Zcash activated its Ironwood (NU6.3) hard fork on July 28, 2026, at block 3,428,143 (approximately 2:35 p.m. ET), sealing the Orchard shielded pool containing roughly 3.66 million ZEC — valued at approximately $1.7 billion at activation prices. The upgrade opens a new shielded pool starting at ze...
"Humanity is going to have a form of money that is unstoppable, private, and has full correctness proofs (formal verification) of some of its key properties, thanks to heroic math by an awesome team." — Zooko Wilcox, Zcash Founder (July 19, 2026)
Zcash activated its Ironwood (NU6.3) hard fork on July 28, 2026, at block 3,428,143 (approximately 2:35 p.m. ET), sealing the Orchard shielded pool containing roughly 3.66 million ZEC — valued at approximately $1.7 billion at activation prices. The upgrade opens a new shielded pool starting at zero balance, connected to the old pool through a turnstile accounting mechanism that caps outflows at verifiable deposits.
The hard fork is the culmination of a 60-day emergency rebuild triggered by the discovery of a counterfeiting vulnerability in the Orchard proof circuit. The bug, found May 29 by Shielded Labs researcher Taylor Hornby using an AI-assisted auditing framework powered by Anthropic's Claude Opus 4.8, had existed undetected since Orchard's activation in May 2022. No evidence of exploitation has been found, but Zcash's privacy architecture makes definitive confirmation impossible. ZEC traded at $462.93 at activation, down 14.88% on the week, with market capitalization at $7.78 billion.
The flaw resided in the halo2_gadgets crate powering Orchard's zero-knowledge proofs. Two lines of code left an elliptic curve multiplication check under-constrained, allowing mathematically invalid inputs to pass verification that should have rejected them. In practical terms, an attacker could have minted unlimited counterfeit ZEC inside the Orchard shielded pool, leaving no on-chain trace.
The bug entered production when Orchard activated in May 2022 and survived approximately four years of review by cryptographers widely regarded as among the field's most capable practitioners. Multiple audit rounds failed to catch it. The under-constrained circuit allowed forged proofs to validate, meaning counterfeit notes could exist inside the pool without any observable anomaly — not in balances, not in transaction patterns, not in chain state.
Because Orchard hides sender, receiver, and amount by design, the protocol's privacy guarantees work against forensic analysis. There is no mechanism to reconstruct shielded history and confirm with certainty that the flaw was never exploited. Developers have stated they found "no evidence" of exploitation, and Orchard balances grew steadily during the vulnerability window, but the caveat is fundamental: absence of evidence is not evidence of absence in a system engineered to prevent observation.
Taylor Hornby, a security researcher contracted by Shielded Labs, discovered the vulnerability on May 29, 2026. His methodology combined human expertise with AI tooling — specifically, he paired Anthropic's Claude Opus 4.8, released the previous day, with a custom AI auditing framework designed to systematically check individual circuit constraints.
Within a single day, Hornby located the flaw, wrote a working exploit, and verified that it produced unlimited counterfeit ZEC on a local testnet. The discovery represents what multiple analysts have described as a human-in-the-loop workflow: the experienced security researcher built the framework and directed the investigation, while the AI model handled the breadth of checking individual constraints across the circuit.
Prior AI-only runs using older models missed the bug entirely. Years of expert human review also missed it. The combination of a researcher who knew where to look and an AI model capable of exhaustive constraint checking proved necessary.
The disclosure triggered an immediate market reaction. ZEC fell approximately 38%, from roughly $635 to an intraday low near $309, before recovering to approximately $330 in the days following the patch. The crash erased roughly $5 billion in market capitalization within hours.
The response proceeded in two phases.
Phase 1 — Containment (5 days). Developers at the Zcash Open Development Lab (ZODL) shipped an emergency soft fork on June 2, disabling Orchard transactions. A follow-up hard fork (NU6.2) activated on June 3, re-enabling the pool with the corrected circuit. This contained the vulnerability but did not resolve the supply verification problem.
Phase 2 — Ironwood rebuild (60 days). ZODL initiated what Josh Swihart, the organization's executive director, described as "wartime development mode." According to Swihart, "Orchard was fixed in 5 days and replaced in 60." The engineering effort involved 51 developers working continuously without weekends, merging 1,391 pull requests. ZODL's 14 engineers accounted for over 80% of the merged changes to Zcash's protocol and wallet repositories.
The rebuild went beyond patching the circuit. The team retired the decade-old zcashd core client, transitioned to the modernized Zebra consensus node (now mandatory at block 3,417,100), upgraded the Zallet wallet from alpha to beta, launched the Zakura light wallet, and updated mobile SDKs.
Swihart characterized the broader outcome: "We resolved the issue, battle-tested our incident support processes, built stronger relationships with others who support the network, tested our own resilience, and unified as a community of builders to agree on a path forward."
Ironwood introduces three primary mechanisms:
1. Pool Sealing and Turnstile. The old Orchard pool is sealed: no new deposits, no internal transfers between users. Funds can only exit through Zcash's turnstile accounting mechanism, which enforces a strict rule — total outflows cannot exceed the amount that legitimately entered the pool. Any counterfeit ZEC, if it exists, remains permanently trapped in the old pool. The mechanism provides a public checkpoint on circulating supply without exposing private balances or transaction details.
As of press time, approximately 1,500 ZEC had migrated to the new pool. The remaining 3.66 million ZEC sits in Orchard awaiting user-initiated migration. Zooko Wilcox advised users on July 27: "Don't rush to migrate your funds out of Orchard right away — take your time." The Zodl wallet (version 3.8.0) supports direct migration without requiring a new wallet or address. An automated migration feature is planned for a future release.
2. New Shielded Pool. Ironwood opens a new shielded pool built on the patched Orchard circuit. It reuses Orchard's Action structure and Halo2 proof system but implements a separate note commitment tree, nullifier set, chain value pool, and chain-history data. It uses the v6 transaction format. The pool starts at zero balance, providing a clean accounting baseline.
3. Formal Verification and Quantum Groundwork. The new pool's zk-SNARK circuits are undergoing formal verification through Project Tachyon and the Valar Group, using the Lean theorem prover to mathematically prove that the circuits cannot produce counterfeiting bugs. According to Project Tachyon, "Zcash's new Ironwood pool is being formally verified to rule out all undetectable counterfeiting bugs, up to the underlying cryptographic assumptions."
Ironwood also introduces quantum-recoverable notes via ZIP 2005 — a mechanism that supports future recovery of funds if quantum computers break current cryptography. This does not make Zcash quantum-secure today; it establishes the groundwork for a future migration path. Project Tachyon's broader roadmap includes removing on-chain ciphertext that quantum attackers could harvest.
The vulnerability disclosure on June 5 triggered ZEC's largest single-day decline in years: a 38% crash from $635 to a low of approximately $309. Market capitalization fell from roughly $10.7 billion to $5.2 billion.
Recovery followed the containment and Ironwood development timeline:
At activation, ZEC's market capitalization stood at $7.78 billion. Derivatives activity was elevated: ZEC futures volume exceeded $1.35 billion, indicating substantial open interest. The year-to-date performance remains approximately a 10x increase despite the June crash.
The upgrade required coordinated action across the Zcash ecosystem:
zcashd client ceased functioning at block 3,417,100.The upgrade was proposed jointly by ZODL, Project Tachyon, the Valar Group, the Zcash Foundation, and Shielded Labs — a coordinated effort across Zcash's decentralized governance structure.
The Zcash Orchard incident raises structural questions for privacy-preserving protocols.
The audit paradox. Privacy systems are inherently harder to audit after deployment. The same properties that protect users — hidden amounts, hidden senders, hidden receivers — prevent forensic analysis of whether bugs were exploited. This creates a category of risk unique to privacy protocols: vulnerabilities that are simultaneously critical and unverifiable in their impact.
AI as audit infrastructure. The discovery method — a human researcher directing an AI model to exhaustively check circuit constraints — may represent a template for future cryptographic auditing. The bug survived years of expert review, and AI-only runs with older models also failed. The combination proved necessary, suggesting that the audit surface of complex zero-knowledge systems may exceed what either humans or current AI can cover alone.
Supply verification as a design requirement. Ironwood's turnstile mechanism acknowledges that privacy and supply verification exist in tension. The solution — pooling transitions that enforce accounting constraints at migration boundaries — adds operational friction but provides periodic verification checkpoints. Other privacy protocols face the same trade-off.
Formal verification as a response to complexity. The move toward machine-checked proofs of circuit correctness through Project Tachyon reflects a broader trend in cryptographic protocol development. As zero-knowledge circuits grow more complex, informal review becomes insufficient. The question is whether formal verification can scale to cover the full circuit stack, including underlying cryptographic assumptions.
Ironwood is, at its core, an admission and a response. The admission: a four-year-old bug in Zcash's most advanced privacy pool could have allowed undetectable counterfeiting, and the protocol's own privacy guarantees make it impossible to prove it did not happen. The response: seal the old pool, trap any potential counterfeit coins, and rebuild with formal verification intended to prevent recurrence.
The execution was rapid — five days to contain, sixty to rebuild — and the engineering effort was substantial. Whether it restores confidence depends on two unresolved questions: will the turnstile migration proceed without revealing supply discrepancies that would indicate exploitation, and will Project Tachyon's formal verification prove comprehensive enough to rule out analogous bugs in the new circuits.
The broader lesson extends beyond Zcash. As zero-knowledge cryptography proliferates across DeFi, Layer 2 networks, and institutional applications, the Orchard incident demonstrates that the complexity of these systems can exceed the audit capacity of even the field's most experienced practitioners. The combination of AI-assisted auditing and formal verification may become standard infrastructure — not because it is sufficient, but because nothing less appears to be.