Zcash says Ironwood proof rules out counterfeiting bugs
Zcash says Ironwood proof rules out undetectable counterfeiting bugs after researchers published more than 2,700 machine-checked theorems for the new shielded pool. The Lean proof targets balance integrity so the pool cannot pay out more value than entered, restoring supply confidence after an Orchard flaw.
Key Takeaways
- Project Tachyon said the Ironwood formal verification spans over 2,700 theorems written in Lean and took more than a month across three research teams.
- The proof focuses on balance integrity for Ironwood’s zero-knowledge proof system, circuit rules, and ledger-level accounting—not separate privacy guarantees.
- Ironwood arrived via Zcash’s NU6.3 upgrade after a theoretical Orchard counterfeiting vulnerability; developers said they found no evidence of exploitation.
- Orchard-to-Ironwood migrations must pass a public “turnstile” checkpoint meant to stop any hypothetical excess coins from entering the new pool.
For more market and protocol alerts, see BlasterPost’s Fintech & Crypto Alerts hub.
What did Zcash announce about the Ironwood proof?
According to Cointelegraph, Zcash researchers completed formal verification of Ironwood and published a machine-checked proof that the network’s new shielded pool does not contain undetectable counterfeiting bugs under its stated cryptographic assumptions.
On Tuesday, Project Tachyon said the proof comprises more than 2,700 theorems and that three teams of researchers and cryptographers spent over a month finishing the work. The stated goal is a security property called balance integrity: the shielded pool should not be able to pay out more value than has publicly entered it.
Why does balance integrity matter for Zcash holders?
Undetectable counterfeiting would quietly inflate the ZEC supply inside a shielded pool, undermining trust in the coin’s scarcity. A machine-checked proof is meant to give stronger assurance than informal audits alone that Ironwood’s accounting cannot create value from nothing under the model’s assumptions.
Researchers said the proof covers the components needed for that property, including Ironwood’s zero-knowledge proof system, circuit rules, and ledger-level accounting. It does not cover Ironwood’s separate privacy guarantees, so users should not read the result as a full privacy certification.
How is Ironwood tied to the Orchard shielded-pool flaw?
Ironwood was introduced through Zcash’s NU6.3 upgrade after a vulnerability in the Orchard shielded pool that could theoretically have enabled undetectable ZEC counterfeiting. Zcash developers said they found no evidence that the flaw had been exploited. The new pool was designed to restore confidence in supply integrity.
Funds migrating from Orchard must pass through a public accounting checkpoint known as a turnstile, which is designed to prevent any hypothetical excess coins from entering Ironwood. As funds leave Orchard, that process could also provide growing evidence about whether the old pool was exploited.
The announcement does not claim the Orchard issue never existed; it frames Ironwood’s verified balance property—and the turnstile migration path—as the technical response aimed at ruling out undetectable counterfeiting in the new pool.