Zcash backers propose Ironwood upgrade after Orchard bug disclosure

Zcash backers propose Ironwood upgrade after Orchard bug disclosure

A late-July proposal would migrate Orchard funds into a new privacy pool with stronger supply verification after a patched flaw raised temporary doubts about ZEC issuance and pressured the token.

USDT
ZEC

Fact Check
All substantive elements of the claim are confirmed by the official Zcash Community Forum disclosure co-authored by Taylor Hornby, Zooko Wilcox, and Jason McGee, and corroborated by CoinDesk: Hornby identified the bug; it existed in the Orchard Shielded Pool since May 2022; it could have enabled undetectable counterfeit ZEC minting; ZEC fell 38%. The only minor inaccuracy is the timing phrase 'patched before June 1' — disclosure was on June 1 with the emergency fix deployed June 1-2, 2026, not strictly before June 1.
    Reference123
Summary

ZODL, Tachyon, Valar Group, the Zcash Foundation and Shielded Labs have proposed a Zcash network upgrade centered on a new privacy pool called Ironwood after disclosure of a critical Orchard Shielded Pool flaw that security engineer Taylor Hornby said had existed since May 2022 and was patched before June 1. The proposal would migrate all Orchard ZEC through a Turnstile mechanism into the new pool, which backers said would be built on Orchard with formal verification, additional independent audits and stronger total-supply verifiability aimed at letting anyone independently verify circulating supply. ZODL said there was no evidence the patched soundness issue had been exploited or had affected funds, privacy or total supply. The disclosure pressured ZEC and raised supply doubts, though the token later rebounded; OKX data showed it rose 9.01% over 24 hours to 406.5 USDT after the privacy-pool proposal and verification updates emerged.

Terms & Concepts
  • Orchard Shielded Pool: Zcash's privacy-focused pool for shielded transactions.
  • Turnstile mechanism: A migration and supply-checking process proposed to move ZEC from Orchard into the new Ironwood pool.
  • formal verification: Mathematical checking of code or system behavior to strengthen confidence in security and correctness.