Zcash says Ironwood proof rules out undetectable counterfeiting bugs
Zcash researchers have completed formal verification of Ironwood, publishing a machine-checked proof that the network's new shielded pool does not contain undetectable counterfeiting bugs under its stated cryptographic assumptions.
Intelligence analysis by Llama

Zcash researchers have completed a formal verification of Ironwood, a new shielded pool that does not contain undetectable counterfeiting bugs. The proof covers the components needed for balance integrity, including Ironwood's zero-knowledge proof system, circuit rules, and ledger-level accounting.
Imagine you have a special box where you can store your money. The box has a lock that makes sure no one can take your money without you knowing. Zcash just made sure that the lock on this box is super strong and can't be broken. This makes people trust the box more and feel safer storing their money in it.
Analysis
A $60B Vote of Confidence
The completion of the Ironwood proof is a significant milestone for Zcash, as it establishes a security property known as balance integrity. This property ensures that the shielded pool cannot pay out more value than has publicly entered it. The proof covers the components needed for this property, including Ironwood's zero-knowledge proof system, circuit rules, and ledger-level accounting. The researchers used the Lean programming language to write the proof, which comprises over 2,700 theorems. The work took three teams of researchers and cryptographers over a month to complete.
Why Zcash Needed Ironwood
The introduction of Ironwood was in response to a vulnerability discovered in Zcash's Orchard shielded pool. This vulnerability could have theoretically enabled undetectable ZEC counterfeiting. Zcash developers said they found no evidence that the flaw had been exploited. The new pool was designed to restore confidence in Zcash's supply integrity.
The Road Ahead
The completion of the Ironwood proof is a significant step forward for Zcash. It establishes a security property that ensures the shielded pool cannot pay out more value than has publicly entered it. The researchers said that the proof covers the components needed for balance integrity, including Ironwood's zero-knowledge proof system, circuit rules, and ledger-level accounting. The work establishes a security property known as balance integrity, designed to ensure the shielded pool cannot pay out more value than has publicly entered it.
Key points
- Zcash researchers have completed formal verification of Ironwood, publishing a machine-checked proof that the network's new shielded pool does not contain undetectable counterfeiting bugs under its stated cryptographic assumptions.
- The proof covers the components needed for balance integrity, including Ironwood's zero-knowledge proof system, circuit rules, and ledger-level accounting.
- The introduction of Ironwood was in response to a vulnerability discovered in Zcash's Orchard shielded pool that could have theoretically enabled undetectable ZEC counterfeiting.
- The new pool was designed to restore confidence in Zcash's supply integrity.
If this development plays out positively, it could increase trust in Zcash's supply integrity and lead to more people using the network. This could also lead to an increase in the value of ZEC.
However, if the flaw in the Orchard shielded pool was exploited, it could lead to a loss of trust in Zcash's supply integrity and a decrease in the value of ZEC. Additionally, if the proof is not widely accepted, it could lead to a decrease in the value of ZEC.



