Zcash will cut off access to its legacy Orchard pool via the Ironwood (NU6.3) hard fork, scheduled to activate at block 3,428,143 on July 28, 2026. This lockdown is being implemented to permanently eliminate risks stemming from a critical cryptographic bug that previously threatened the privacy network’s shielded system.
The bug was first discovered by security researcher Taylor Hornby on May 29 during an audit of Zcash’s shielded system. Its severity was critical: the vulnerability could have allowed an attacker to mint counterfeit ZEC directly within the Orchard environment without generating any public record. Orchard’s core feature of obscuring transaction details became a double-edged sword in this scenario. While the Zcash team believes the vulnerability was never exploited, the network’s privacy architecture makes that impossible to prove with absolute certainty.
Turnstile Mechanism
Since no one can observe what has actually occurred inside the legacy pool, Ironwood implements a protocol-level containment solution. The legacy Orchard pool will be fully sealed. All remaining withdrawals must pass through a strict “turnstile” mechanism. This rule imposes a rigid cap: the total amount of ZEC exiting the old pool will never be allowed to exceed the amount of legitimate coins that previously entered it.
If an attacker had minted thousands of fake coins through the exploit, those phantom assets would remain permanently trapped inside, unable to pass through the turnstile to reach exchanges. The Zcash network has already migrated active transaction flows to a new shielded pool, running on the repaired cryptographic framework from the earlier NU6.2 release.
Clearing Supply Concerns
Ahead of the Ironwood rollout, the price of ZEC responded positively, breaking above the $500 mark. Regular users do not need to take any action. However, to safeguard user funds, crypto exchanges and wallet services will likely suspend deposits and withdrawals temporarily during the network transition.
This hard fork exists purely to resolve lingering questions regarding ZEC supply integrity, as the primary bug itself has already been patched. Subsequent code reviews assisted by Anthropic’s Mythos AI model identified no other serious vulnerabilities following the May discovery. As a final safeguard, Zcash developers are completing independent audits and formal verification for their new cryptographic architecture, taking the long road to ensure there is no room left for phantom coins. Reported by crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




