Zcash says Ironwood proof rules out undetectable counterfeiting bugs
Zcash researchers have completed formal verification of Ironwood, a new shielded pool introduced via the NU6.3 upgrade. They published a machine-checked proof, written in Lean and comprising over 2,700 theorems, that establishes the pool's "balance integrity." This proof confirms that, under its cryptographic assumptions, Ironwood cannot contain undetectable counterfeiting bugs, ensuring it cannot pay out more value than has publicly entered it. The verification, which took multiple teams over a month, covers the zero-knowledge proof system, circuit rules, and ledger accounting but not Ironwood's separate privacy guarantees. Ironwood was created in response to a theoretical vulnerability in the older Orchard pool that could have allowed undetectable counterfeiting, though there's no evidence of exploitation. Funds migrating from Orchard must pass through a public "turnstile" checkpoint, designed to prevent any hypothetical excess coins from entering the new pool and to provide evidence on whether the old pool was exploited.
cointelegraphDün 01:15