Zcash's Ironwood upgrade goes live today at block 3,428,143, expected around 10 AM Eastern time. The network upgrade, formally designated NU6.3, introduces a new shielded pool and forces roughly 3.76 million ZEC through a public accounting checkpoint called the turnstile. Once the activation height is reached, wallets will route new shielded payments to Ironwood, while the older Orchard pool will accept no new deposits or internal transfers.
What makes Ironwood significant beyond its immediate function is what's happening underneath: Project Tachyon and a coalition of developers have been working to formally verify the new pool's zero-knowledge circuit using the Lean 4 theorem prover. If successful, Ironwood would become the first production blockchain privacy protocol to achieve mathematical supply certainty rather than the weaker standard of "no evidence of exploitation."
The Verification That Matters
The formal verification effort targets a property called knowledge soundness. In practical terms, this means producing a mathematical proof that any prover who generates a valid Ironwood transaction proof must actually possess a valid transaction witness. Real ZEC. Correctly derived. At the right address.
This approach separates counterfeiting risk into two categories. Specification bugs in the ZK circuit are the only class that can remain permanently hidden from observers. Implementation bugs, by contrast, leave permanent records in the chain that can be detected by replaying corrected software. By formally verifying the specification itself, the entire class of undetectable counterfeiting is eliminated by mathematics rather than by inspection.
The work involves contributors from zkSecurity (Gregor Mitscha-Baude), the Zcash Open Development Lab (Daira-Emma Hopwood), and Tachyon's own Tal Derei. Advances in AI-assisted proof generation have compressed what once took years into a matter of weeks. Zcash founder Zooko Wilcox stated in early July that the team is "on the verge of producing a mathematical proof that there are no undetectable counterfeiting bugs in the latest Zcash shielded pools."
Ironwood's Architecture
Ironwood reuses the Orchard proof system and circuit but starts a fresh pool with the patched code. The formalization is a Lean 4 development built over Mathlib; a successful build is itself the verification. Any remaining balance in the old Orchard pool can leave only by passing through the turnstile, which publicly records the exact amount exiting and entering. That rule prevents more ZEC from leaving the old pool than ever entered it.
Node operators must upgrade to Zebra 6.0.0 before activation. The transition also completes Zcash's migration away from the legacy zcashd client, which reached end-of-life on July 18.
What Comes Next: Tachyon
The Tachyon protocol, currently in development, represents a more ambitious architectural shift. The project introduces a stateless model where wallets carry recursive ZK proofs of their solvency rather than scanning every transaction on the chain. This proof-carrying data approach means a single proof can validate an entire block or transaction tree, and the chain stores only commitments and proofs rather than encrypted note data.
Tachyon uses out-of-band payments for shielded transactions, eliminating in-band secret distribution and reducing the computational complexity of zk-SNARK circuits. Note secrets are shared offchain via URIs, secure channels, or merchant APIs. The result is a protocol where validators can begin pruning all old blockchain state, dramatically reducing storage requirements without compromising privacy.
The recursive proofs powering Tachyon run on Ragu, a Rust-language proof-carrying data framework built by the Tachyon team. Ragu follows the original Halo recursive proof construction, requires no trusted setup, and is designed for the same Pasta curves Zcash already uses.
Quantum Considerations
Zcash is pursuing what it calls "quantum-recoverable" wallets, with ZODL CEO Josh Swihart stating at Consensus Miami that the broader goal is full post-quantum security within 12 to 18 months. The shielded pool's architecture provides what developers call "harvest resistance": because Tachyon moves encrypted note data off-chain entirely, there is no sensitive ciphertext on the ledger for a future quantum computer to harvest and later crack.
The 60-day rebuild that produced Ironwood included bringing the new Zallet wallet from alpha to beta, hardening the Zebra consensus node, and updating essential mobile SDKs. Engineers from the Zcash Open Development Lab authored over 80 percent of the changes in the protocol and wallet repositories.
The affected Orchard pool holds approximately $1.89 billion at current prices, representing nearly 22 percent of total circulating supply. Those funds will migrate through the turnstile over the coming weeks. A smooth activation would convert what started as a security incident into a demonstration that privacy and supply verifiability can coexist.


