Hello Zcash community,
We’ve submitted a grant application to ZCG for adding Ironwood shielded transaction support to the ELLIPAL TITAN air-gapped hardware wallet. Posting here for community input and feedback.
Full application
What we’re building
ELLIPAL is an air-gapped hardware wallet manufacturer. Our TITAN device uses QR codes as its sole communication channel — no USB, no Bluetooth, no NFC. The device remains physically isolated from all networks at all times.
We currently support Zcash transparent transactions (T-addresses). This grant ($95,000, ~9 months, 4 milestones) will add full Ironwood shielded transaction support:
- Shielding (T → Ironwood), deshielding (Ironwood → T), and fully shielded (Ironwood → Ironwood) transactions
- PCZT-based signing via QR codes — spending keys never leave the air-gapped device
- Clear Signing: full transaction details (recipient, amount, fee, Memo) displayed on TITAN screen before physical confirmation
- Companion app integration: UFVK import, lightwalletd/Zaino sync, balance display, Memo support
Why this matters
Air-gapped hardware support for Ironwood shielded signing is still in its early stages across the ecosystem. ELLIPAL TITAN serves hundreds of thousands of self-custody users worldwide who chose air-gapped security — users with strong security awareness and a natural demand for privacy. They are an ideal audience for Zcash’s shielded pool, but currently cannot access Ironwood features.
Adding another hardware wallet to the Zcash shielded ecosystem reduces dependency on any single device and brings Ironwood to a user base that prioritizes the highest level of physical isolation.
Milestone overview
- M1 (Oct 2026, $65,000): Core Ironwood hardware signing — Pallas/Vesta curves, ZIP-32 key derivation, PCZT parsing, Clear Signing, all three transaction types on TITAN firmware
- M2 (Dec 2026, $20,000): ELLIPAL App integration — UFVK import, lightwalletd/Zaino sync, PCZT construction, proof generation, Memo, transaction history
- M3 (Feb 2027, $10,000): Security hardening, external audit cooperation (Least Authority, coordinated by ZCG), regression testing, public documentation
- M4 (Mar 2027, $0): Production release — multi-model compatibility, App Store release, user documentation
Open-source commitment
All Zcash-related firmware code (Ironwood key derivation, PCZT parser, Clear Signing logic) will be publicly released under an open-source license. Test vectors and regression results will be shared with the community. We’ll post monthly progress updates in this thread.
Technical collaboration request
Beyond funding, we’re requesting guidance from the Zcash core team and community on:
- librustzcash integration best practices for air-gapped PCZT-via-QR scenarios
- PCZT specification edge cases and upcoming format changes
- Recommended lightwalletd/Zaino endpoints for initial integration
- Reference test vectors for implementation correctness verification
What we’d value feedback on
1. Are there specific PCZT edge cases or payload-size concerns the community has encountered that we should prioritize in our QR transmission testing?
2. Any preferences on which lightwalletd/Zaino infrastructure to target for initial integration?
3. Suggestions for the Clear Signing UX — what transaction details are most important to display on a small hardware screen?
Happy to answer any questions. Thank you for your time.