Just one day after Zcash sealed its largest private funds pool following the discovery of a four-year counterfeiting vulnerability, only about 5 percent of holders have moved their coins to safety. The remaining 95 percent sit in a pool that can no longer accept new deposits — and nobody knows exactly how long it will take for them to find the exit.
By Carlos Martinez | July 29, 2026
The Hook
Imagine discovering that the vault at your local bank had a hidden flaw in its lock mechanism for four years. Nobody can prove anyone broke in, but nobody can prove they did not either. That is essentially what happened to Zcash, one of the cryptocurrency world’s leading privacy-focused coins.
On Tuesday, July 28, Zcash activated its Ironwood upgrade — formally known as NU6.3 — at block 3,428,143. The upgrade permanently closed the Orchard shielded pool, which held about 3.66 million ZEC worth roughly 1.7 billion at current prices. A new pool called Ironwood opened with zero coins, and every holder must now voluntarily move their funds across a one-way bridge called a turnstile.
The reason? A bug discovered on May 29 by Shielded Labs researcher Taylor Hornby. The flaw, hidden inside Orchard’s proof circuit since the pool launched in May 2022, could have allowed someone to create counterfeit ZEC without leaving any trace on the blockchain. In the world of privacy coins, where transactions are designed to be invisible, that is the worst possible scenario.
On-Chain Evidence
The numbers tell an interesting story about how Zcash holders are responding to the crisis. According to the Ironwood migration tracker, roughly 176,000 ZEC — worth about 81 million — had crossed into the new pool within the first 24 hours. That sounds like a lot, but it represents only about 5 percent of what was sitting in Orchard.
The Orchard pool’s balance has dropped from 3.66 million ZEC to approximately 3.51 million, with around 46,000 ZEC crossing over in the past day alone. At this pace, a full migration could take weeks or even months.
Zcash organizes its funds into separate compartments called pools, each representing a generation of privacy technology. The transparent pool works like Bitcoin, with every balance and transaction visible on the chain, and holds about 12.5 million ZEC. The older Sapling pool, introduced in 2018, holds roughly 582,000 ZEC. Orchard, which arrived in 2022 and was the newest pool until this week, held the lion’s share of private funds.
The Core Conflict
Here is the central tension: the bug existed for four full years. While evidence suggests it was never exploited — the Orchard pool’s balance grew steadily through that period, including during last year’s price rally when cashing out counterfeit coins would have been most profitable — nobody can definitively prove that no fake coins were created. That is the nature of zero-knowledge proofs. They verify transactions without revealing details, but they also mean the chain holds no record of whether counterfeit coins were minted.
The turnstile mechanism is Zcash’s answer to this uncertainty. Think of it like a toll booth on the exit ramp of a parking garage. The booth knows exactly how many cars entered the garage, and it will not let more than that number leave. Even if someone somehow parked counterfeit cars inside, those cars cannot get out.
Money crossing into or out of a shielded pool is public information, even when the transactions inside the pool are completely private. So the network already knows precisely how much real ZEC went into Orchard — and it will not release a single coin more than that amount.
Market Implications
The market reaction has been measured but not panicked. ZEC traded near 463 ahead of the switch, down 8 percent on the day of the upgrade and 15 percent over the week. However, the coin remains up roughly tenfold over the past year, suggesting that long-term holders are not treating this as a death blow to the project.
Ironwood also brings two significant improvements that Orchard never had. First, the record each coin leaves on the chain is built to stay recoverable even if quantum computers eventually break today’s cryptography — a feature specified under ZIP 2005 and active from the very first block. Second, the pool’s proof circuit is undergoing formal verification, which produces a mathematical guarantee that the software behaves correctly in every possible scenario, not just the cases that testers thought to check.
Think of it like upgrading from a lock that was tested by trying random keys to one that comes with a mathematical proof that no key exists except the right ones.
The Verdict
The number to watch from here is how fast those 3.66 million ZEC actually move. Migration is entirely voluntary and user-driven. Wallets, exchanges, and individual holders all need to update their software and initiate transfers at their own pace. Until that happens, the bulk of Zcash’s private supply sits in a pool that has been closed to new money since Tuesday.
For everyday investors, the Zcash Ironwood upgrade is a reminder that even the most sophisticated privacy technology is not immune to human error. A single bug in a proof circuit went undetected for four years. The system’s response — sealing the pool, forcing a controlled migration, and adding formal verification — may well become a textbook case for how blockchain networks handle security crises.
But the slow migration rate also raises a question: if 95 percent of holders are in no rush to move their coins to the supposedly safer pool, does that signal confidence that the bug was never exploited, or simply the inertia of a fragmented user base? The answer may not be clear for months.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making investment decisions.
a counterfeiting bug sitting in the proof circuit for 4 years and nobody noticed. this is why I never put more than lunch money into privacy coins. the tech is cool but one missed audit and your entire supply is quietly inflated
95% of holders still sitting in the sealed pool is wild. either they dont know, dont care, or the wallets dont support the turnstile migration yet
@Darian V. probably a mix of all three. moving shielded funds isnt like sending a normal tx, you need compatible wallet software and some people literally cold store their ZEC and check it once a year
a bug that lets you print fake ZEC invisibly for 4 years and nobody panicked? privacy coins are wild. 95% of holders just sitting in a sealed pool basically shrugging
3.66 million ZEC in one pool and the bug could have minted fake coins with zero trace. honestly the fact that they found it before exploitation is the only thing saving confidence here. Hornby deserves a medal
Taylor Hornby finding this before anyone exploited it is honestly the real story here. One researcher caught a flaw that could have burned 1.7B and nobody even noticed it existed since 2022
^ this. shielded labs probably just saved the entire zcash project from an existential crisis and most people will never know their name
one security researcher catching what years of audits missed tells you how few people actually verify zk circuits. this isnt a zcash problem, its an industry wide blind spot
audits get paid to check the code, nobody pays to independently re-verify the circuits themselves. hornby basically did that work for free
the turnstile design is smart but 95% not moving is crazy. are they lazy, do they not care, or do they not know how? gonna take months to drain that pool at this rate
176k ZEC migrated in 24h sounds low but its actually solid for a voluntary migration. people forget shielded txs are slow and expensive
a counterfeiting bug sitting in the proof system for 4 years is exactly why monero people have been smug lately. different privacy architecture, different risk profile
95% of holders not migrating tells you everything about how dead ZEC privacy tech is in practice. people dont care enough to move even after a counterfeiting bug
Henrik B. or maybe the 95% just doesnt hold ZEC in wallets that support the migration. most exchanges probably havent updated their infrastructure
or it means most ZEC sits on exchanges that handle migration on their own schedule. binance and coinbase hold huge chunks of that 95%. holder apathy and exchange inertia are different failures
Fair split, but add paper wallets to the list. Plenty of ZEC sits in cold storage from 2016 that nobody has touched since. No exchange, no apathy, just keys in a drawer.
exchange inertia cuts both ways though. their reserves sit sealed earning nothing until they migrate, at some point that hits their own balance sheet math
exactly this. check exchange reserve charts before calling holders lazy, most of that 1.7B is custody money that migrates when binance schedules it, not when zcash does
Henrik B. calling ZEC privacy tech dead when the turnstile migration literally just worked is a wild take. 176k ZEC moved in 24h voluntarily
ironwood closing a 1.7B pool at block 3428143 with basically zero drama might be the most underrated event in privacy coin history. hornby caught the bug, NU6.3 sealed the pool, market shrugged
a counterfeiting vulnerability in the proof system for 4 years is not a feature of the turnstile design. its a near miss of existential proportions
stefan_r 4 years undetected is the scary part. if one researcher found it how many others looked and stayed quiet
sealed pool means zcash now runs a shrinking 1.7B privacy bubble that only drains through the turnstile. the orchard exit rate over the next year is the only ZEC chart that matters
176k ZEC migrated in 24h is impressive for a voluntary process. most shielded users probably dont even know the turnstile happened
a counterfeiting bug sitting in the proof system for 4 years and ZEC is flat. either the market trusts that Hornby found it first or most holders never read past the headline