Ironwood History

Shielded Labs security researcher Taylor Hornby discovered a counterfeiting bug in the Orchard shielded pool's ZK circuit through the use of AI vulnerability analysis. The vulnerability was quickly patched in a hard fork network upgrade days later by the Zcash Open Development Lab (ZODL).

In the following days, Shielded Labs also proposed a solution: in order to re-establish user guarantees about the circulating supply of ZEC, payments in the Orchard shielded pool would be disabled in a network upgrade and a new pool (based on a patched version of Orchard) would be introduced simultaneously. This would force all payments to send money through the turnstile first if they could hypothetically be counterfeit coins.

Kris Nuttycombe from ZODL provided a key refinement: since the new pool would use the same cryptography, wallets could seamlessly route payments to Orchard receivers into the new Ironwood pool instead, to reduce UX friction.

Governance

The community quickly rallied around the proposed idea and, after some debate, Project Tachyon, Valar Group, ZODL, Shielded Labs and the Zcash Foundation agreed to a limited-scope NU6.3 upgrade introducing the pool. The specific consensus rules were resolved in the days that followed.

One early dispute concerned change. Setting Orchard's existing enableOutputs flag to zero would stop payments, but it would also stop a wallet from making a change note. A migration would then publish the sum of whatever notes happened to fund it. Valar Group argued for retaining change, and the compromise was the new enableCrossAddress restriction: Orchard rejects an output to another receiver but accepts change at the spent note's own expanded receiver.

The technical design and wallet strategy are described on Orchard to Ironwood Migration.

Implementation

The implementation of the upgrade's consensus rules was largely the work of Project Tachyon, Valar Group and ZODL.

Hardware Wallet Support

Valar Group also wanted Keystone users to migrate without reviewing and signing every scheduled transaction separately. That required changes to the PCZT code in orchard and librustzcash, followed by firmware work and testing in Keystone.

Check out the numerous pull requests for the Keystone firmware alone.

Ironwood Circuit Changes

Project Tachyon, for its part, contributed the modifications to the Ironwood circuit that enable the "cross-address restriction" needed for disabling payments in the pool while retaining change during migration.

Formal Verification

Project Tachyon coordinated the formal verification effort for Ironwood, working with zkSecurity and ZODL. On activation day they announced a completed machine-checked proof, written in Lean and comprising more than 2,700 theorems, that undetectable counterfeiting bugs do not exist in Ironwood under the stated cryptographic assumptions.

Activation

The activation height of 3428143 was chosen for NU6.3, and the network activated on schedule on 28 July 2026.

Zcash Foundation landed support for NU6.3. Zakura, our fork of Zebra, has had support for NU6.3 and the Ironwood consensus rules since the initial 1.0.0 release.