Particle.news

Zcash Advances Ironwood Plan to Restore Trust After Orchard Soundness Bug

Developers want full nodes to verify ZEC’s circulating supply on Ironwood’s activation day to repair confidence after a patched zero‑knowledge flaw.

Overview

  • Security engineer Taylor Hornby used an AI‑assisted audit to find a soundness bug in Orchard’s zero‑knowledge circuit that could have let a malicious prover create accepted proofs that did not match valid state changes.
  • Zcash developers issued an emergency soft fork and then the NU6.2 hard fork to install a corrected circuit and reopen shielded transfers, and they report no on‑chain evidence that counterfeit ZEC were minted.
  • The Ironwood proposal would close the legacy Orchard pool to new internal outputs and require funds to exit through a protocol turnstile that tracks legitimate inflows and outflows, letting full nodes immediately check total circulating supply on Day 1.
  • The public disclosure drove a sharp market selloff that cut ZEC prices by roughly 38–50% and triggered large liquidations, and the community now faces a coordination task to test, audit, formally verify, and stage the Ironwood migration.
  • The bug’s discovery by a roughly $200 AI‑assisted review highlights how automated tools are changing cryptographic audits and adds pressure for wider formal verification and independent reviews across privacy‑preserving blockchains.