forum: "We are also currently planning an upcoming university rally/event and we look forward to contributing more to Zcash adoption in Africa."

What Comes Next

The supply audit is incomplete. Only 1,500 ZEC had migrated to the Ironwood pool at the time of activation, against a total Orchard pool of 3.66 million ZEC. A full picture of whether any unauthorized supply was created inside Orchard will only emerge as migration proceeds over the coming weeks and months. ZEC was trading near $463 at activation, down roughly 8% on the day and 15% over the prior week, though the asset had risen approximately 10x over the prior year before the vulnerability disclosure.

The turnstile mechanism also introduces a new argument for privacy coin advocates in regulatory conversations, particularly in markets such as India where privacy coins face restrictions under FATF-aligned compliance frameworks. In Pakistan, Bangladesh, and Sri Lanka, where crypto regulatory frameworks are less formalized and privacy coins are less explicitly targeted but also less accessible due to limited exchange infrastructure, community-level peer-to-peer adoption may benefit from the restored confidence in ZEC supply integrity that Ironwood provides. Ironwood does not make shielded transactions transparent, but it does demonstrate that a privacy-preserving protocol can offer publicly verifiable accounting for cross-pool fund flows. Whether that distinction will matter to regulators across South Asia and Africa remains an open question.