Zcash Launches Ironwood Pool to Fix Critical Orchard Vulnerability
Zcash has activated the Ironwood shielded pool to replace Orchard, which contained a vulnerability that could create fake ZEC. The new pool enforces withdrawal controls to prevent unauthorized minting.
The Zcash team has released Ironwood, a new shielded transaction pool designed to replace Orchard after a critical vulnerability was disclosed in May. The flaw allowed the potential creation of counterfeit ZEC without detection, exploiting the privacy-preserving design that hides transaction amounts.
Although no exploitation of the bug has been observed, the nature of shielded pools makes it cryptographically impossible to prove that no fake coins were minted. To eliminate this risk, Ironwood enforces a boundary check: all withdrawals from Orchard must pass through the Ironwood pool, which verifies that the amount leaving does not exceed the total legitimate deposits.
Users do not need to move funds manually; simply updating their wallet software to the latest version will migrate to the new pool. The protocol-level safeguard ensures that any excess ZEC created via the vulnerability cannot be withdrawn, according to the team.
Source: ForkLog