Zcash researchers have completed a formal verification effort for Ironwood, the network's new shielded pool, publishing a machine-checked proof that the system cannot be exploited to counterfeit ZEC without detection. The findings were published by Project Tachyon on its blog at tachyon.z.cash.

The proof, written in the Lean programming language, comprises more than 2,700 individual theorems. Three separate research teams and cryptographers worked on the effort, which took over a month to complete.

Mathematical equations are written on a white page.
Photo by Bozhin Karaivanov on Unsplash

What the proof actually covers

The verification establishes what researchers call "balance integrity" — a guarantee that Ironwood's shielded pool can never distribute more value than has been publicly deposited into it. The scope of the proof spans Ironwood's zero-knowledge proof system, its circuit rules, and its ledger-level accounting. Notably, the team excluded privacy guarantees from this particular verification pass, meaning the proof speaks to counterfeiting resistance rather than transaction confidentiality.

Why Ironwood exists

Ironwood was introduced as part of Zcash's NU6.3 upgrade, built specifically as a response to a vulnerability discovered in the older Orchard shielded pool. That flaw could, in theory, have allowed an attacker to counterfeit ZEC without leaving any detectable trace. Developers have said they found no evidence the bug was ever actually exploited in practice.

The turnstile mechanism

To manage the transition away from the potentially vulnerable pool, funds moving from Orchard into Ironwood must pass through what the team calls a "turnstile" — a public accounting checkpoint designed to catch any hypothetical excess coins before they could enter the new, formally verified system. Over time, the turnstile's accounting is also expected to provide additional evidence on whether the Orchard flaw was ever exploited historically.

The completion of the Ironwood proof marks one of the more extensive formal verification efforts undertaken in the privacy-coin space, reflecting a broader trend of blockchain projects turning to machine-checked mathematics rather than audits alone to back up security claims about shielded or zero-knowledge systems.