Zcash activated Ironwood NU6.3, a formally verified shielded pool, at block height 3,428,143 on July 28. The network upgrade restricts the original Orchard pool and forces all outbound funds through a verifiable turnstile mechanism designed to strengthen protocol security after a soundness vulnerability discovered in May.
The Orchard vulnerability, identified on May 29 by researcher Taylor Hornby, posed a risk of undetectable counterfeiting. Ironwood replaces Orchard with a new shielded pool built on corrected cryptography and backed by formal verification conducted through Project Tachyon, a joint effort between zkSecurity and the Zcash Open Development Lab. Approximately 3.76 million ZEC has transited the turnstile since activation, according to on-chain data.
The announcement from the Zcash Open Development Lab states that Ironwood is formally verified and independently auditable. The new pool design allows the integrity of Zcash's circulating supply to be verified without trusting a single implementation, whereas transparent blockchains require running a full node to audit supply.
Orchard, activated in late 2022, introduced Unified Addresses and a redesigned shielded architecture meant to improve scalability. The vulnerability affected Orchard's constraint system, potentially allowing an attacker to create counterfeit ZEC undetectably. Zcash does not appear to have suffered active exploitation; the flaw was caught during internal review before public disclosure.

Formal verification of the new pool remains ongoing, with proofs constructed in the Lean theorem prover. Zcash previously conducted formal verification work on its Halo 2 commitment scheme. The effort follows a broader industry trend toward provably correct cryptographic systems after high-profile vulnerabilities in trusted-setup ceremonies and zero-knowledge protocols.
The turnstile mechanism requires all ZEC exiting Orchard to pass through a visible layer before entering Ironwood, creating an auditable record of the transition. This design prevents the creation of unmapped ZEC supply and enables independent verification of whether the total ZEC in Ironwood matches the sum of Orchard funds migrated. Zcash's total circulating supply is approximately 15.6 million coins.
Ironwood deployment required coordination across node operators, wallet developers, and the exchange ecosystem. The upgrade follows Zcash's May incident response protocol, which prioritized ecosystem notification over a staged rollout. A second formal verification audit of Ironwood's core components is underway and expected to conclude before year-end, according to Project Tachyon's public documentation.
The activation puts Zcash's security model ahead of competing privacy protocols in one specific dimension: mathematical proof of correctness for its shielded pool's core constraints. Monero, which uses a different privacy approach, does not employ formal verification. If Project Tachyon's formal verification audit identifies gaps in the current Ironwood specification before the planned completion date, Zcash would face pressure to issue another protocol amendment.