Zcash seals its shielded pool and starts counting: inside the Ironwood turnstile
Zcash activated Ironwood today at block 3,428,143, sealing the Orchard shielded pool and metering every coin out through a turnstile. The counterfeiting flaw behind it sat undiscovered for years and was found in May by a researcher working with an AI model.
Listen to this article

Zcash activated a hard fork today called Ironwood, at block 3,428,143, shortly after 14:00 UTC. It closes the pool where most shielded ZEC has been sitting, opens a fresh one, and makes every coin that wants to leave the old pool walk through a counter.
The reason is a counterfeiting flaw.
The bug
On 29 May 2026, Taylor Hornby, a security researcher at Shielded Labs, was running what the disclosure calls “a highly targeted review of the Orchard circuit” using Anthropic’s Opus 4.8. He found what the Zcash developers later described as “an under-constrained element of the Orchard circuit” that permitted “arbitrary false inputs into an elliptic curve multiplication” while still passing verification.
In practice, that means the zero-knowledge proof that is supposed to guarantee a shielded transaction is honest could be satisfied by a dishonest one. Someone who found the flaw first could have minted ZEC that never existed, inside the pool, where nobody can see balances. The flaw had been present for years.
Hornby disclosed it immediately. An emergency remediation was completed on 2 June, and the disclosure went public on 4 June in a joint post from Zooko Wilcox, Jason McGee and Hornby himself.
The uncomfortable part is what came next. The developers’ stated position is that “our assessment is that exploitation of this vulnerability was unlikely.” They then say the thing a less careful project would have left out: “due to the privacy properties of Orchard and the nature of the bug, there is no definitive way to determine using only cryptography whether such exploitation occurred.”
Privacy cuts both ways. The property that stops anyone seeing your balance also stops anyone proving the total is honest.

What the turnstile does
Ironwood is not a patch bolted onto the old pool. It is a new shielded pool running the same Orchard protocol, starting from zero, with the flaw fixed. From activation, wallets stop sending and receiving inside old Orchard; payments to an Orchard address route into Ironwood instead.
The old pool is sealed on the way in and metered on the way out. That meter is the turnstile, and Sean Bowe and Dev Ojha describe the principle as an arrangement where “any funds that enter or leave a pool are publicly tallied such that the amount of funds (supposedly) within a given pool is known with certainty at all times.”
The turnstile cannot see who owns what. It enforces one rule: no more ZEC can come out of the old pool than went in. If counterfeit coins were ever created in Orchard, they are now trapped behind a door that will not let the total exceed the honest figure. And as real holders migrate their funds across, the gap between what leaves and what should be there becomes a measurable signal rather than an open question.
That is the elegant part. The upgrade does not just fix the flaw. It converts an unanswerable question into an audit that runs in public, at whatever pace holders choose to move.
What holders and exchanges do
Users do not need to do anything for the fork itself. Wallets and exchanges needed to upgrade their software, which is why activation was pushed back a week to give them room.
Holders with funds in the old Orchard pool do need to migrate them, and there is no deadline. There is a precedent for how that goes: when Zcash retired its first shielded pool, Sprout, roughly 25,000 ZEC were still sitting in it eight years later. Some coins never move, because some keys are gone.
Anything left behind becomes progressively less useful, because nothing new will be sent to it.
What it says about security research
One detail deserves attention beyond Zcash. A years-old flaw in a heavily reviewed zero-knowledge circuit, in a protocol that has been picked over by cryptographers since 2016, was found by one researcher with a frontier model pointed at the right file. The Zcash team’s own list of next steps starts with formally verifying the Orchard circuit and doubling down on AI-assisted security research, and includes hiring a Head of Security and a cryptographer.
Sources
- Zcash Community Forum, 'The Orchard Counterfeiting Vulnerability and Next Steps', Zooko Wilcox, Jason McGee and Taylor Hornby, 4 June 2026forum.zcashcommunity.com
- Project Tachyon, 'Ironwood: Auditing the Orchard Pool's Supply', Sean Bowe and Dev Ojha, 6 June 2026tachyon.z.cash
- Zcash Community Forum, 'Ironwood update for users', Zooko, 18 July 2026forum.zcashcommunity.com
- Project Tachyon, 'Detecting Counterfeiting after Zcash's Ironwood'tachyon.z.cash
- Zcash Community Forum, 'Ironwood: Verifying the Soundness of Zcash's Circulating Supply'forum.zcashcommunity.com
- Blockchair Zcash network statistics (block height checked 28 July 2026)blockchair.com


