NEAR - Sponsor Image NEAR - Confidential swaps across 35+ chains Friend & Sponsor Learn more

Zcash Trades Trust for Proof

Zcash's Ironwood upgrade is live, replacing the wounded Orchard pool with a formally verified successor.
Zcash Trades Trust for Proof
Listen
0
0
0:00 0:00

Subscribe to Bankless or sign in

To date, Privacy chains have faced a paradoxical thorn latent in their designs. When something might have gone wrong, the same cryptography that shields users also blinds auditors.

Zcash Zcash has been pressured by this exact paradox for the past two months. In late May, Shielded Labs researcher Taylor Hornby used AI to surface a critical bug in Orchard, Zcash's largest shielded pool, i.e. a private layer where senders, recipients, and amounts stay hidden.

Rotten Apples in the Orchard on Bankless
Zcash patched a critical privacy pool bug that could have enabled fake ZEC, though it can’t prove, as of now, no fake ZEC was already minted.

The flaw sat in Orchard's circuit (the zero-knowledge rulebook that defines a valid private transaction) and had been there since the pool launched in 2022.

In theory, this vector could've let an attacker mint counterfeit ZEC undetected. Emergency forks patched the circuit within days, though a wound remained. Since Orchard hides everything, nobody could prove that no fake ZEC had ever been created. That possibility spooked traders, and ZEC shed over half its value on the disclosure.

But fast forward to today, and Zcash just shipped its definitive repair: the Ironwood upgrade.

Ironwood, also the name of the new shielded pool, reapplies the corrected Orchard circuit and its Halo 2 proving system, but its protocol has now been formally verified, i.e. mathematically machine-checked against the rules it must enforce, rather than merely audited and tested.

And this is no marketing gimmick, as multiple teams of cryptographers spent over a month producing a public Lean proof (+2,700 theorems' worth) culminating in "balance integrity," which is the guarantee that undetectable counterfeiting bugs (the exact class that burned Orchard) cannot exist in Ironwood.

Zcash co-founder Sean Bowe and Tal Derei broke down the whole proof effort in a new report out today:

Enjoying this article?

Subscribe to Bankless or sign in

Additionally, with the arrival of Ironwood has come the sealing of Orchard.

The old pool is closed to new deposits, and funds inside can no longer circulate freely. Every exit must pass Zcash's "turnstile" system, a public value-accounting checkpoint that caps outflows at what verifiably flowed in, before entering Ironwood. And in extension, new shielded payments now route to Ironwood automatically.

Accordingly, not only does Ironwood protect the future of Zcash going forward, but it also makes sure that its past can't contaminate the future, so to speak. Any hypothetical counterfeits are cornered inside Orchard whose exits are capped at its legitimate deposits.

Notably, too, this healing took impressive coordination across multiple orgs, like the Zcash Foundation, the Zcash Open Development Lab, Shielded Labs, Tachyon, and beyond. Not bad for a decentralized ecosystem with no central company steering it, to be sure, as plenty of centralized teams would have struggled to replace this pool in two months. The Zcash community got it done despite the challenges.

In the meantime, migration out of Orchard is discretionary, though painless, since Ironwood reuses Orchard's receiver structure, meaning no new wallets or addresses are needed and apps like Zodl have migration support built in. At the time of writing, +111k ZEC had made the move over, leaving +3.5M ZEC still sitting in the old pool for now.

As for what comes next, Zcash has its ensuing upgrade slated as NU7, which aims to target faster blocks (~25 seconds, down from 75) and higher shielded throughput for Ironwood. The throughput gains would come from roughly doubling shielded capacity per block, which, teamed with 3x faster blocks, pencils out to a ~6x increase. It might be unglamorous prep work, but it's the kind of stuff that will help pave the way for shielded Zcash payments to become the norm.

It's true that Orchard was a serious setback. However, the silver lining is that this thorn led to Zcash's state today, as the network is now oriented around machine-checked math. Making privacy ubiquitous starts with making it provable, and Zcash just took its biggest step yet in that direction. Now, let's see how the chain proceeds and recuperates from here.


William M. Peaster

Written by William M. Peaster

1023 Articles View all      

William M. Peaster, Senior Writer, has been with Bankless since January 2021. Immersed in Ethereum since 2017, he covers the onchain frontier with a particular interest in art, games, and other culture apps. He has a background in creative writing and writes fiction in his free time.

No Responses
Buscar en Bankless