How does turnstile defense against counterfeiting work

To be more precise, the consensus rule prevents the Sprout or Sapling pool values from going negative. The transaction that would have caused it to go negative may still be in nodes’ mempools, but will never be mined.

A rational attacker would probably try to avoid tanking the price before they could cash out their forged coins, so they would probably not transfer all the forged coins at once. In any case it’s correct that the maximum impact on supply is limited by the pool value (for each of Sprout and Sapling).

Just as a reminder, we have no reason to believe that there has been any forgery. This is a precaution to limit the maximum impact on supply of any potential forgery in the shielded pools.

5 Likes