Zcash Activates Ironwood Protocol to Verify Circulating Supply Amid Vulnerability Concerns
Zcash has activated the Ironwood (NU6.3) protocol, which introduces a new mechanism to verify the circulating supply of ZEC. This move is not a security patch, but rather a response to a problem that arises from prioritizing transaction privacy over auditability. In May 2026, researcher Taylor Hornby identified a vulnerability in the Orchard circuit that could have allowed counterfeit ZEC to be created without leaving an on-chain record.
The Ironwood protocol implements the Turnstile mechanism, which is a public counter that tracks the inflow and outflow of funds from the Orchard pool. The accounting rule is simple: no more ZEC can leave than was legitimately deposited. Any surplus, including potentially counterfeit ZEC, will be permanently trapped in Orchard.
This design change has significant implications for the market. Historically, Zcash assumed its supply was fixed and verifiable. Ironwood introduces a mechanism that allows any node operator to mathematically verify that the circulating supply does not exceed legitimate deposits.
Analyst Kyle du Plessis notes that the $530 level is a key threshold to watch: breaking above would suggest no exploitation occurred, while remaining below could indicate otherwise. However, Ironwood cannot retrospectively prove whether any counterfeit ZEC existed or was exploited.