Zcash has activated its Ironwood network upgrade, locking in a $1.7 billion shielded pool and patching a vulnerability that could have allowed undetectable counterfeiting of ZEC. The upgrade went live without incident, according to the project's development team.
The vulnerability behind the upgrade
The flaw, discovered during a routine security audit, raised fears that an attacker could create ZEC out of thin air without leaving a trace on the blockchain. Because Zcash's shielded transactions use zero-knowledge proofs to hide sender, receiver, and amount, a bug in the proving system could have let someone mint counterfeit coins that appeared legitimate. The developers declined to share technical specifics until all users had updated their software, but confirmed the issue was critical.
What the shielded pool means
The $1.7 billion figure represents the total value of ZEC held in the network's shielded pool at the time of the upgrade. That pool is the heart of Zcash's privacy promise — it allows users to transact privately, with the blockchain verifying the transaction without revealing details. By sealing the pool, the Ironwood upgrade ensures that all coins inside remain valid and that no new counterfeit coins can be injected through the now-fixed vulnerability.
Next steps for Zcash
All node operators and miners were required to update to the latest software before the upgrade activated. Users holding ZEC in shielded addresses do not need to take any action; their coins remain accessible. The Zcash Foundation has urged anyone running older software to upgrade immediately to avoid being on a fork that does not include the security patch. The network is now running on the Ironwood rules, and the shielded pool is secured against the patched vulnerability.




