What is the Ironwood shielded pool?

Please see our full section of articles on the Ironwood upgrade.

What is Ironwood?

Ironwood is Zcash's new shielded pool. It activates on mainnet at block 3,428,143 as part of the NU6.3 network upgrade.

It succeeds Orchard, the pool shielded Zcash used before it, and is built on the same proven Orchard protocol, strengthened with formal verification and independent security audits.

Activation does not move anyone's coins, though. Shielded ZEC you already held stays in Orchard until it is moved across.

Why Ironwood exists

Earlier this year, a Zcash security researcher discovered a soundness flaw in Orchard: a bug that could, in theory, have allowed counterfeit ZEC to be created inside the pool without anyone noticing. It was responsibly disclosed and patched through a coordinated emergency upgrade.

There is no evidence the flaw was ever exploited, no evidence that any user's funds were affected, and no evidence that the total supply of ZEC changed. It never touched anyone's privacy either.

The difficulty is proving that. Shielded pools hide transaction amounts by design, so nobody can inspect the inside of the pool to confirm no counterfeit ZEC exists there. That question can only be answered at the pool's edge.

How Ironwood settles it

When Ironwood activates, the old Orchard pool is restricted. It can no longer receive payments, and the only way for funds to leave it is forward, into Ironwood.

Everything leaving Orchard passes through Zcash's turnstile, the rule that a pool can never release more ZEC than legitimately entered it. Genuine funds cross into Ironwood; anything counterfeit that might hypothetically exist is stranded, unspendable.

That guarantee took effect the moment Ironwood went live. Anyone running a Zcash node can verify it from the network's own rules, without trust and without waiting for anyone to migrate.

What formal verification adds

The turnstile deals with the old pool. Formal verification is what makes the new one stronger.

Orchard was designed and reviewed by experienced cryptographers, and the flaw still went unnoticed. Review can establish that nobody spotted a problem. It cannot establish that no problem is there.

Formal verification is a different kind of check. The protocol's design is expressed mathematically and its properties are then proven, in the way a theorem is proven rather than tested. For Ironwood, that work rules out design-level errors capable of allowing undetectable counterfeiting, under the protocol's stated cryptographic assumptions.

It is a strong guarantee rather than an absolute one: it covers the design rather than every line of code implementing it, and it rests on those assumptions holding. That is why Ironwood also went through independent security review and auditing, which check the parts a proof cannot reach.

Together, they give substantially stronger assurance against the class of bug found in Orchard.

What it means for you

Your addresses have not changed. Ironwood uses the same receiver structure as Orchard, so addresses you have shared keep working, and shielded payments now arrive in Ironwood without you doing anything.

Any shielded balance you held before activation is still sitting in Orchard, and moving it across is worth doing. Your funds are safe, they remain yours, and there is no deadline.

One thing is worth knowing before you move anything: the amount that crosses between pools is recorded publicly on the blockchain. This is true of every wallet, not just Zodl. Who sent it and who received it stay private, but the figure does not.

Our guide to moving your funds to Ironwood explains how to handle that, and walks through the process step by step.

Read more

For the full story of how Ironwood was built, and who across the Zcash ecosystem contributed to it, keep a watch on our blog for announcements.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.