Zcash Developers Recommend Upgrading Nodes to Ironwood Fork

cryptonews.ruPublished on 2026-07-27Last updated on 2026-07-27

Abstract

The Zcash Foundation has released Zebra 6.0.0 and recommends all node operators upgrade to the Ironwood fork. This update introduces a new shielded pool and version 6 transaction format. The change was prompted by a vulnerability discovered in the old Orchard pool that could have allowed an attacker to create counterfeit $ZEC undetected. Developers patched the vulnerability in June, finding no evidence of exploitation, though Zcash's privacy architecture prevents absolute certainty. Ironwood utilizes the Orchard action structure and Halo2 proof system. It adds a separate note commitment tree, a nullifier set, a network value pool, and network history data. After activation, nodes can track the new pool independently from Orchard. Zebra also updates node commands for operators to verify pool and commitment tree states. This upgrade is critical, as older software will not follow the correct chain post-activation. Ironwood's key protection mechanism is a "turnstile" between the Orchard and new pools. Once activated, Orchard will stop accepting new outputs and internal transfers. Funds can be withdrawn, but an accounting rule prevents withdrawing more $ZEC from Orchard than was legitimately deposited. This design allows public auditing of the circulating supply without revealing private balances or transaction details, with any excess capital becoming locked inside Orchard. Zcash had scheduled this hardfork for July 28 after developers confirmed the patched bug raised inflation...

The Zcash Foundation developers have released Zebra 6.0.0 and recommended all node operators upgrade to the fork. The update includes a new shielded pool and transaction format v6.

Its release is related to a vulnerability discovered in the old Orchard pool, which could have allowed an attacker to covertly create counterfeit $ZEC.

The developers addressed the vulnerability with emergency patches in June. At the same time, they did not find any evidence of the vulnerability being exploited, but Zcash's privacy architecture does not allow them to state this with complete certainty.

According to the Zebra 6.0.0 release notes, Ironwood uses the Orchard action structure and the Halo2 proof system. It also adds a separate note commitment tree, a set of nullifiers, a network value pool, and network history data. Once activated, these records allow nodes to track the new pool independently of Orchard.

Zebra also updates several node commands so operators can check the state of the pool and the commitment tree. On GitHub, this update is marked as critical for operators because the old software will not follow the correct network after the activation height is reached.

The primary supply protection mechanism of Ironwood is a kind of "turnstile" between Orchard and the new pool. After activation, Orchard will stop accepting new outputs and internal transfers. Funds can be withdrawn, but a value accounting rule prevents withdrawing more $ZEC from Orchard than was legitimately added to it.

The Ironwood design description notes that this mechanism provides users with public oversight over the circulating supply without revealing private balances or transaction details. After withdrawals, any excess capital will remain locked inside Orchard.

As Happy Coin News previously reported, Zcash scheduled the hard fork for July 28 after developers confirmed the fixed bug raised doubts about supply inflation.

end-content

Related Questions

QWhy did the developers of Zcash release Zebra 6.0.0?

AThe developers of Zcash Foundation released Zebra 6.0.0 to address a vulnerability in the old Orchard pool that could have allowed an attacker to create counterfeit $ZEC, and to prepare for the Ironwood fork which introduces a new secure pool and v6 transaction format.

QWhat is the main security mechanism introduced by the Ironwood fork?

AThe main security mechanism introduced by the Ironwood fork is a 'turnstile' between the old Orchard pool and the new secure pool. After activation, Orchard will stop accepting new outputs and shielded transactions, and funds can only be withdrawn up to the amount legitimately deposited, preventing the creation of counterfeit coins.

QWhat does the Zebra 6.0.0 update enable node operators to do?

AThe Zebra 6.0.0 update enables node operators to check the state of the new secure pool and the commitment tree, ensuring they can track the new pool independently of the old Orchard pool.

QWhat key technology does the Ironwood fork utilize?

AThe Ironwood fork utilizes the Orchard action structure and the Halo2 proof system. It also adds a separate spending commitment tree, a set of nullifiers, a network value pool, and network history data.

QWhen is the Zcash hard fork scheduled to occur?

AAccording to the article, the Zcash hard fork is scheduled for July 28.

Related Reads

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

The Coldcard hardware wallet has been compromised, with hackers stealing approximately 594.5 Bitcoin (~$40 million) from 500 addresses in just 25 minutes. The root cause was a critical software bug, undetected for five years, which disabled the device's secure chip for generating true random numbers. This led to the creation of private keys based on predictable data like the processor's serial number, drastically reducing cryptographic security. The attackers exploited this offline by brute-forcing possible seed phrases, finding active addresses on the public ledger, and signing transactions. Initially, Coinkite (Coldcard's maker) claimed only older models were at risk but later admitted all devices running the compromised firmware were vulnerable. CEO Rodolphe Novak (NVK) apologized but ruled out financial compensation for affected users. To secure funds, owners must urgently update their firmware to specific safe versions, generate a completely new seed phrase on the updated device, and transfer all assets to new addresses created with that new seed. While a BIP-39 passphrase can help, it does not replace this migration process. Other Coinkite products like TAPSIGNER were not affected. This incident underscores that even specialized hardware requires rigorous, independent code audits, especially for cryptographic functions. It parallels past failures, like a 2006 OpenSSL bug in Debian, and raises questions about whether automated code analysis can ever fully replace human scrutiny in critical security areas.

cryptonews.ru2h ago

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

cryptonews.ru2h ago

Trading

Spot
活动图片