Cut Through CryptoBetaSubscribe
1 entry
Zcash Seals Its Vault, Starts Over

Zcash Seals Its Vault, Starts Over

PrivacyJul 29, 2026

Zcash's Ironwood upgrade activated July 28, sealing the Orchard shielded pool — roughly 3.6 million ZEC, about $1.7 billion — after a researcher in May found a four-year-old flaw that could have allowed undetectable counterfeiting. Funds can now exit only through a "turnstile" capping withdrawals at verified deposits, and a replacement pool opened from zero, with about 40,000 ZEC migrated in the first day, per trackers.

Zcash Ironwood: the privacy coin that had to expose itself to save itself

Ironwood is the fix, and it's carefully scoped. Seal the old pool. Open a new one, its math machine-checked — formally proven incapable of the same class of bug. Then make every coin exit the old pool through a turnstile: an accounting gate that counts total value leaving against the total that verifiably entered, and refuses to let the pool pay out more than it took in. Note what the gate can't do: it can't tell a real coin from a fake one, because who deposited what was hidden by design. It polices the pool, not the coin.

That scoping is the honest heart of this upgrade, and it's worth stating plainly. If fake ZEC exists and its holder exits early, they walk out with real value — and the loss surfaces only at the end, landing on whoever migrates last, when the pool's fixed capacity runs out before their coins do. What Ironwood guarantees is not that every holder is safe; it's that Zcash's supply can no longer be silently inflated, and that any counterfeiting that did happen is capped and will eventually show up in public arithmetic. An invisible, unlimited threat became a bounded, detectable one. In cryptography, that trade is called progress — but it's a smaller promise than "the fakes are trapped," and Zcash holders should know which promise they actually got. Meanwhile the privacy cost stands: every holder passes a publicly auditable checkpoint, into a new pool whose protective crowd is rebuilding from zero.

One more thing this story is not: proof that AI saved Zcash. Claude's role was finding the four-year-old flaw humans missed — not catching an attacker, and not building the fix. Put it next to the HAWK story from earlier and the real pattern shows: AI found what years of expert review missed, twice. At HAWK, before deployment — a candidate got weakened on paper, which is the vetting process working. At Zcash, four years after — with $1.7 billion already sitting on the broken math.

The capability is the same. The only variable that mattered was whether it read the math before or after the money arrived. And here's the part that should unsettle every protocol, not just Zcash: Orchard was audited. It shipped in 2022 after expert review, and the flaw lived through four years of scrutiny — because an audit is a snapshot of what the best adversary of that day could find, and the best adversary keeps improving. "Audited" used to be a credential you earned once. It just became one that expires.

The protocols that internalise this will re-run the exam every time the examiner gets smarter. The ones that don't will have it run for them.

Multi-media snippets

Related storylines

3 sources