Just one day after Zcash sealed its old privacy pool over a counterfeiting flaw that went unnoticed for four years, roughly 176,000 ZEC — worth about 81 million in dollar terms — has already rushed into the network’s brand-new Ironwood pool. The race to migrate is on, but the vast majority of the privacy coin’s hidden supply remains trapped in a pool that can no longer accept new deposits.
By Jennifer Kim | July 29, 2026
The Hook
Imagine your bank discovered a flaw in its vault door that, in theory, could have let someone print fake money for four years without anyone noticing. The bank’s solution? Build a brand-new vault next door, seal the old one shut so no new money can go in, and let every customer individually move their funds to the new building — at their own pace, through a hallway that carefully counts every coin on the way out.
That is exactly what happened with Zcash, one of the oldest privacy-focused cryptocurrencies, when it activated its Ironwood upgrade on Tuesday. The upgrade formally known as NU6.3 closed the Orchard shielded pool — the compartment where most of Zcash’s private transactions lived — and opened a fresh pool starting with zero coins.
On-Chain Evidence
The numbers tell a story of cautious but steady movement. According to the Ironwood migration tracker, about 176,000 ZEC had crossed into the new pool within the first 24 hours. At current prices near 463 per ZEC, that translates to roughly 81 million in dollar value.
That sounds like a lot — and it is — but it represents only about 5 percent of the 3.66 million ZEC that was sitting in Orchard when the upgrade went live. Another 46,000 ZEC crossed over in the past day alone, bringing Orchard’s balance down to approximately 3.51 million ZEC.
The rest of Zcash’s supply sits elsewhere. The transparent pool, which works like Bitcoin with every transaction visible on the public ledger, holds about 12.5 million ZEC. The older Sapling pool, introduced in 2018, contains roughly 582,000 ZEC. Each generation of Zcash’s privacy technology gets its own pool, and every time the network upgrades, holders must move their coins across themselves.
The Core Conflict
The urgency behind this upgrade traces back to May 29, when Shielded Labs researcher Taylor Hornby discovered that Orchard’s proof circuit contained a bug that could have allowed someone to mint counterfeit ZEC without leaving any trace on the blockchain. The flaw had been live since Orchard launched in May 2022 — four full years.
Here is the unsettling part: nobody can prove the bug was never exploited. Zcash’s zero-knowledge proofs are designed to reveal nothing beyond the fact that a transaction is valid. So the chain holds no record of whether counterfeit coins were ever created. If someone did mint fake ZEC, those coins are now locked inside Orchard with no way out except through the turnstile.
The turnstile is the clever part of this whole design. Money crossing between pools is public, even when transactions inside the pool are completely private. The network knows exactly how much real ZEC went into Orchard. It will not release more than that amount. Any fake coins sitting inside are effectively trapped forever.
The evidence, thankfully, points away from exploitation. A CoinDesk Research report published in July found that Orchard’s balance grew steadily through the four years the flaw was open, including during last year’s major price rally when cashing out would have been most profitable. If someone had printed fake coins, they likely would have moved them out to sell — and that movement would have shown up as funds leaving the pool.
Market Implications
ZEC traded near 463 ahead of the Ironwood switch, down 8 percent on the day and 15 percent over the week, though the coin remains up roughly tenfold over the past year. The price reaction suggests the market views the upgrade as necessary medicine — unpleasant in the short term but far better than the alternative of leaving a counterfeiting vulnerability open indefinitely.
For context, Bitcoin hovered near 64,000 on Wednesday while the broader crypto market waited on the Federal Reserve’s rate decision. Ethereum traded around 1,890, down about 1.5 percent. ZEC’s 8 percent single-day decline stood out as steeper than most major coins, reflecting the upgrade-specific uncertainty.
The key question for investors is how quickly the remaining 3.5 million ZEC migrates. Because the process is entirely voluntary and user-driven, the timeline depends on individual holders, wallet providers, and exchanges updating their software to support Ironwood deposits. Until that happens, the majority of Zcash’s private supply sits in a pool that has been closed to new money since Tuesday — a sort of financial limbo.
The Verdict
Ironwood brings two major improvements that Orchard never had. First, the record each coin leaves on the blockchain is built to stay recoverable even if future quantum computers break today’s cryptography — a forward-looking safeguard specified under proposal ZIP 2005. Second, the pool’s proof circuit is undergoing formal verification, a rigorous process that produces mathematical proof the code works correctly in every possible scenario, not just the cases testers thought to check.
Think of it like upgrading from a door lock that was visually inspected to one that comes with a mathematical guarantee. The old lock probably worked fine — and all evidence suggests it did — but you can never be completely sure. The new lock comes with proof.
For everyday investors, the Zcash Ironwood story is a reminder that cryptocurrency is still a young technology where fundamental issues can hide for years. It also shows that well-designed systems can fix problems without imploding. The turnstile mechanism — a simple accounting rule at the pool’s exit — neutralized a potentially catastrophic bug without disrupting the broader network. Whether the market rewards that kind of responsible engineering remains to be seen, but the first day of migration suggests holders are paying attention and moving their coins.
This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry significant risk. Always do your own research before making investment decisions.
Disclaimer: This article is for informational purposes only and does not constitute financial advice.
4 years of potential counterfeiting and nobody noticed. this is supposed to be a privacy coin? more like an audit coin at this point
to be fair the flaw was theoretical, nobody actually printed fake coins. the migration math checks out so far
frost_mage_ theoretical until someone proves it wasnt. privacy coins with trusted setups are inherently unverifiable. the migration is the right call but late by years
Lev P. theoretical or not, a counterfeiting bug in a privacy coin for 4 years means nobody can verify the true supply. thats kind of important for money
Lev P. 4 years of undetected counterfeiting risk in a privacy coin is existential. if someone actually exploited it the entire supply is unverifiable forever
zkbunker_ is right. if someone actually exploited the Orchard flaw the entire ZEC supply is unverifiable. privacy coins live and die by trusted setups and this one had a crack for 4 years
four years the flaw sat open and on chain supply never did anything weird. either nobody found it or whoever did was patient beyond belief
176k ZEC moved in one day is actually impressive for a coin most people forgot existed. question is whether the new Ironwood pool actually fixes the root issue or just moves the problem
176k ZEC rushing to the new pool in 24 hours shows people actually understand the risk. the rest sitting in the old pool are either lazy or dont follow crypto news
Bence K. 176k ZEC moved in 24 hours but millions still sitting in the old pool. either people dont know or dont care. probably both
176k ZEC moved in 24 hours but the article says millions are still in the old Orchard pool. 4 years of potential counterfeiting and people are too lazy to migrate. incredible
lazy is unfair. some of those orchard coins belong to people who lost keys or passed away. that balance sits there forever and the closure handles it anyway
lost keys are real but some of those holders just refuse to surface. moving shielded coins means exposing yourself right when every regulator is watching the pool die
Greta W. nailed the real question. most ZEC holders probably dont even know the migration is happening. privacy coin users are the least likely to check announcements
closing orchard is the most decisive move zcash has made in years. should have happened the moment the disclosure dropped instead of waiting out a migration window
81 million migrated in a day and everyone skips the better story, the audit that found a 4 year old flaw deserves the headline more than the race did
agree the audit deserves top billing. commissioning a review of a pool that old is the rare move. finding a 4 year flaw before anyone exploited it is the whole difference between disclosure and apology
4 years of potential counterfeiting in a privacy coin and the fix is just close the pool and start fresh. trust me bro it didnt happen
176k ZEC migrated in 24 hours is actually impressive for a coin most people wrote off. the Ironwood upgrade at least forced action
Minjae L. impressive until you realize millions of ZEC are still stuck in Orchard because users lost keys or dont know the migration exists
trusted_setup_void the catch 22 of privacy coins, you cant even email holders a migration reminder without breaking the whole point. ugly outreach problem
176k moved day one and the pace already slowed. the long tail never migrates, those coins are effectively burned. call it what it is, a supply cut paid for by the people who forgot they owned zec
an effective supply cut paid for by forgotten wallets is honestly the most bullish zec narrative in years. nobody in the community wants to say it out loud
four years open and zero anomalies in on chain supply is the strongest audit by accident you will ever see. ironwood still should have sealed the old pool the day the disclosure dropped
Tereza V. audit by accident is exactly right. four years of temptation and nobody touched it, then the fix arrives before any damage. weird hill to be bearish on