CoinYQ Dossier

Zcash Made Payments Private—Then Had to Patch Orchard in Public

Zcash began with ceremony-dependent Sprout, moved through Sapling to Halo-based Orchard, then had to disable and repair Orchard in 2026. NU6.3 now routes new shielded value into Ironwood and seals Orchard to inflows. ZEC remains optional-privacy proof-of-work money; Ironwood prepares recoverability but is not itself post-quantum protection.

Zero-knowledge research became spendable money

The Zerocash paper published on 18 May 2014 proposed decentralized anonymous payments using succinct zero-knowledge proofs. Electric Coin Company formed in 2015 to turn that research into Zcash, which launched in October 2016 with transparent addresses and a shielded Sprout pool.

Privacy was optional rather than universal. Transparent transactions expose values and addresses, while shielded transactions hide payment details inside cryptographic commitments and proofs. Wallet records, exchanges, network metadata, address reuse, and movement between pools can still reveal information outside the proof system.

Orchard removed one ceremony and changed wallet design

Network Upgrade 5 activated on 31 May 2022 at block 1,687,104. It introduced the Orchard shielded protocol, Halo proofs without an Orchard trusted setup, and Unified Addresses that let wallets package compatible receiver types behind one address.

The live ecosystem now centers shielded-capable products such as Zodl (formerly Zashi) while preserving transparent compatibility. Protocol capability does not guarantee shielded use: sender, recipient, wallet, exchange, and service support determine whether a payment stays private end to end.

Issuance and funding are rules, not holder ownership

ZEC has a 21-million maximum supply and is issued through proof-of-work block rewards. At NU6.1 height 3,146,400, 78,750 ZEC accumulated under the earlier lockbox was paid once to a 2-of-3 multisig whose key holders are Zcash Foundation, ECC and Shielded Labs. The rules also continue 8% of subsidy for ZCG and 12% for the deferred lockbox through height 4,406,400. Those signers and grant processes control allocated funds; ordinary ZEC holders do not own a proportional share.

ZEC pays fees and can be mined, held, and transferred through transparent or shielded pools. The reviewed protocol materials do not establish that holding ZEC alone grants equity in Electric Coin Company or the Zcash Foundation, a fixed-value redemption claim, a contractual share of development-fund revenue, or a general governance vote; separate contracts and legal rights are outside that evidence.

A 2026 soundness bug tested the upgrade process

On 29 May 2026, an AI-assisted audit reported an Orchard circuit flaw that could have permitted invalid balance creation and theft if exploited. The emergency response disabled Orchard while developers prepared a corrected circuit; the record does not establish that an attacker used the flaw.

NU6.2 activated at block 3,364,600 on 3 June 2026 and re-enabled Orchard with the fix. The incident is material even without proven exploitation because zero-knowledge soundness is a monetary-security boundary, and emergency upgrades create coordination and availability costs.

Ironwood became the live boundary after the repair

On 28 July 2026, NU6.3 activated Ironwood at block 3,428,143. It prohibited new value from entering Orchard and required funds leaving that pool to pass through a publicly visible turnstile before entering Ironwood. That boundary lets observers compare the old pool’s inflows and outflows, while moving new shielded activity to the replacement pool.

ZIP 2005 still carries a Proposed header, yet NU6.3 activated its recoverable note format for Ironwood. The distinction matters: those notes are structured for a possible future Recovery Protocol, but that protocol is not deployed and the change does not make present Zcash quantum-safe. Sprout, Sapling and pre-Ironwood Orchard funds do not acquire recoverability.

How the project changed

  1. 2014-05-18
    The Zerocash paper is published

    Researchers described decentralized anonymous payments built with succinct zero-knowledge proofs.

  2. 2016-10-28
    Zcash launches

    The network began with transparent transfers and the original Sprout shielded pool.

  3. 2022-05-31
    NU5 activates Orchard and Halo

    Block 1,687,104 introduced Orchard, Unified Addresses, and a proving system without an Orchard trusted setup.

  4. 2026-05-29
    Orchard soundness flaw is reported

    An audit identified a circuit error capable in principle of violating balance rules; Orchard was temporarily disabled while a fix was prepared.

  5. 2026-06-03
    NU6.2 re-enables corrected Orchard

    The network activated the repaired Orchard circuit at block 3,364,600; the public record does not establish prior exploitation.

  6. 2026-07-28
    NU6.3 activates Ironwood

    At block 3,428,143, new shielded value began entering Ironwood and Orchard became spend-down only; Zebra followed the new rules after zcashd had halted.

Evidence and primary sources

Last evidence review: 2026-09-05

More stories about this project

What is Zcash?

Zcash is a proof-of-work payment network whose native ZEC can move transparently or through shielded pools. Under current NU6.3 rules, new shielded value enters Ironwood while legacy Orchard can only be spent down. The reviewed protocol materials do not establish that holding ZEC alone grants equity, a fixed-value redemption claim, a share of protocol revenue, or a general governance vote; separate contracts and legal rights are outside that evidence.

What problem does Zcash solve?

Each privacy generation changed a different security boundary. Sprout and Sapling depended on multi-party parameter ceremonies; Orchard used Halo 2 without a new trusted setup, yet a 2026 circuit flaw still threatened monetary soundness. Ironwood now separates new shielded value from the old Orchard pool so supply migration can be audited.

How does Zcash work?

Sprout launched in 2016, Sapling activated at height 419,200 in 2018, and NU5 introduced Orchard at 1,687,104 in 2022. ZIP 257 records Orchard’s emergency disablement and corrected NU6.2 circuit in June 2026. NU6.3 activated Ironwood at height 3,428,143 on 28 July: new value cannot enter Orchard and must cross the public turnstile into Ironwood. Zebra validates the upgraded chain; zcashd halted before activation. Transparent receivers remain available, so privacy is still a user and wallet choice.

Key facts

  • Native asset: ZEC, issued by Equihash proof of work with a 21 million maximum supply.
  • Launch: mainnet started on 28 October 2016 with transparent transfers and the Sprout shielded pool.
  • Trust boundary: Sprout used a six-participant ceremony; Sapling used a larger ceremony; Halo removed the need for a new setup only for Orchard-era proofs.
  • Optional privacy: transparent transfers publish addresses and values, while shielded pools conceal payment details; metadata and pool crossings can still leak information.
  • NU5: Orchard, Halo 2 and Unified Addresses activated at height 1,687,104 on 31 May 2022.
  • ZIP 257: a 29 May 2026 Orchard soundness report led to temporary disablement and corrected NU6.2 activation at height 3,364,600 on 3 June.
  • Current consensus: protocol specification 2026.8.0 records NU6.3; it activated Ironwood at height 3,428,143 on 28 July 2026 and stopped new value entering Orchard.
  • Quantum boundary: Ironwood notes use a recoverable format, but the Recovery Protocol is future work and current Zcash is not post-quantum.
  • Node boundary: zcashd halted before NU6.3 and does not support it; Zebra is the current full validator implementation.
  • Current funding: NU6.1 paid 78,750 ZEC from the old lockbox to a Zcash Foundation/ECC/Shielded Labs 2-of-3 multisig; 8% ZCG and 12% deferred-lockbox streams continue to height 4,406,400.

Official links

Categories

Related coins

Frequently asked questions

Is every Zcash payment private?

No. Transparent receivers remain public, and shielded privacy also depends on wallet support, counterparties, network metadata and movements between pools.

What changed from Sprout to Sapling and Orchard?

Sprout and Sapling used separate multi-party setups. Sapling improved proving and key handling; Orchard introduced Halo 2 without a new Orchard trusted setup.

What happened to Orchard in 2026?

A soundness flaw was reported on 29 May. Orchard Actions were temporarily blocked, and NU6.2 activated a corrected circuit at height 3,364,600 on 3 June. ZIP 257 documents this completed response.

Is Orchard still the current receiving pool?

No. Since NU6.3 on 28 July 2026, new shielded value enters Ironwood. Orchard can be spent down but cannot receive new value.

Does Ironwood make Zcash quantum-safe?

No. Its note format is designed so a future recovery protocol could recover Ironwood notes after a discrete-log break. That recovery protocol is not live, and Sprout, Sapling and old Orchard notes do not gain this property.

Who controls Zcash?

ECC, Zcash Foundation, ZCG, developers, miners and node operators have different roles. Network changes require software and operator adoption; holding ZEC is not a formal vote over consensus.

What happened to the development-fund streams?

NU6.1 moved 78,750 ZEC from the old lockbox to a 2-of-3 multisig held by Zcash Foundation, ECC and Shielded Labs. It also continued 8% of subsidy for ZCG and 12% for the deferred lockbox through height 4,406,400.

What legal rights does ZEC provide?

ZEC can be mined, held, transferred and used for fees. The reviewed protocol materials do not establish that holding ZEC alone grants equity, a fixed-value redemption claim, a share of protocol revenue, or a general governance vote; separate contracts and legal rights are outside that evidence.

External trackers

Choose a tracking site for Zcash: