July 19, 2026 ChainGPT

Zcash hard forks July 28 — Ironwood seals Orchard pool, blocks potential counterfeit ZEC

Zcash hard forks July 28 — Ironwood seals Orchard pool, blocks potential counterfeit ZEC
Zcash will activate a hard fork on July 28 to “seal” its old Orchard shielded pool and close an open question about whether a recently discovered cryptographic bug could have created counterfeit ZEC. What’s happening - The upgrade, dubbed Ironwood (NU6.3), will activate at block 3,428,143 on July 28. It will retire the existing Orchard shielded pool and launch a new pool built on the corrected circuit. - Rather than trying to identify or freeze any individual coins, Ironwood uses a “turnstile” mechanism that restricts how much ZEC can leave the old Orchard pool. Any hypothetical excess value would remain trapped inside the retired pool instead of entering wider circulation. - Zcash founder Zooko Wilcox explained the approach in a July 19 post on X: because Orchard transactions are private, the network cannot cryptographically prove that counterfeit coins were never created, so the safest path is to seal the old pool. Why this is needed - Security researcher Taylor Hornby discovered the Orchard flaw on May 29 while auditing the shielded system. The bug could have allowed creation of ZEC inside Orchard without an obvious public record. - Developers initially disabled Orchard, then restored it with corrected cryptography in a prior NU6.2 hard fork. No evidence of unauthorized value creation has been found, but Orchard’s privacy means exploitation cannot be ruled out with absolute certainty. - Ironwood is designed to address that unresolved supply question by preventing any hypothetical counterfeit ZEC from leaving the sealed pool. What users and operators should know - Users do not need to take immediate action before the fork, but wallets, exchanges and infrastructure providers will need to upgrade. Some services may temporarily suspend deposits, withdrawals or related operations during the upgrade. - Wallets will eventually require support for migration tools to move funds from the old Orchard pool into the new one; funds may remain unavailable in wallets that haven’t added those tools. - Node operators will be able to verify that circulating ZEC does not exceed the network’s monetary limits thanks to the turnstile’s control over withdrawals. Broader security work - The Orchard incident prompted wider reviews across the Zcash ecosystem. An AI-assisted audit using Anthropic’s Mythos reportedly found no additional serious vulnerabilities. - Developers are pursuing independent audits and formal verification of the updated cryptographic system to reduce the risk of another hidden counterfeiting flaw and to strengthen verifiability of Zcash’s supply rules. - The Ironwood activation also arrives as the project phases out the legacy zcashd client; providers still migrating may need extra time to support the upgrade. Bottom line Ironwood does not retroactively prove that no counterfeit ZEC was created, but it prevents any hypothetical surplus from entering circulation by sealing the old Orchard pool and restricting withdrawals. The July 28 hard fork is intended to close the supply uncertainty while the Zcash team continues audits and formal verification of its shielded protocol. Read more AI-generated news on: undefined/news