Zcash Activates Ironwood Upgrade to Fix Critical Shielded Pool Vulnerability

A security researcher found a bug that could have let someone print fake privacy coins with zero trace on the blockchain. Zcash’s response: rebuild the entire shielded pool from scratch.
Zcash activated its Ironwood upgrade, formally designated NU6.3, on July 28 at block height 3,428,143, a security-driven overhaul of the network’s privacy infrastructure following the discovery of a critical vulnerability in its existing shielded pool design.
The vulnerability traces back to late May 2026, when independent researcher Taylor Hornby, working with security-focused organization Shielded Labs, discovered a soundness flaw in the zero-knowledge circuit underlying Zcash’s Orchard shielded pool. The bug could theoretically have allowed someone to create counterfeit ZEC within the shielded pool without leaving any trace on the public blockchain — a serious threat to the core supply-integrity guarantee that any cryptocurrency depends on.
Ironwood’s fix centers on a new shielded pool alongside a turnstile mechanism that caps how much value can exit the old Orchard pool to no more than what was verifiably deposited into it in the first place. New deposits and internal transfers within Orchard are no longer permitted; the pool is now limited primarily to withdrawals as users migrate to the new Ironwood pool. That accounting checkpoint creates an independently verifiable boundary on circulating supply, closing the specific gap the vulnerability had opened.
The stakes were sizable: the Orchard pool being retired held roughly 3.7 million ZEC, worth about $1.7 billion, meaning the upgrade needed to migrate a genuinely significant amount of value without disrupting the privacy guarantees that are Zcash’s entire reason for existing.
Market reaction has been cautiously positive — ZEC posted gains following the upgrade’s rollout, breaking a bearish stretch that had followed the initial vulnerability disclosure, as the successful, verifiable fix helped restore some confidence in the coin’s monetary integrity.
The episode is a pointed reminder that privacy-preserving cryptography is genuinely difficult to get right: a subtle flaw in a zero-knowledge proof system can sit undetected for years, and fixing it after the fact requires exactly the kind of careful, verifiable supply-accounting mechanism Ironwood introduces.
Want to understand how zero-knowledge proofs actually enable privacy in a cryptocurrency like Zcash? Learn more in the Bitcoin Academy.
