Ironwood update for users

Hi folks! We wrote this to explain the basics of Ironwood: When, What, Why, and “Do I need to take any action?”. (Answer: no, you do not need to take any action.) Please share with users that you know. Feedback welcome. Thanks! :slight_smile:

What Is Ironwood?

Ironwood is a Zcash network upgrade designed to restore every user’s ability to independently verify the soundness of Zcash’s circulating supply. It is scheduled to activate as NU6.3 at block height 3,428,143, approximately July 28 at 12:00 p.m. UTC.

Ironwood was developed in response to a critical counterfeiting vulnerability discovered by Shielded Labs security researcher Taylor Hornby in Zcash’s Orchard shielded pool. The vulnerability was fixed through an emergency network upgrade led by the Zcash Open Development Lab (ZODL), and we believe it is unlikely to have been exploited. However, because Orchard’s transaction data is shielded, users cannot independently verify that no counterfeit ZEC was created before the vulnerability was fixed.

Ironwood solves this problem by creating a new shielded pool using the corrected Orchard circuit and sealing the original Orchard pool. After Ironwood activates, users will no longer be able to send or receive ZEC inside the Orchard pool. Funds will only be able to leave through Zcash’s existing turnstile, which prevents more ZEC from exiting the pool than legitimately entered it.

As a result, if any counterfeit ZEC exists, it will be unable to continue circulating within Orchard or be moved into another pool. Users will not need to wait for funds to migrate, determine whether the vulnerability was exploited, or trust anyone else’s assessment. By running a node, they will be able to verify for themselves that no more than the correct amount of ZEC can be circulating.

Ironwood is also being supported by additional security analysis, including independent audits, AI-assisted security research, and formal verification.

Why Ironwood Matters

  • Ironwood retires the Orchard pool. It seals the original pool and replaces it with a new pool using the corrected Orchard circuit.
  • Ironwood prevents hypothetical counterfeit value from increasing Zcash’s circulating supply. Funds can leave the original pool only through the turnstile, which prevents more ZEC from exiting than legitimately entered.
  • Ironwood restores independently verifiable soundness. Regardless of whether the vulnerability was ever exploited, anyone running a node can verify that Zcash’s supply limits are being enforced.

What Users Should Expect

Users do not need to take any action, but temporary service interruptions are possible during two separate upgrades.

The first is the migration from zcashd to the new Z3 stack built around Zebra, Zaino, and Zallet. The current target for this transition is July 18. The second is the Ironwood (NU6.3) network upgrade, which is expected to activate on July 28.

Exchanges, wallets, or other service providers that are not fully prepared for either transition may temporarily suspend deposits, withdrawals, or other services. If this happens, don’t panic. It does not mean user funds are at risk or that there is a problem with the security of Zcash or the Ironwood upgrade. It most likely means the affected service provider is still completing or troubleshooting its upgrade. Users should contact their service provider and ask when it plans to support the new Zcash infrastructure and Ironwood.

Wallet users should also be aware that Orchard funds will eventually need to be migrated to Ironwood. Until your wallet supports this migration, your Orchard funds may be temporarily unavailable. Wallet developers are actively implementing migration support, and some may offer privacy-preserving migration options that avoid revealing your balance during the process. Check with your wallet provider for details about their migration plan before moving your funds.

Additional Resources

Built Through Collaboration

Ironwood is the result of an extraordinary collaborative effort completed on a very tight timeline. Project Tachyon, Valar Group, ZODL, the Zcash Foundation, and Shielded Labs worked together to discover and remediate the vulnerability, design and review the solution, and prepare the ecosystem for activation.

The speed and care with which these teams responded demonstrate the strength of Zcash’s independent development community. Ironwood would not have been possible without their shared commitment to protecting Zcash users and the integrity of the network.

Special thanks to Project Tachyon, Valar Group, and ZODL for helping define Ironwood’s architecture, implementing the new consensus rules, and carrying out the critically important formal verification work. We also thank the Zcash Foundation for implementing Ironwood in Zebra and supporting the ecosystem-wide transition from zcashd to Zebra.

We also posted this on the Shielded Labs web site.
I also tweeted and blueskied.

18 Likes

Since how private the migration is depends on the wallet, what can a non technical holder check, or ask their provider, to know theirs is the balance hiding kind?

3 Likes

Oh man, this is a great question, and you deserve a good answer, but I don’t know exactly what the right answer is yet, and it’s ultimately between you and your wallet provider.

I think the main question you should ask your wallet provider is “Will my IP address be exposed and linked to my balance?”.

We think it is possible to prevent that linkage by leveraging Tor or Nym to prevent your IP address from being linked to your balance, but it requires a lot of engineering on the part of wallet makers, and it’ll probably require some iterations to work out the kinks.

So I think my second bit of advice to you as a user is, be patient and give your wallet provider time to work out the kinks and wait until they tell you that it is safe before moving your funds.

Shielded Labs has been helping wallet builders with this. If you’re a wallet builder, please check your Signal messages from us.

5 Likes

That’s really cool; I didn’t know it was possible to link an IP address to a wallet transaction. I’m curious about that topic, but I won’t ask so I don’t stray from the post’s main point.

@zooko Would it be more interesting to transfer the balance from one wallet to a different one, or to use the wallet’s own migration mechanism?

1 Like

If you had visibility over the network you potentially could and why it is suggested to use a vpn, such as the built-in arti tor option in zkool (just turn it on). Different wallets will likely have different levels of migration-tool enforcement so in some cases you may just have to sit back and let do its thing, but doing it manually is what everyone would otherwise have to do and it’s perfectly fine. I’m assuming the migration tool(s) will split up funds into at least three different transactions of some random amounts in order to disconnect any quantitative input amounts that went into the pool from the output.

4 Likes

There is only Ironwood.

4 Likes

The wallet’s own migration mechanism.

Once Ironwood activates (July 28!), you won’t be able to send any transactions from your Orchard funds without thereby exposing the amount of ZEC in the transaction. My advice for what to do at that point:

  1. Don’t rush. There’s no hurry.
  2. Find out what the maker of your wallet — the one that contains your Orchard funds — recommends. Zodl has already posted images of what the migration UI will look like, and said to stay tuned for instructions: Zcash Open Development Lab on X: "Stay tuned for simple Zodl wallet migration details coming soon: https://t.co/ZSCALVOlhW" / X
  3. If your wallet doesn’t yet have such a UI or such recommendations, then just wait until they do. :slight_smile:
2 Likes

Thanks for putting this together in a way that is understandable for users. I’m part of the Gem Wallet team, where we currently support transparent ZEC.

For wallets that currently support transparent ZEC only, is confirming NU6.3 compatibility the main preparation users should look for, or is there any additional guidance you would recommend that wallet providers communicate before Ironwood activates?

Hello @zooko, I’m thinking of taking advantage of the Ironwood migration to switch wallets (using a new wallet with new seed phrases) to get better organized. After the 28th, will it be possible to manually transfer funds to an Ironwood key in a different wallet? If I move all the funds to a single Ironwood key, will everyone be able to see the amount of ZEC I hold in that transaction, or would the transaction remain shielded? Will this manual migration reveal my public keys and the amount? What are the risks of performing the migration manually for the purpose of switching wallets? Do I run the risk of being intercepted by a hacker or having my data exposed?

Waiting for your own wallet’s migration flow makes sense over guessing. Does migrating alongside a lot of other people change how well that one exposed amount blends in, or is timing beside the point once Orchard funds have to move anyway?

What wallet do you have your Orchard funds in currently? The makers of that wallet may be able to give more specific answers to these questions.

Yes.

It will not reveal your public keys or addresses.

Everyone will be able to see the amount of all funds that leave the Orchard pool. This is by design, so that everyone can verify how much ZEC leaves the Orchard pool.

And your server/endpoint/lightwalletd sees your IP address that you are connecting from when you make that transaction, which means that server will be able to link your IP address with the amount of your Orchard funds. Unless you use a network-layer privacy tool such as Nym, or unless your current wallet has Tor or Nym built in and you configure it to turn that on.

Some risks:

  • Risk: Scammers tricking you into thinking they are support personnel and stealing your funds. Scammers do this all the time, and I saw reports today that they have started specifically posing as support personnel for the Ironwood migration. To defend against this risk:
    • Take your time. There’s no hurry.
    • Do not reply to or click links from anyone who reached out to you. You only talk about your wallet with people when you reached out to them, never the other way around. And only reach out to the correct support contact for your wallet.
    • No legitimate support personnel will ever ask you for your seed words or ask you to enter your seed words into anything. (Anything other than the restore-from-seed-words functionality of your wallet.) Anyone who does is a scammer. The only reason to ask for your seed words, or to ask you to enter your seed words into anything else, is to steal your money.
  • Risk: You uninstalling or deleting your old wallet and then finding out that you didn’t save the seed words where you thought you did, or they were written down wrong so that they don’t work when you try to enter them again, or something. To defend against this risk:
    • If you’re depending on seed word backup, then test that by restoring from the seed words in a new wallet, in order to be sure that you really can do it and it works, before deleting the old wallet.
  • Risk: The server/endpoint/lightwalletd finds out both your IP address and the amount of ZEC that you migrated out of Orchard. To defend against this risk:
    • Install Nym and turn it on now and leave it on. It’ll be protecting your IP address from getting leaked, both to the Zcash server/endpoint/lightwalletd, and for all your other internet traffic, as soon as you turn it on.
    • Ask the maker of your wallet if they’ll provide an update with built-in migrate functionality (like Zodl has already described) or otherwise how they advise you to do it safely.
2 Likes

That’s a good question. The most important thing is preventing your IP address from being leaked to the server/endpoint/lightwalletd, like I was just describing to Lord of the Pings in the previous post. (Use Nym.)

Beyond that, use a built-in migration function if your wallet offers one, and yeah, it helps if you start your migration process at the same time as other users, but (surprisingly!) it doesn’t need to be “everyone at once”. As long as there are at least a few other users who are migrating at the same time as you, and as long as you’re using network-layer protection such as Nym, then nobody will be able to tell exactly how much ZEC any individual user migrated. Observers will basically only be able to tell the total amount of ZEC that migrated (from all users) during that time period. If that makes sense. If not ask me again. :rofl:

1 Like

Hm, the risks I described in my previous reply weren’t specific to your plan to send the migration transaction manually. I guess the specific risks of that one are:

  • Risk: You accidentally send to the wrong address. To defend against this:
    • Send a small test amount first.
  • Risk: Your server/endpoint/lightwalletd can see the exact amount migrated out of Orchard in that transaction, and link it to your IP address. To defend against this:
    • Use Nym, or use any built-in Nym or Tor support in your wallet.
  • Risk: Observers can see the exact amount migrated out of Orchard in that transaction.

In other words, you are not getting the benefit of that property that I described in my previous reply to ZKZeek. The good property is observers can only tell the total amount of ZEC that migrated in a given time period, rather than being able to tell that different wallets had different exact amounts. If you send your migration transaction manually, then observers will be able to tell that some wallet had exactly that amount of ZEC in Orchard.

There are two ways this could be potentially harmful to you. The first is, if you’re not using Nym, then the server/endpoint/lightwalletd finds out both the exact amount of ZEC that you had in Orchard and also finds out your IP address.

The second is, what if, even if you hide your IP address, someone just knowing your exact Orchard balance all by itself reveals something about you?! I never thought of this one before Dev Ojha from Valar Group explained it to me, when we were designing the Ironwood upgrade. I wrote it down. See Appendix D, below.

So to recap, the second risk was:

  • Risk: Observers can see the exact amount migrated out of Orchard in that transaction, and potentially link that to your IP address. To defend against this risk:
    • Use Nym, or turn on any built-in Nym or Tor integration in your wallet.
    • Use your wallet’s built-in migration process instead of sending migration transactions manually.

Appendix D: A Motivating Story

Suppose a Zcash user initially received ZEC in only two transactions. They withdrew USD 1000 worth (2.18250071 ZEC) from a Know-Your-Customer (KYC) compliant exchange, which is required by its government to take a copy of their photo ID and home address. Kidnappers stole a copy of their photo ID and home address. (This part is unfortunately not hypothetical—it happens all the time.) So now the kidnappers know who the user is and where they live and that they have 2.18250071 ZEC.

Then the user used a no-KYC exchange, to protect their privacy, while acquiring an additional USD 1 million worth (2,182.50070931 ZEC). The kidnappers observed that someone acquired USD 1 million worth of ZEC, but they have no information linking that transaction to the user whose KYC information they have.

Then the user performed a transaction which caused their wallet to combine their notes, such as sending 2.2 ZEC back through the no-KYC exchange for Bitcoin (and paying a 100 μZEC transaction fee). The kidnappers see that someone is now 2.2 ZEC poorer, but they have no information linking that to either the user’s KYC information or to the USD 1 million worth of ZEC. The user now has 2,182.48311002 ZEC in a single note in the Orchard pool.

Then the user is forced by the Ironwood upgrade to migrate their funds from Orchard to Ironwood if they want to use their funds. If they just send all of the 2,182.48311002 ZEC in one transaction, this will accidentally leak information to the kidnappers that the user has a million dollars worth of ZEC, thus exposing the user to the risk of being kidnapped!

The kidnappers can use a “subset sum” computation on the amounts that have been revealed, to infer that the same person whose KYC information they have must also be the person who acquired USD 1 million worth of ZEC and sold 2.2 ZEC.

Note that transactions that are invisible to the attacker quickly reduce the amount of information that the attacker can learn from learning a user’s balance. For example, if the user had sent some ZEC (of an amount unknown to the attacker) to the shielded address of a recipient which the attacker had not compromised, or had received ZEC to their own shielded address from a sender that the attacker had not compromised, then this would have changed the user’s remaining balance by a number unknown to the attacker. For example, if they had sent or received an amount, even if less than 100 ZEC, that was unknown and unguessable to the attacker, that would probably leave only two significant digits—the 2000 ZEC and the 100 ZEC—still containing information that could be recognized by the attacker. I.e., even if their entire balance was revealed to the attacker, he would probably only be able to use that information as if it said “2,1xx.xxxxxxxx ZEC”.

Thanks to Dev Ojha for telling us about this attack, which is in fact why we designed the Ironwood upgrade to allow wallets to make change-to-self inside the Orchard pool, thus enabling wallets to use algorithms like this one to protect their user.

5 Likes

No that makes sense. So as more of the network’s Orchard balance migrates out over time, the crowd migrating alongside you might get thinner too and waiting longer actually leaves less cover instead of more. Waiting too long, that could also give you less cover for privacy - which could be something to balance.

Yes, that’s true. But practically speaking, this part doesn’t matter very much.

The number one issue is network-layer privacy. If you don’t have it, i.e. if you’re just connecting to your endpoint/server/lightwalletd over unprotected IPv4, then the lightwalletd can see right through any of those other defenses anyway. Like, you can break up your migration amount into many smaller amounts and send them through over time, alongside a dozen other users who are doing the same thing the same day, and the lightwalletd knows exactly which ones are yours because it sees your IP address the whole time. So at the end, while doing all that did prevent “This specific balance existed in Orchard” from appearing on the permanent public blockchain, it did not prevent your lightwalletd from knowing that that specific balance existed in Orchard and furthermore from linking that specific balance to your IP address.

So for every user, the number one most important issue is having network-level privacy (i.e. Tor or Nym) before migrating.

That’s necessary and sufficient to prevent your lightwalletd (or anyone who spies on your network) from seeing your IP address linked to your Zcash balance. All the other defenses are of secondary importance, and none of the other defenses protect you at all from your lightwalletd (or from a spy on your network) unless you also have Tor or Nym working.

There are two ways to get Tor or Nym working to hide your IP address: either your wallet maker integrates it into your Zcash wallet, or you install it yourself and run it in your operating system.

So to circle back to your comment about having lots of other users migrating simultaneously as you, ZKZeek. Yes, that’s better, but it doesn’t really matter much. Even if there are zero other simultaneous migrators, and you have network-level privacy, then even if observers could guess that a certain balance got migrated, they probably couldn’t link it to anything else about you. If there are even one or two other people who migrate at the same time as you, if they use network-level privacy like Nym, then observers probably can’t deduce exactly what anyone’s starting balance was.

Lowo in the chat jumping in on @zooko point: the question to ask your wallet is basically “Will my IP get linked to my turnstile balance?”

Why Nym matters for Ironwood migration

Ironwood’s turnstile is public by design (so the supply stay checkable). That means the leftover risk is attribution: who can join that amount to you.

@LordOfThePings & @ZKZeek

If a wallet syncs and broadcasts migration txs over clearnet to a remote server, that server (or someone watching the path) can often see:

  • your IP, and
  • the public migration amount / timing,

and treat that as “this person moved this much.”

Nym is how native wallets can cut that link for network metadata:

  • mixnet for small sensitive submits (broadcast),
  • 2-hop dVPN for bulk compact sync,

per Harry/Mark’s guidance at zcash-sdk.nym.com.

Important: Nym is not a replacement for good wallet behavior. Transport hides IP from the destination; the wallet still has to avoid dumb timing/start-height fingerprints. That’s why we shipped baseline hygiene first.

What NozyWallet is doing

We’re actively building this stack for Orchard → Ironwood:

  1. Baseline hygiene shipped (defaults on): start-height obfuscation, randomized migrate-broadcast delay, tip-sync guard so we don’t broadcast the second we catch tip.
    Details: What NozyWallet just shipped (baseline hygiene)

  2. Nym transport in progress: mixnet path for remote submit (IP relocate proven), dVPN compact-sync spike live against public LWD after Mark’s current SDK pins. Local Zebrad users already get a strong IP cut for submit without needing Nym day-to-day.

  3. Desktop coming soon: we’re wiring this into the desktop so migration privacy isn’t “compile the spike yourself.” We’ll say when it’s ready to use an please don’t rush funds until your wallet (ours included) tells you it’s safe, same advice Zooko gave.

If you run your own node, keep using it. If you depend on remote lightwalletd / remote broadcast, ask for Nym or Tor + hygiene, not just “we support Ironwood.”

Happy for feedback an especially if wallets should converge on shared hygiene defaults.

— NozyWallet / LEONINE-DAO

3 Likes

Great to see @zooko bring up the important question of network privacy during the Ironwood upgrade. Also, for all those not lucky enough to use NozyWallet or that can’t wait to Zingo to upgrade, we’ve made NymVPN free during the Ironwood update, so you can just run your wallet at same time as NymVPN to protect your Ironwood migrations. See here for instructions: Free NymVPN for Zcash's Ironwood migration | Nym

We’re also working with Shielded Labs to build a Nym mixnet-enabled zainod instance, but not sure when will that will launch.

7 Likes