Key Takeaways
- Ironwood (NU6.3) seals Zcash’s old Orchard pool at block 3,428,143 on July 28.
- Taylor Hornby’s May bug find pushed ZEC lower before it stabilized above $500.
- Sean Bowe and Dev Ojha’s Zakura node syncs Zcash 5 times faster than Zebra.
The Ironwood hard fork, known as NU6.3, activates around July 28, 2026, at block height 3,428,143. It closes a soundness flaw in the Orchard shielded pool and opens a new pool built on corrected code. Alongside it, a fast new node called Zakura is already live, giving operators a faster way to run the network.
A Bug Nobody Could See
Security researcher Taylor Hornby, working with Shielded Labs, found the flaw in late May 2026. The bug sat inside Orchard’s cryptographic circuits. In theory, it lets someone mint counterfeit ZEC inside the shielded pool without leaving a trace. Zcash’s privacy design, the same feature that protects users, also blocks outside observers from checking whether anyone has exploited it.
Developers moved fast. A soft fork shut down the Orchard pool temporarily. A hard fork, NU6.2, patched the immediate danger. ZEC’s price dropped sharply on the news before recovering part of its losses. The episode tested a core Zcash promise: that privacy and provable scarcity can coexist.
How Ironwood Locks the Old Pool
Once Ironwood activates, the legacy Orchard pool stops accepting new deposits or internal transfers. Existing coins in the old pool still work, but only if they move through a new checkpoint called a turnstile on their way to the new Ironwood pool.
The turnstile enforces a simple rule. Outflows from the old pool cannot exceed the coins that legitimately went in. That means the total circulating ZEC supply becomes verifiable the moment Ironwood turns on, without waiting for every user to migrate.
Two outcomes are possible if counterfeit coins existed. If no excess supply tries to leave the old pool, that stands as strong evidence that nothing was exploited. If excess supply does appear, the turnstile blocks it from leaving, and the extra coins get destroyed, giving the public proof of what happened.
Project Tachyon is running formal verification on the new Ironwood circuits, producing machine-checked proofs rather than relying only on manual code review.
What Users Need to Do
Node operators must upgrade before block 3,428,143 hits, expected around 8 a.m. EST on July 28. Wallet providers tied to the Zcash Open Development Lab are adding prompts to guide shielded fund migration. Users holding transparent balances or funds outside the old Orchard pool do not need to take action. The legacy zcashd node software is reaching end of life around the same window, pushing remaining users toward modern clients.
Zakura Enters the Race
Zakura 1.0.0 launched July 15, 2026, forked from the Zcash Foundation’s Zebra codebase. Sean Bowe, a Zcash cofounder and the cryptographic engineer leading Project Tachyon, built it with Dev Ojha, the Osmosis cofounder now leading Valar Group. Both projects are funded through private ZEC donations.
Zakura syncs the Zcash mainnet in about four hours and 20 minutes, compared to roughly 20 hours and 46 minutes for Zebra in the same test. Pruned snapshots let a new node bootstrap in under two minutes. A zcashd compatibility mode keeps older wallets and integrations working during the transition.
Bowe and Ojha say the long-term goal is Visa and Mastercard-level throughput, near 50,000 transactions per second, for private payments. Today’s shielded pool tops out near one transaction per second. Getting there depends on cryptography upgrades from Tachyon and Valar Group working alongside faster node software like Zakura.
The Zcash Foundation says it welcomes the new client, framing multiple independent node implementations as a safeguard against the kind of single point of failure that let the Orchard bug go unnoticed for as long as it did.
What This Means for Traders
For traders, the Ironwood fork works like a public audit with a deadline. The turnstile design means the market gets a clear signal within days, not months of speculation, about whether the May bug was ever exploited. That fast, verifiable answer matters for a privacy coin, where doubts about hidden supply can weigh on price longer than a typical bug disclosure.
Zakura adds a separate signal. Faster sync times and lower node costs make it easier for exchanges, miners, and block explorers to run independent infrastructure, which lowers the odds that a future bug slips through unnoticed, the way the Orchard flaw did.
ZEC has stabilized above $500 as the July 28 activation approaches, with developers, the Foundation, Shielded Labs, Project Tachyon, and Valar Group aligned around the same upgrade window.


