📈 Get daily crypto insights that make you smarter about your money

Zcash Seals Its Old Privacy Pool After a 4-Year Counterfeiting Flaw and Holders Are Already Racing to Migrate

Just one day after Zcash sealed its old privacy pool over a counterfeiting flaw that went unnoticed for four years, roughly 176,000 ZEC — worth about 81 million in dollar terms — has already rushed into the network’s brand-new Ironwood pool. The race to migrate is on, but the vast majority of the privacy coin’s hidden supply remains trapped in a pool that can no longer accept new deposits.

By Jennifer Kim | July 29, 2026

The Hook

Imagine your bank discovered a flaw in its vault door that, in theory, could have let someone print fake money for four years without anyone noticing. The bank’s solution? Build a brand-new vault next door, seal the old one shut so no new money can go in, and let every customer individually move their funds to the new building — at their own pace, through a hallway that carefully counts every coin on the way out.

That is exactly what happened with Zcash, one of the oldest privacy-focused cryptocurrencies, when it activated its Ironwood upgrade on Tuesday. The upgrade formally known as NU6.3 closed the Orchard shielded pool — the compartment where most of Zcash’s private transactions lived — and opened a fresh pool starting with zero coins.

On-Chain Evidence

The numbers tell a story of cautious but steady movement. According to the Ironwood migration tracker, about 176,000 ZEC had crossed into the new pool within the first 24 hours. At current prices near 463 per ZEC, that translates to roughly 81 million in dollar value.

That sounds like a lot — and it is — but it represents only about 5 percent of the 3.66 million ZEC that was sitting in Orchard when the upgrade went live. Another 46,000 ZEC crossed over in the past day alone, bringing Orchard’s balance down to approximately 3.51 million ZEC.

The rest of Zcash’s supply sits elsewhere. The transparent pool, which works like Bitcoin with every transaction visible on the public ledger, holds about 12.5 million ZEC. The older Sapling pool, introduced in 2018, contains roughly 582,000 ZEC. Each generation of Zcash’s privacy technology gets its own pool, and every time the network upgrades, holders must move their coins across themselves.

The Core Conflict

The urgency behind this upgrade traces back to May 29, when Shielded Labs researcher Taylor Hornby discovered that Orchard’s proof circuit contained a bug that could have allowed someone to mint counterfeit ZEC without leaving any trace on the blockchain. The flaw had been live since Orchard launched in May 2022 — four full years.

Here is the unsettling part: nobody can prove the bug was never exploited. Zcash’s zero-knowledge proofs are designed to reveal nothing beyond the fact that a transaction is valid. So the chain holds no record of whether counterfeit coins were ever created. If someone did mint fake ZEC, those coins are now locked inside Orchard with no way out except through the turnstile.

The turnstile is the clever part of this whole design. Money crossing between pools is public, even when transactions inside the pool are completely private. The network knows exactly how much real ZEC went into Orchard. It will not release more than that amount. Any fake coins sitting inside are effectively trapped forever.

The evidence, thankfully, points away from exploitation. A CoinDesk Research report published in July found that Orchard’s balance grew steadily through the four years the flaw was open, including during last year’s major price rally when cashing out would have been most profitable. If someone had printed fake coins, they likely would have moved them out to sell — and that movement would have shown up as funds leaving the pool.

Market Implications

ZEC traded near 463 ahead of the Ironwood switch, down 8 percent on the day and 15 percent over the week, though the coin remains up roughly tenfold over the past year. The price reaction suggests the market views the upgrade as necessary medicine — unpleasant in the short term but far better than the alternative of leaving a counterfeiting vulnerability open indefinitely.

For context, Bitcoin hovered near 64,000 on Wednesday while the broader crypto market waited on the Federal Reserve’s rate decision. Ethereum traded around 1,890, down about 1.5 percent. ZEC’s 8 percent single-day decline stood out as steeper than most major coins, reflecting the upgrade-specific uncertainty.

The key question for investors is how quickly the remaining 3.5 million ZEC migrates. Because the process is entirely voluntary and user-driven, the timeline depends on individual holders, wallet providers, and exchanges updating their software to support Ironwood deposits. Until that happens, the majority of Zcash’s private supply sits in a pool that has been closed to new money since Tuesday — a sort of financial limbo.

The Verdict

Ironwood brings two major improvements that Orchard never had. First, the record each coin leaves on the blockchain is built to stay recoverable even if future quantum computers break today’s cryptography — a forward-looking safeguard specified under proposal ZIP 2005. Second, the pool’s proof circuit is undergoing formal verification, a rigorous process that produces mathematical proof the code works correctly in every possible scenario, not just the cases testers thought to check.

Think of it like upgrading from a door lock that was visually inspected to one that comes with a mathematical guarantee. The old lock probably worked fine — and all evidence suggests it did — but you can never be completely sure. The new lock comes with proof.

For everyday investors, the Zcash Ironwood story is a reminder that cryptocurrency is still a young technology where fundamental issues can hide for years. It also shows that well-designed systems can fix problems without imploding. The turnstile mechanism — a simple accounting rule at the pool’s exit — neutralized a potentially catastrophic bug without disrupting the broader network. Whether the market rewards that kind of responsible engineering remains to be seen, but the first day of migration suggests holders are paying attention and moving their coins.

This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry significant risk. Always do your own research before making investment decisions.

3 thoughts on “Zcash Seals Its Old Privacy Pool After a 4-Year Counterfeiting Flaw and Holders Are Already Racing to Migrate”

  1. 4 years of potential counterfeiting and nobody noticed. this is supposed to be a privacy coin? more like an audit coin at this point

    1. to be fair the flaw was theoretical, nobody actually printed fake coins. the migration math checks out so far

  2. 176k ZEC moved in one day is actually impressive for a coin most people forgot existed. question is whether the new Ironwood pool actually fixes the root issue or just moves the problem

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,476.00-0.7%ETH$1,884.22-1.8%SOL$72.52-2.2%BNB$567.19-0.6%XRP$1.07+0.4%ADA$0.1628+2.4%DOGE$0.0694-1.8%DOT$0.7570-0.6%AVAX$6.33-3.8%LINK$8.21-1.9%UNI$3.89+0.6%ATOM$1.27-2.5%LTC$44.73-3.7%ARB$0.0776-0.8%NEAR$1.59-3.3%FIL$0.6606-6.0%SUI$0.6790-2.1%BTC$63,476.00-0.7%ETH$1,884.22-1.8%SOL$72.52-2.2%BNB$567.19-0.6%XRP$1.07+0.4%ADA$0.1628+2.4%DOGE$0.0694-1.8%DOT$0.7570-0.6%AVAX$6.33-3.8%LINK$8.21-1.9%UNI$3.89+0.6%ATOM$1.27-2.5%LTC$44.73-3.7%ARB$0.0776-0.8%NEAR$1.59-3.3%FIL$0.6606-6.0%SUI$0.6790-2.1%
Scroll to Top