But evidence points away from exploitation, a CoinDesk Research report found in July. If someone had minted counterfeit ZEC, the obvious next step would be to move it out and sell it, which would show up as funds leaving the pool. However, Orchard’s balance grew steadily through the four years the flaw was open, including through last year’s price rally, when cashing out would have been most profitable.
Developers patched the bug within days, but the patch could not account for the four years it was open. A zero-knowledge proof reveals nothing beyond the facts that it verified, so the chain holds no record of whether any Orchard transaction actually moved, and nobody can prove counterfeit coins were never created.
The turnstile is an answer to that. Money crossing into or out of a shielded pool is public even when the transactions inside are not, so the network already knows how much ZEC went into Orchard and will not release more than that. Any counterfeit coins sitting inside are stuck there.
As of press time, 1,500 ZEC have already moved into the new pool, according to a tracker.
Ironwood also launched with two protections Orchard never had. The record each coin leaves on the chain is built to stay recoverable if quantum computers eventually break the cryptography now securing it, a property specified under ZIP 2005 and in place from the first block.
















