Ironwood: Verifying the Soundness of Zcash’s Circulating Supply

@fivelittleducks Pretty sure that everything I’ve written in this thread specifically does treat the possibility of exploitation having occurred as contingent.

I guess one unknown for me is whether the ironwood proposal necessarily does put a hard cap on the qty of migrate-able ZEC in place. That’s what I’m reading between the lines in @zooko’s post (how else is there a hard and immediate guarantee of total ZEC quantity?) and I am arguing against that if it’s the case because if you gate the migration a priori, then you are creating arbitrary winners and losers a priori and in a situation like this one, that seems ethically wrong to me.

1 Like

a priori

Ethical considerations notwithstanding, a posteriori is definitely in play here and should be the default. Conclusions made strictly from evidence and observation are called for, and no conclusions can be drawn without taking action which forces the exposure of theoretical counterfeit ZEC in the absence of an alternative supply verification solution. While arbitrary winners and losers may emerge, no definitive outcome is observable without forcing the issue.

I’m actively looking for errors in this logic. Help me find some.

1 Like

I didn’t read the rest of the message after this. If these are the two interpretations you can see, then I guess we’re not going be able to help each other understand things better.

If you really didn’t read it, I think you should. You might want to at least read the next sentence which starts with “I also don’t know what I don’t know and am curious what that is…” which is meant to acknowledge that there could be other interpretations that I can’t see.

1 Like

Yeah, you had good points there but you wrote emotionally the first bit and now it’s standing in the way of your intended outcome. Done that way too many times myself, it’s a worthwhile lesson!

@zooko I read the message and I come from a similar background. The TLDR is that we seem to be handwaving the possibility of an exploit - if it was the case that infinite genuine looking ZEC has been minted there seems to be only 2 possible things to do: rush to exit the pool (100% for those that make it, -100% for everyone else) or ratio the loss against the whole pool (if a big enough issuance happened, effective -100% for everyone).

Above is his point. Mine may be a bit more… dramatic I think. I’m looking at this with a binary outcome. I think any confirmed additional coins >0 would be long term irreparable.

3 Likes

This is also what confused me a bit about why Orchard V2 (aka Ironwood) was effectively any different from the status quo, outside of the obvious formal verification, and any other improvements/findings that come with it. Maybe not allowing trade in the old pool is what differentiates it, but doesn’t seem as important if no services take orchard V1 notes (you’d be silly to if V2 existed).

I totally agree with the upgrade regardless, but feels like we learn nothing new about the exploit, unless it was actually exploited and the attacker beats everyone out of the pool - so I guess this forces their hand…that’s good for everyone sooner than later.

1 Like

Hope Zooko will still read it, though he’s rightful to feel attacked. I read it and felt a little burn there too. Zooko had good intentions and chooses his words wisely, but maybe don’t come overly clearly in written form. Would love to listen to a longer form podcast on this exact debate/subject!

2 Likes

I believe this vulnerability hasn’t been exploited. I believe it’s a very difficult vulnerability to exploit, and a hacker would focus on projects with very high values instead of Zcash, which hasn’t yet reached a value as high as Bitcoin. Speaking for myself, if I was scared and wanted to migrate pools as quickly as possible, imagine how other, newer users feel? In my view, it will be a real race to switch pools. Furthermore, if it’s proven that the vulnerability was exploited, many users will lose confidence in the project, while many others will be desperate if they can’t migrate pools in time to avoid losing their Zcash. There’s also the issue of fees, which can become expensive when many people decide to switch pools at the same time. There could be a maximum fee limit to avoid penalizing those who want to migrate pools, preferably a free fee only for migration so as not to penalize anyone in this process.

1 Like

An equitable solution would be to lift the 21M unit ZEC for the conversion from Orchard to Ironwood.

1 Like

There’s a lot of good questions in this thread. Please see our latest post attempting to clarify those questions and ask (I guess in reply to that post) any more questions you have.

3 Likes

Lovely thread. I will not move my coins from orchard as long as the new pool is ready :slight_smile:

2 Likes

That is the behaviour specified in ZIP 209, yes. It’s specified that way because it’s the only thing that is feasibly implementable in the consensus rules.

1 Like

Will this migration happen in a simplified way within the wallet itself, or will it be necessary to transfer the ZEC manually?

That’s up to the wallet! In my humble opinion, this is the sort of thing that the wallet ought to do automatically for the user, but on the other hand maybe some users prefer manual control.

Vizor Wallet and ValarGroup have already demonstrated the automated method on an Ironwood testnet!

2 Likes

First, Thank you to everyone carrying the Ironwood work. The cross org effort across Shielded Labs, the Zcash Foundation, Valar, and ZODL has moved fast since the Orchard disclosure on June 5, and the community feels it.

The last detailed activity on the main Ironwood thread was around June 12 (I think). With a late July activation target and a stated height of 3,417,100, the next few weeks matter a lot. People still holding in the Orchard pool are watching closely and trying to plan around the Turnstile migration. Could we get a short status update on where things stand?

A quick read on the Ironwood circuit and ZIP 2005 review, where formal verification and the external audits sit, whether late July still looks realistic and what the current gating items are, and how wallet and exchange readiness is shaping up for migration day would help the whole community prepare.

Nothing polished needed. Even a few lines would be appreciated and if there is a newer update somewhere that I missed, please point me to it. Thank you again for the work.

@zooko @earthrise @aquietinvestor @ZcashFoundation

4 Likes

I think this is an important step for the ecosystem.

One of the strongest aspects of blockchain is that users should be able to verify, not simply trust. Restoring independent verification of the circulating supply helps strengthen confidence in Zcash and its long-term future.

Looking forward to seeing Ironwood move forward.

1 Like

This is a really interesting initiative.

One of the biggest strengths of blockchain is verifiability, and having independent tools to verify the circulating supply adds another layer of confidence to the ecosystem.

Looking forward to seeing how Ironwood develops.

1 Like

Thanks for asking—yeah we should give people an update! The thing is, there are many different teams working on Ironwood (Shielded Labs, Zcash Open Development Labs, Tachyon Project, Zcash Foundation, and Valar Group). I’ll let the other orgs describe their own work. From what I’ve seen they are working super hard, long hours, and making good progress.

At Shielded Labs our focus has been security, and in particular our new project, which we are calling Zero, of supporting enterprise users (e.g. mining pools, exchanges, and wallets). Our current focus within the Zero project is to help them prepare to safely make the transition to Ironwood.

As far as the security side, it is going well. We’ve been hunting for bugs using a variety of techniques and finding no new serious bugs. That’s encouraging! We’ll post more details about that work as soon as we can.

8 Likes

I’ll add a bit more detail to what Zooko shared.

First off, thanks for the question. I can’t speak for the other teams, but I can share how we’re thinking about it at Shielded Labs. There are two major efforts happening in parallel, and it’s helpful to separate them because they’re often discussed together. The first is the Ironwood (NU6.3) upgrade. The second is the migration from zcashd to the new Z3 stack built around Zebra, Zaino, and Zallet. The current goal is to complete both efforts by late July.

With regard to Ironwood, the teams at Project Tachyon, Valar Group, ZODL, the Zcash Foundation, and Shielded Labs have been working hard and have made significant progress over the past several weeks. Development is moving forward on schedule, and testnet activation of the new consensus rules is expected shortly. Work is also continuing on formal verification of the new circuit, with the goal of completing a proof of soundness before Ironwood activates.

Development of Z3 is also making progress. The challenge is that key pieces of the new stack, specifically Zallet and Zaino, are still under development and aren’t yet ready for production use, which leaves mining pools, exchanges, and other infrastructure partners with limited time to deploy and test everything before Ironwood activates.

ZODL and the Zcash Foundation have been leading outreach efforts to help mining pools and exchanges prepare for the migration. At Shielded Labs, we’ve also been speaking directly with partners to understand how we can best support the transition.

The consistent feedback we’ve received is that completing both the Ironwood upgrade and the migration to Z3 on the current timeline will be challenging. That seems consistent with a questionnaire Pacu recently circulated, where most did not respond and those who did provided mixed responses, with some indicating they’ll be ready while others said they need additional time.

From Shielded Labs’ perspective, our primary concern is security. We’d prefer to see the Ironwood implementation and the components of the Z3 stack undergo independent third-party security audits once development is complete, before recommending that infrastructure providers deploy them in production.

For that reason, we believe it’s worth considering a few options that could reduce deployment risk:

  • Delay Ironwood activation to give infrastructure partners more time to complete the transition to the Z3 stack.
  • Use the additional time to complete independent third-party security audits of the production software before deployment.
  • Alternatively, decouple the Ironwood upgrade from the Z3 migration by providing temporary Ironwood-compatible zcashd support. As I mentioned on the most recent Arborist call, Shielded Labs is currently working on providing this option for partners who need additional time.
  • We’ve also asked @earthrise to conduct a risk assessment of the strategy of requiring the ecosystem to migrate from zcashd to the new Zebra-based stack on the current timeline. We plan to share a version with the core developers this week and may also publish a version for the community.

Ultimately, we all share the same goal to activate Ironwood as quickly as possible while making sure our partners can safely migrate away from zcashd. We think the focus over the coming weeks should be on making that transition as smooth and secure as possible.

15 Likes

We cannot tolerate any delays, users demand Ironwood immediately, after the public messaging scare accentuated by @zooko at Shielded Labs. But good news, it brought the ecosystem people together to ship something far better in record time! I believe was Zooko’s intention? Good work!

Yet you are posting in here, bike shedding on vague or imaginary blockers.

There are TWO implementations completed by ZFdn and Valar, going into testnet tomorrow. Contrary to your misinformation, these clients include functional Zallet code.

Audits are already underway (which obviously will gate release, this is the purpose of an audit and does not need to be caveated).

Your vague “feedback about readiness” lacks any detail whatsoever such that it is useless as a decision making factor. You cite a survey from @pacu without any source. How are we to know who he surveyed? Is it public anywhere? Do any of the survey participants matter for the critical upgrade path?

Whoever is not ready that is actually critical to upgrading the network (basically the prime mining pools), needs to be made ready, and if you or anyone else lack the skills to make them ready then then they need to be replaced by someone who is able to make them ready.

Zcash is THE leading chain of 2025-2026 (and beyond!) and does not need to bend the knee any longer. If Solana can manage 3 day network upgrades across their much larger ecosystem, then Zcash not even managing monthly upgrades is just excuses.

Shielded Labs is welcome to participate in the upgrade, but permission is not required to run NU6.3, and it will happen with or without you.

4 Likes