Zcash Explained: Ironwood Upgrade, ZEC Supply & Privacy

Datawallet Team
Last updated
July 13, 2026
This date marks a full audit, not a minor edit. Our editing team reviews every claim, figure, and platform detail in line with our editorial guidelines before republishing.
Fact checked
Editorially Verified
Editorial fact-check process

This article has been reviewed and verified for accuracy by our editorial team. All claims, data points and platform details are cross-referenced against primary sources.

Data accuracy verified
Sources cross-referenced
Platform details confirmed
View our fact-checking process
Disclaimer
Affiliate Disclosure
How Datawallet is funded

Some links on this page are affiliate links. Datawallet may earn a commission when you sign up through them, at no extra cost to you. This never influences our editorial ratings, rankings or recommendations.

Read our full disclosure

Summary: Zcash is a proof-of-work blockchain that uses zero-knowledge cryptography to hide the sender, receiver, and amount of a transaction while keeping a Bitcoin-style 21 million supply cap.

Its ZEC coin became the largest privacy asset by market cap after a rally that carried it from around $50 to a peak near $737.

The network is now days away from Ironwood, a July 28 upgrade that replaces the Orchard shielded pool after a counterfeiting bug was found and patched in early June.

Site
Zcash (ZEC) Overview
4.5
/5
Our Rating
Our rating is an editorial verdict from hands-on testing of fees, security, liquidity, and features. It is not a paid placement. See our Editorial Methodology for the full framework.

Zcash is the largest privacy coin, using zk-SNARKs to encrypt transactions on a Bitcoin-style 21 million supply, with the Ironwood upgrade restoring verifiable supply integrity.

Max Supply
21,000,000 ZEC, over 80% issued
Privacy Tech
zk-SNARK shielded pools via Halo 2
Next Upgrade
Ironwood (NU6.3), activating July 28
We may receive a commission when you make a transaction through our links, at no extra cost to you.

What is Zcash?

Zcash is a Layer 1 blockchain launched in October 2016 by cryptographer Zooko Wilcox and the team now known as Electric Coin Co. It began as a fork of the Bitcoin codebase and kept its monetary design, including the hard cap of 21 million coins, then added the ability to encrypt transaction details with zero-knowledge proofs.

Every Zcash user chooses between two address types. Transparent addresses behave like Bitcoin addresses, where amounts and counterparties are visible to anyone. Shielded addresses encrypt the sender, receiver, and value, and a holder can hand over a viewing key when they want to show their own history to an auditor, tax office, or exchange.

That optional design kept ZEC listed on regulated exchanges through years of pressure on privacy coins, and it explains why institutions treat Zcash differently from Monero.

The SEC closed a near two-year investigation into the Zcash Foundation in January without enforcement action, and Grayscale has filed to convert its Zcash Trust into what would be the first US spot ETF for a privacy coin. The CLARITY Act debate has added further momentum by separating compliant privacy tools from illegal mixing services.

ZEC trades near $500 with roughly 16.8 million coins issued, meaning more than 80% of the maximum supply already exists. Around 30% of circulating ZEC now sits in shielded pools, up from about 8% two years earlier, a sign that private usage is growing alongside speculation.

How Does Zcash Work?

Zcash runs Bitcoin-style proof-of-work consensus underneath an encrypted transaction layer.

1. Transparent and Shielded Transactions

A transparent Zcash transaction publishes the same data Bitcoin does, so anyone can trace it on a block explorer. A shielded transaction replaces that public record with an encrypted note and a mathematical proof that the transaction obeys the rules, which hides who paid whom and how much.

Users can also mix the two. Shielding moves coins from a transparent address into a private pool, deshielding moves them back out, and fully shielded transfers keep every detail hidden. Wallets such as Zashi, built by Electric Coin Co, now default to shielded transfers so privacy needs no manual setup.

Selective disclosure is the compliance bridge. A shielded user can generate a viewing key that reveals their own transactions to a chosen party without exposing anyone else on the network, which is why custodians and regulated platforms can support ZEC.

2. zk-SNARKs and the Halo 2 Proving System

Zcash was the first cryptocurrency to deploy zk-SNARKs, short for zero-knowledge succinct non-interactive arguments of knowledge. A zk-SNARK lets a sender prove a statement such as "I own these coins and have not spent them" without revealing the coins, the balance, or the addresses involved.

Early versions of this cryptography required a trusted setup, a one-off ceremony that generated secret parameters which had to be destroyed. The Halo 2 proving system, developed by Electric Coin Co and activated with the NU5 upgrade in May 2022, removed that requirement, and the same mathematics now underpins zero-knowledge projects beyond Zcash.

3. Shielded Pools and the Turnstile

Zcash privacy has shipped in generations, each running as its own shielded pool. Sprout was the 2016 original, Sapling followed in 2018 with far faster proofs, and Orchard launched in May 2022 as the first pool built on Halo 2 with no trusted setup.

A consensus rule called the turnstile connects these pools to the public ledger. It tracks how much ZEC enters and leaves each pool, and blocks any withdrawal that would exceed what legitimately went in. That lets anyone verify that the total ZEC supply matches the issuance schedule even though balances inside the pools are hidden, and it proved decisive during the June security incident.

4. Mining, Nodes, and Governance

Zcash is mined with the Equihash proof-of-work algorithm on 75-second blocks, which release the same aggregate issuance as Bitcoin over each four-year period despite the faster pace. Research under the Crosslink project is exploring a hybrid design that would add proof-of-stake finality on top of mining, though any change of that scale would need community approval, per Messari's protocol overview.

Protocol changes move through Zcash Improvement Proposals (ZIPs), public specifications debated across Electric Coin Co, the Zcash Foundation, Shielded Labs, and independent grant recipients. The node software is mid-transition, with the legacy zcashd client reaching end of support and the ecosystem migrating to the Z3 stack, which bundles the Zebra full node, the Zaino indexer, and the Zallet wallet.

Zcash Exploit Explained

On May 29, security researcher Taylor Hornby, contracted by Shielded Labs to audit the protocol, discovered a critical soundness flaw in the Orchard pool's zero-knowledge circuit. Using an auditing framework built around Anthropic's Claude Opus 4.8 model, Hornby produced a working exploit that minted unlimited counterfeit ZEC in a local test environment, per CoinDesk's coverage of the disclosure.

The bug sat in the halo2_gadgets code that performs an elliptic curve multiplication check inside the Orchard circuit. A missing constraint meant the circuit never bound a witnessed value to the correct base point, so a skilled attacker could have forged proofs and spent coins that did not exist. BlockSec's technical analysis notes the flaw had been live since Orchard activated in May 2022, surviving four years of expert review and multiple audits.

The response was fast. Developers coordinated privately with miners and exchanges, shipped an emergency soft fork on June 2 that temporarily disabled Orchard transactions, then activated the NU6.2 hard fork on June 3 at block 3,364,600 with a corrected circuit. Transparent and Sapling transactions ran normally throughout, and no user funds were stolen.

Markets still punished the uncertainty. ZEC fell roughly 50% within 48 hours of public disclosure, sliding from about $603 to $299, because Orchard's privacy makes it cryptographically impossible to prove the bug was never exploited during its four-year window. The turnstile capped the theoretical damage at insolvency inside the Orchard pool, since counterfeit coins could never have inflated the total supply, but the network needed a way to settle the question permanently. That answer is Ironwood.

Zcash Exploit Explained

Zcash Ironwood Upgrade Explained

Ironwood, shipping as network upgrade NU6.3, activates at block 3,428,143, expected around July 28 after a one-week delay to give exchanges, mining pools, and wallets more preparation time, per confirmation from core developer Sean Bowe. It is the most consequential upgrade in Zcash's history because it turns an unprovable question about supply integrity into a verifiable one.

The main changes Ironwood introduces are the following:

  • New shielded pool: A fresh pool launches on the patched Orchard circuit under a proposal from the Zcash Open Development Lab, hardened with independent security audits and an ongoing formal verification effort intended to mathematically prove the counterfeiting class of bug cannot recur.
  • Orchard sealed: The legacy Orchard pool stops accepting new deposits and internal transfers, so any hypothetical counterfeit notes created through the bug can no longer circulate.
  • Turnstile checkpoint: Funds can only exit Orchard through the turnstile into the new pool or a transparent address, forcing any counterfeiter to either surface fake coins at the accounting boundary or abandon them permanently.
  • Supply verification: Once migration completes, anyone running a full node can total the balances across active pools and confirm the circulating supply matches the issuance schedule without trusting developer assurances.
  • Quantum-recoverable notes: ZIP 2005 updates note formats to support fund recovery in a future quantum computing scenario, groundwork for a later post-quantum transition.
  • Software migration: The upgrade lands alongside the shift from zcashd to the Z3 stack, so node operators must move to Zebra or another updated client before activation or fall off the canonical chain.

Wallets will prompt users to migrate shielded funds out of the old Orchard pool, typically with a single approval, and exchanges are expected to pause ZEC deposits and withdrawals briefly around the activation block.

Zcash Tokenomics & Supply

ZEC copies Bitcoin's monetary skeleton and changes almost nothing about it. The supply is capped at 21 million coins, issuance halves roughly every four years, and there was no premine or token sale, only a brief slow-start mining period at launch in 2016.

Key figures from the official network documentation and issuance schedule:

  • Maximum supply: 21,000,000 ZEC, with roughly 16.8 million already issued, putting the network past the 80% emission milestone.
  • Block reward: 1.5625 ZEC per 75-second block following the second halving in November 2024, down from 3.125 ZEC.
  • Third halving: Scheduled for late 2028, when the subsidy drops to 0.78125 ZEC per block and annual inflation compresses further.
  • Miner share: 80% of each block subsidy goes to miners who secure the network with Equihash proof-of-work hardware.
  • Community grants: 8% funds Zcash Community Grants, which pays independent teams building wallets, infrastructure, and ecosystem tools.
  • Lockbox: 12% accrues to an in-protocol reserve created by NU6, now governed under NU6.1 as a coinholder-controlled fund that ZEC holders can direct toward grants or leave untouched until the third halving.

The original Founders' Reward sent 20% of early block rewards to insiders and investors, a direct dev fund replaced it from 2020, and the NU6 model stripped Electric Coin Co and the Zcash Foundation out of the protocol in favour of the lockbox and grants split.

Supply dynamics also shape trading behaviour. With about 30% of ZEC held in shielded pools and further supply parked in the Grayscale trust and corporate treasuries such as Winklevoss-backed Cypherpunk Technologies, the liquid float is thin, which amplifies moves in both directions. Futures open interest recently climbed past $1 billion ahead of Ironwood, and our ZEC liquidation heatmap tracks where leveraged positions cluster.

Zcash Tokenomics & Supply

Zcash vs Monero: Best Private Money

Zcash and Monero answer the same question with opposite designs. Monero makes privacy mandatory, hiding sender, receiver, and amount on every transaction through ring signatures and stealth addresses, while Zcash makes privacy optional and mathematically stronger inside its shielded pools.

Feature
Zcash (ZEC)
Monero (XMR)
Privacy model
Optional shielded transactions
Mandatory on every transaction
Cryptography
zk-SNARKs via Halo 2
Ring signatures, RingCT, FCMP++ in testing
Supply
Fixed 21 million cap
No cap, 0.6 XMR per block tail emission
Compliance path
Viewing keys and selective disclosure
None by design
Exchange access
Listed on major regulated platforms
Widely delisted, traded peer to peer
Institutional products
Grayscale trust, spot ETF filing
None

Monero's mandatory model means every user strengthens the anonymity pool, whereas Zcash's shielded set is only as strong as the share of people who opt in, and analytics firm Arkham has claimed it can label a majority of Zcash's transparent activity. Monero's design also carries the cost of exile, since dozens of exchanges have delisted XMR and holders increasingly rely on no-KYC platforms and decentralised venues.

Our view is that the two serve different owners. Monero remains the purer digital cash for users who prize censorship resistance above access, while Zcash is the private store of value that can live inside regulated portfolios, ETF wrappers, and corporate treasuries. Rising shielded adoption, now covering roughly 30% of supply, is steadily closing Zcash's anonymity gap. Both feature in our ranking of the best privacy coins.

Zcash vs Monero: Best Private Money

Is Zcash Safe?

Zcash's core cryptography has held up for nearly a decade, the turnstile protected total supply even during the worst plausible reading of the Orchard bug, and the June incident showed the ecosystem can coordinate an emergency fix within days. Formal verification work and new security hires at Shielded Labs aim to prevent a repeat.

The caveat is that privacy systems concentrate risk in their proving circuits, and a flaw there can hide for years precisely because the data is encrypted. Holders also face ordinary market risks, including a thin liquid float, heavy derivatives positioning, and regulatory regimes such as the EU's anti-money-laundering rules that could restrict privacy assets regionally. Treat ZEC as a volatile asset whose security story improves if Ironwood activates cleanly.

Final Thoughts

Zcash has spent a decade proving that encrypted money can coexist with public blockchains, and this cycle rewarded that work with institutional attention, a spot ETF filing, and the largest privacy coin market cap.

The Orchard exploit was the hardest test the network has faced, and the response arguably strengthened the investment case. A bug that survived four years of review was found by a defender first, patched within days, and answered with an upgrade that lets anyone verify the supply independently.

Ironwood's activation on July 28 is the near-term event to watch, followed by the NU7 roadmap covering shielded assets, Tachyon scaling, and the Crosslink proof-of-stake research. If those ship, Zcash's claim to be the private counterpart to Bitcoin gets harder to dismiss.

Zcash Explained: Ironwood Upgrade, ZEC Supply & Privacy

Table of Contents

Share this Post

Datawallet Crypto Newsletter

Get the market brief 100,000+ investors read

One email a weekData-driven & independentFree forever
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

No spam · Unsubscribe anytime