Neon shield design with geometric patterns
Crypto

Zcash researchers publish machine-checked Ironwood proof targeting supply integrity

Project Tachyon said the Lean verification includes 2,700+ theorems and focuses on “balance integrity” after the Orchard flaw.

By AI News Crypto Editorial Team4 min read

Zcash researchers published a machine-checked formal verification of Ironwood designed to rule out undetectable counterfeiting bugs under stated cryptographic assumptions. The work targets “balance integrity,” a supply-integrity property meant to ensure the new shielded pool cannot pay out more value than has publicly entered it.

Key Takeaways

  • A machine-checked formal verification for Zcash’s Ironwood shielded pool was published to address undetectable counterfeiting risk under stated cryptographic assumptions.
  • Project Tachyon described the proof as “written in the Lean programming language” and comprising “more than 2,700 machine-checked theorems,” produced by three teams over more than a month.
  • The verified security target is “balance integrity,” intended to ensure Ironwood cannot pay out more value than has publicly entered the pool.
  • Ironwood shipped via the NU6.3 upgrade after a disclosed Orchard vulnerability that could theoretically enable undetectable ZEC counterfeiting, with developers stating they “found no evidence that the flaw had been exploited.”

Ironwood Gets a Machine-Checked “Balance Integrity” Proof

Zcash researchers have completed and published a machine-checked proof for Ironwood, the network’s newer shielded pool. The stated objective is narrow but market-relevant: rule out undetectable counterfeiting bugs along the specific path that would break supply integrity, assuming the cryptographic model holds.

Project Tachyon said the verification was produced in Lean and spans more than 2,700 machine-checked theorems, with three teams of researchers and cryptographers working for over a month. For traders, the headline is not the tooling. It is the property being proven. “Balance integrity” is the direct answer to the inflation fear that lingers any time a shielded pool is suspected of being able to mint value invisibly.

What the Proof Covers—and What It Explicitly Doesn’t

The proof is scoped to the components required to establish balance integrity: Ironwood’s zero-knowledge proof system, its circuit rules, and ledger-level accounting. That matters because it targets the accounting invariant that would have to fail for undetectable inflation to occur.

The researchers also drew a hard boundary around what is not being claimed. The formal verification does not cover Ironwood’s separate privacy guarantees. That distinction is important for positioning. This publication is best read as a supply-integrity assurance, not a blanket statement that every shielded-pool property has been formally verified.

Like any formal proof, it is conditional. The guarantee is “under its stated cryptographic assumptions,” which means the market still has to care about what those assumptions are and whether the threat model matches real-world adversaries.

From Orchard’s Theoretical Counterfeiting Risk to NU6.3’s Ironwood Rollout

Ironwood arrived through Zcash’s NU6.3 upgrade after a vulnerability was discovered in the prior Orchard shielded pool. The disclosed risk was severe in kind, even if theoretical in practice: undetectable ZEC counterfeiting. Developers said they found no evidence the flaw had been exploited.

That “no evidence” line is not the same as a proof of non-exploitation, and traders know the difference. The point of Ironwood, and now the formal balance-integrity verification, is to reduce the supply-integrity overhang by moving the system onto a design with a machine-checked argument that the shielded pool cannot pay out more than has publicly entered.

Turnstile Migration: The Public Checkpoint That Can’t Import Hypothetical Excess Coins

Migration from Orchard to Ironwood is forced through a public accounting checkpoint called a “turnstile.” The design goal is clean-room isolation: even if Orchard had hypothetical excess coins, the checkpoint is intended to prevent those coins from entering Ironwood.

That mechanism also sets up the next stream of evidence. As funds leave Orchard, the turnstile process could surface discrepancies consistent with Orchard-era exploitation, if any existed. Traders should watch for developer or Project Tachyon updates on migration totals and whether the checkpoint indicates anything abnormal.

The other watch item is scope creep in the right direction: clarifications on the cryptographic assumptions and threat model behind the balance-integrity proof, plus any follow-on audits or proof extensions. Finally, wallet and exchange support that accelerates user migration from Orchard to Ironwood would increase the amount of observable data the turnstile can generate over time.

How Traders Should Frame the Remaining Orchard Overhang

The threshold that matters is whether the market can separate two risks that often get bundled together: Ironwood’s ability to inflate going forward versus the unresolved question of whether Orchard was ever exploited. The new proof is aimed squarely at the first category by formally establishing balance integrity under stated assumptions.

I treat the remaining overhang as an evidence problem, not a vibes problem. If the turnstile migration continues without discrepancies and support ramps across wallets and exchanges, the setup starts to look structural rather than narrative-driven, because the market gets a cleaner pool and a growing public trail that is hard to square with hidden inflation.

Sources