Zcash Sealed a $1.7 Billion Pool to Prove Its Money Is Real

In July we wrote that Ironwood was the test to watch for Zcash — the upgrade that would decide whether the market's trust survived June's vulnerability scare. It activated on July 28 at block 3,428,143, and the reason behind it is more interesting than the upgrade itself.
A previously undisclosed bug in the proof circuit of Orchard — Zcash's main shielded pool — could have allowed someone to create counterfeit ZEC without leaving any on-chain trace. Not steal coins. Mint them, invisibly, inside the very pool designed so nobody can see what's inside.
Privacy's hardest problem
To see why that's the nightmare scenario for private money, consider what's easy on Bitcoin. Anyone can run a node and verify that the supply is exactly what the rules say it should be — every coin, every issuance, publicly auditable forever. Transparency is what makes the 21 million credible.
Encrypted money gives that up on purpose. Inside a shielded pool, amounts and participants are hidden — which is the entire point, and also means you cannot simply count the coins. Supply integrity has to be enforced by the cryptography instead: the proofs are supposed to make it mathematically impossible to spend more than you put in. When a flaw appears in that circuit, you lose the ability to answer the most basic question about money: is there exactly as much of it as there should be? A privacy coin with unauditable inflation isn't private money. It's a rumour.
What a turnstile actually does
Here's the elegant part, and it exploits an asymmetry most people miss about shielded pools. Transactions inside the pool are private — but money crossing the boundary, in or out, is publicly visible. The network has always known exactly how much ZEC went into Orchard, even though it can't see what happened in there.
So Ironwood sealed Orchard — roughly 3.66 million ZEC, some $1.7 billion — and opened a new shielded pool starting from zero. A turnstile governs the exit: the network will never let more ZEC out of the old pool than provably went in. If counterfeit coins exist inside Orchard, they are now permanently stuck there. They can't be spent out, and every real coin can still leave. The flaw is quarantined by arithmetic rather than by trust.
Ironwood also ships formally verified proof circuits — mathematical proof that the code does what the specification says, rather than an audit hoping to spot the next bug — and quantum-resilient record-keeping. Those are the two things you'd want after a soundness scare: prove this class of bug can't recur, and start preparing for the threat model after this one.
The honest half
Ironwood is a quarantine, not a cure, and the uncomfortable details deserve stating.
Migration is voluntary and slow. Coins don't move themselves — holders have to shift funds from the sealed pool into the new one, and how fast Zcash's private supply actually becomes trustworthy depends entirely on how quickly people act. A new pool starting at zero has a smaller anonymity set than the mature one it replaced, which means the earliest migrants get somewhat weaker privacy in exchange for stronger supply guarantees. That's a real trade, not a free upgrade.
The bug existed for a long time before anyone found it. That's the same lesson the Coldcard entropy failure taught last week from a different direction: cryptographic systems fail silently, and "no problems reported" is not evidence of correctness. Nobody knows whether the flaw was ever exploited — the pool's privacy cuts both ways here, which is precisely why the turnstile approach was necessary.
And the market has already priced some of this. ZEC fell roughly 48% after June's disclosure. For a privacy coin, trust is the product — we said that last month and it held.
Tachyon is the real exam. Ironwood was defensive. The next upgrade is ambitious: recursive proof aggregation, oblivious synchronisation, prunable node state — shrinking transactions by orders of magnitude and, as a side effect, removing the on-chain ciphertext that a future quantum attacker could harvest today and decrypt later. The NU7 testnet has been encouraging, with block times reportedly falling from 75 seconds to 25. But shipping recursive proofs, oblivious queries and pruning together in production, on a network securing real value, has no direct precedent. Judge it when it lands, not when it's announced.
Why this matters if you hold ZEC
Two practical notes. First, if your ZEC sits in the old shielded pool, plan your migration deliberately — follow guidance from your wallet and the Zcash project rather than a stranger's thread, and remember that anyone DMing you about "urgent pool migration" is running a scam. Second, this is a good moment to check that you actually hold shielded ZEC rather than transparent: as we covered in the BTC → XMR and ZEC guide, swap routes often deliver to transparent (t1...) addresses, and the privacy only starts when you move the funds into a shielded address yourself.
Worth noting for context on how people are actually acquiring it: something on the order of $1.5 billion of ZEC volume has moved through NEAR Intents without KYC — the same protocol TokensFund routes ZEC through today. Privacy assets are increasingly being bought on non-custodial rails rather than exchanges, which is what you'd expect for coins that keep getting delisted from the custodial ones. Our terminal compares THORChain, Chainflip, NEAR Intents, Changee and CCE.Cash and sends your swap to the best rate, wallet to wallet — no account, no KYC for standard swaps, flat 2% in the quote.
The broader point is one worth sitting with. A blockchain found a flaw that could have quietly broken its own money supply, disclosed it, and shipped a mechanism that quarantines the damage using nothing but the chain's own arithmetic — no bailout, no rollback, no committee deciding whose coins were real. Whatever you think of Zcash, that is the machinery working as designed. It's a considerably better week for encrypted money than the headlines suggested.
A note on risk
Nothing here is financial advice. Details reflect reporting and Zcash project communications as of August 10, 2026; upgrade specifics and timelines can change, and the Zcash project's own documentation is authoritative for anything affecting your funds. No claim is made that the Orchard flaw was ever exploited — it may never have been. Privacy assets are volatile and their regulatory treatment varies by jurisdiction. Verify addresses, send test amounts, and be suspicious of anyone who contacts you first about migrating your coins.
Shielded ZEC, no account required
Compare ZEC routes →