The activation of Ironwood (NU6.3) at block height 3,428,143 on July 28, 2026, marks a defining moment for Zcash. Following the emergency patch NU6.2 on June 3, which addressed a critical vulnerability in the Orchard circuit discovered by researcher Taylor Hornby of Shielded Labs, the Zcash ecosystem now implements a radical containment strategy. The vulnerability, present since Orchard’s launch in May 2022, theoretically allowed the creation of counterfeit ZEC without leaving any on-chain trace — a flaw inherent to the zero-knowledge proofs that underpin Zcash’s privacy.
Ironwood introduces the Turnstile mechanism, a public counter that permanently locks the Orchard pool, containing 3.76 million ZEC (approximately $1.89 billion, or 22% of the circulating supply). No new outputs can enter the pool, and only legitimate deposits can exit. Any surplus — potentially counterfeit coins — remains trapped forever. As Zooko Wilcox noted, the verification is now “mathematical and publicly verifiable by anyone running the node software,” a stark departure from the closed handling of a similar vulnerability in the Sprout pool back in 2018.
The upgrade arrives alongside a broader infrastructural overhaul: the legacy zcashd software reaches end-of-life on July 18, replaced by the Rust-based Z3 stack (Zebra, Zaino, Zallet). A total of 51 developers contributed 1,391 pull requests over a relentless 60‑day cycle. The new Zakura full node can sync in just four hours, and ZIP 2005 introduces quantum-recoverable notes as a future-proofing measure.
Despite the engineering feat, uncertainty lingers. Ironwood cannot retroactively prove no counterfeit ZEC was ever minted, only that any such coin cannot enter the tradable supply. The effective circulating supply has instantly shrunk by 3.76 million ZEC. Market reaction has been cautiously optimistic: ZEC rebounded from a 50% drop to $299.25 after the vulnerability disclosure, climbing back near $492.61, while open interest in ZEC futures surged 18% in 24 hours to $914.91 million. Analyst Kyle du Plessis points to $530 as the critical threshold: breaking above it would signal market belief that no exploitation occurred.
Operational risks remain for holders migrating out of Orchard. Every exit is a public transaction that exposes the amount, and connecting to a wallet server can reveal the user’s IP address. Wilcox strongly advises using Tor or Nym for network‑level privacy before initiating any migration, a reminder that even supply verifiability comes with trade-offs.