Zcash’s Ironwood Upgrade Passes an 87% Migration Milestone

Nearly nine out of every ten shielded ZEC coins have now moved into a privacy pool that didn’t exist five months ago. The Zcash Ironwood upgrade just passed a milestone…

Abstract glowing digital network symbolizing the security fix behind the Zcash Ironwood upgrade

Nearly nine out of every ten shielded ZEC coins have now moved into a privacy pool that didn’t exist five months ago. The Zcash Ironwood upgrade just passed a milestone that says more about trust than about technology: as of September 12, the network’s shielded supply climbed to 4.86 million coins, and 87% of that total now sits in Ironwood, the rebuilt privacy engine that replaced a flawed predecessor in barely six weeks.

What Went Wrong With Orchard

The story starts with a flaw nobody wanted to find. In late May, independent researcher Taylor Hornby spotted a soundness bug buried in the zero-knowledge circuit powering Orchard, Zcash’s prior shielded pool. The math itself had a crack in it. Someone who understood the flaw well enough could, in theory, mint counterfeit ZEC without leaving a trace behind. No attacker exploited it before Electric Coin Company patched the hole, but the exposure was real, and it couldn’t wait for a routine upgrade cycle.

Developers moved fast. They disabled Orchard with an emergency soft fork on June 2, then pushed a corrective hard fork the very next day. That bought the team time to build something sturdier from the ground up.

How the Zcash Ironwood Upgrade Fixes the Flaw

Ironwood, which went live on mainnet at the end of July, keeps the same Halo 2 proof system Orchard used, but with the vulnerable circuit corrected and rebuilt. What’s new is the scrutiny around it. The corrected circuit went through formal verification, a mathematical process that checks code behaves correctly under every possible input instead of just the cases engineers thought to test.

Ironwood also adds two protections aimed at the future, not just the present bug. Quantum-recoverable notes, defined under ZIP 2005, give shielded coins a documented recovery path if a quantum computer eventually breaks today’s cryptography, the same concern that has Ethereum’s developers working toward a fixed 2029 deadline of their own. And a new turnstile mechanism caps how much ZEC can exit the shielded pool at once, letting outside auditors verify the circulating supply independently instead of taking the network’s word for it.

Why the Migration Number Is the Real Story

Cryptographic fixes only matter if people actually use them, and that’s where this week’s number stands out. Reaching an 87% migration rate in about six weeks, with no hard deadline forcing anyone’s hand, suggests Zcash holders understood what was at stake and acted on it voluntarily. Shielded ZEC had already grown from 8% of circulating supply in 2024 to 30% by this past spring. Ironwood’s adoption curve shows that growth didn’t stall after a scare. It kept climbing, straight into safer infrastructure.

That pattern is worth watching across the industry. A network that ships a security patch is one thing. A network whose users migrate en masse within weeks, the way Core Lightning’s user base stuck around through its own quiet security patch, is a stronger signal that privacy tooling on blockchains has grown past the theoretical stage and into something people are actually willing to rely on.

Related Reading