The Zcash Shielded Pool Is Sealed. 3.5M ZEC Are Still Inside.

Zcash sealed the Orchard shielded pool after a four year counterfeiting bug. Only about 5% of 3.5M ZEC has crossed into Ironwood so far.

Jan Kara News

Zcash locked its main privacy vault on Tuesday. At block 3,428,143 the Orchard shielded pool stopped taking deposits, and a replacement called Ironwood opened with a balance of zero. About 176,000 ZEC crossed over on day one, roughly $81 million, according to CoinDesk. Crypto Times counted more than 182,000 ZEC by Wednesday. Both numbers land near the same place: something like 5% of the old shielded pool has moved, and the other 95% sits behind a gate that only opens one way.

The trigger for all of this was a bug that nobody can prove was ever used. That sentence is the whole story, and understanding why it can stand at all means understanding how supply works on a chain built to hide it.

Zcash runs four pools, and only one of them is public

Most people picture Zcash as a single anonymous coin. The reality is layered. Coins live either in transparent addresses, which behave like Bitcoin and show balances to anyone, or inside one of several shielded pools. A shielded pool encrypts amounts, senders and receivers, then validates the transaction with zero knowledge proofs.

Each pool is its own cryptographic system with its own note format. Sprout came first in 2016. Sapling replaced it in 2018 and made shielded transactions light enough for phones. Orchard arrived in May 2022. Ironwood opened this week.

The split matters more than the branding. Roughly 12.5 million ZEC sit in transparent addresses, per Crypto Times, against about 3.5 million in Orchard and 581,380 in Sapling. Bitquery puts total supply near 16.75 million against a 21 million cap.

PoolLive sinceBalanceStatus
Transparent2016~12.5M ZECPublic balances
Sprout2016MinimalLegacy, exit only
Sapling2018~581,380 ZECActive
OrchardMay 2022~3.5M ZECSealed, exit only
IronwoodJuly 28, 2026~182,000 ZECOpen

One design choice makes any of this auditable. Individual shielded notes stay private, but every pool publishes a running total of value that has entered minus value that has left. Zcash calls it the chain value pool balance. You cannot see who holds what. You can see how much the pool is supposed to contain.

A flaw in the Orchard circuit sat there for four years

On May 29, 2026, Taylor Hornby of Shielded Labs reported a defect in the zero knowledge proof circuit behind Orchard. Decrypt reports he worked with an AI model, Claude Opus 4.8, while probing the code. The flaw had shipped with Orchard in 2022 and survived four years of review.

What it allowed, in theory, was a forged proof. Someone could have created a shielded note out of nothing and spent it as real ZEC, with no visible trace at the moment of creation. Developers patched it under emergency conditions in early June through NU6.2.

Then came the awkward part. Because Orchard hides amounts by design, no auditor could rule out that the trick had already been pulled. The market did what markets do with an unfalsifiable claim. ZEC dropped 38% on the disclosure, wiping roughly $2.5 billion off its market value, per Decrypt. The coin had been one of the year's strongest performers before that, and Coinliva covered the rally that took it up 136% in a month back in May.

How you check a hidden supply from the outside

You cannot open a shielded pool and count. What you can do is watch the doors.

Bitquery pulled Zcash's full history and cross checked it against a block explorer and the emission schedule. Their reasoning is simple. Counterfeit coins that never leave a shielded pool do no damage and produce no evidence. Counterfeit coins that get cashed out have to pass through a public exit into transparent addresses, and that shows up as a drain in the pool balance.

Their findings: total supply tracking the emission schedule with no excess, shielded pool balances near an all time high set in April 2026 rather than drained, and unremarkable flows during the window when the bug was exploitable. Between May 28 and June 2, the Orchard pool gained about 11,000 ZEC. Normal daily variation runs near 25,000 ZEC, and single days routinely move 200,000.

Bitquery was blunt about the limits. Fake coins sitting unspent stay invisible forever. A small theft spread across several days, or buried under larger honest inflows, would disappear into the noise. The evidence points one direction. It does not close the question.

The turnstile caps the exit at what went in

Ironwood is a clean restart. New note commitment tree, new nullifier set, new value pool, and a machine checked correctness proof written in Lean that crypto.news describes as more than 2,700 theorems built by three teams over roughly a month. It also ships ZIP 2005 quantum recoverable notes from block one, aimed at the same long horizon exposure that leaves 34% of Bitcoin's supply with an exposed public key.

Orchard, now a closed shielded pool, runs in exit only mode, and everything leaving it passes a turnstile. The rule is an accounting cap: the total that walks out can never exceed the total that verifiably walked in. Any counterfeit value stays locked behind the gate.

Read that rule twice, because it does not do what a casual scan suggests. The turnstile cannot tell a forged note from a real one. It only counts. If forged value exists inside Orchard, the cap gets reached before the last honest holders reach the door, and the shortfall lands on whoever is still queued. That converts an invisible risk into an ordinary race to get funds out, with the difference that nobody has announced a starting gun.

Migration is voluntary and no deadline exists. Wallets and exchanges are still shipping support, with Cake Wallet among the first. Zooko Wilcox, who founded Zcash, told users to run Tor or Nym before moving anything, since a wallet server can pair an IP address with a migration amount even when the chain cannot.

The pool numbers themselves come with a spread. CoinDesk put Orchard at 3.66 million ZEC worth about $1.7 billion at activation with ZEC near $463. BeInCrypto quoted 3.76 million ZEC and $1.89 billion at a price near $506, calling it 22% of circulating supply. Different snapshots, different price feeds, same order of magnitude. Crypto Times had ZEC at $462.85 on Wednesday with a market cap around $7.77 billion.

Frequently asked questions

Is my ZEC stuck if I leave it in Orchard? No deadline has been published. Funds can still exit through the turnstile, and old addresses keep working for withdrawals. Deposits are the thing that stopped. The practical risk is wallet support lagging rather than a hard cutoff.

Did anyone actually counterfeit ZEC? No evidence of it has surfaced. Supply tracks the emission schedule and the shielded pool was near a record high rather than drained. Proving a negative on an encrypted ledger is not possible, which is exactly why Ironwood exists.

What software do I need now? The old zcashd node no longer supports the current consensus rules after NU6.3. Zebra is the required implementation, and the Z3 stack became the standard for infrastructure operators.

Why not just fix Orchard instead of replacing it? A patch stops future forgery. It does nothing about coins that might already exist inside the pool. Sealing the pool and metering the exit is the only way to contain a supply question you cannot see.

Is there a reason to move early? If you believe counterfeit value exists, position in the queue matters. If you do not, the argument for waiting is that wallet tooling gets better and network level privacy gets easier. Both readings are defensible from the same data.

Watch the Orchard balance rather than the price. If it drains steadily toward zero over the coming months and the turnstile never binds, the counterfeiting question closes itself with arithmetic instead of assurances. If outflows stall well short of 3.5 million ZEC, the reason for the stall becomes the next story.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.
Jan Kara
Author

Jan Kara

Jan Kara is the founder and Editor-in-Chief of Coinliva. His coverage focuses on the macro crypto landscape, including regulatory developments, institutional adoption, and structural shifts shaping the digital asset industry. He tracks how policy decisions, ETF flows, and corporate treasury moves connect to broader market dynamics, drawing on primary regulatory filings, official statements, and on-chain data.