I love what #Starknet and other zk-based assets like #COTI, and #Midnight are doing for private “programmable“ infrastructure, and making privacy more injectable into peripheral blockchain solutions and protocols. My personal investment plan, these days, is more centered around accumulating scarce assets wrapped in privacy. That’s the best SOV (Store of Value) to accumulate for generational wealth. #Zcash has one very simple purpose: Scarcity value with ZERO KNOWLEDGE. $ZEC is as transportable and as spendable as any other digital asset with the bonus of complete #privacy.
Just buy the bottom and you’re golden. Your investment in yourself over the next 5-10 years will increase your quality of life immensely. BUY BOTTOMS!
🛡️💰💰💰💰🛡️
The @Zcash bug leads to Ironwood, formal verification of the Orchard payment circuit. I love and support it.
I also want to stress that @Starknet has been doing that -- formal verification -- for over 5 years.
It's important to support great projects like Zcash for reacting quickly, as in this case.
It’s also important to recognize projects that are future-proof and ahead of the curve, like Starknet. (Details in the article below)
I’ve said often that Starknet is that system which already has the stuff other chains claim they soon will. It's been true for many things.
We've been at the vanguard of many unpopular choices that now everyone recognizes are important, including post-quantum secure ZK-STARKs as the best scaling and privacy solution, lean zkVMs (Cairo is best), Validium data availability, and formal verification.
Formal verification means that you use automated tools like the Lean system to mathematically prove that your code is safe.
It's very hard to capture each and every aspect of what it means for code to be safe, but led by our CTO @LiorGoldberg2 (co-creator of Cairo zkVM and language), we've been at it for more than 5 years.
The very first paper on formal verification of claims related to ZK (Professor Jeremy Avigad, Yoav Seginer, and others) showed that the set of polynomial constraints defining the Cairo VM is correct.
If you've been following the news lately, the bug that was recently discovered by AI and now fixed for Zcash (another project I co-founded, and which I'm very proud of and support) had to do with a missing constraint.
The decision to verify their code to rule out other such bugs is the right step. Running this kind of verification for the Cairo core VM provided us, the StarkWare team, with mathematical certainty that there is no missing constraint in our Cairo VM.
So, in addition to proving the core VM of Cairo, we have also proved the S-two STARK system, part of the compiler, and many of the functions in the standard Cairo library.
Is the job done? No. There are a lot of other things that can be proven formally . But we are committed to continuing to formally prove all the core properties that have to do with the soundness and safety of our systems. It's great to see other projects embracing formal verification as an important tool. I'm proud that StarkWare led the path in this aspect too. That’s what Future Proof blockchain means to us.
Want to learn more?
Here's a detailed account of our Lean proving efforts over the past few years
Ironwood gives every Zcash holder a trustless guarantee of supply integrity.
Formally verified circuit. Independent audits. Turnstile-bounded.
Target: late July 2026.
The Zcash core teams turned a patched soundness bug into the strongest answer in crypto.
.@mert on Zcash's future:
"The next upgrade is a formally verified, quantum-proof and more scalable shielded pool in Tachyon.
One of the most bullish possible network upgrades I've seen in the history of crypto."
Zcash is unstoppable private money.
Mert says the Zcash situation was a known trade-off amplified by a wrong narrative and a perfect storm of timing:
"Known ZK trade-off, not an exploit. Not vibe-coded with AI. World-class auditor explicitly tasked to find bugs found one. Bitcoin and Monero have similar issues."
"Network upgrade locked Binance deposits during the biggest market selloff since April 2025. Zcash couldn't dump with the market. Unlocked into it as the only coin still up. Mass hysteria. Kept piling on."
tl;dr
not only will upgrade ironwood let you verify the supply is in tact
more importantly, it will be formally verified! so the same class of bugs mathematically will not exist again and reduce risk by orders of magnitude
I have ironwood from hearing this
BREAKING: Introducing Ironwood, a new shielded pool for Zcash, backed by formal verification and independent audits, proposed by Zcash's core dev teams. Target activation: late July 2026.
.@mert:
"All of crypto needs to start doing formal verification, simpler arithmetic, and open source. That's fundamentally how we get out of this."
@TachyonZcash is built for exactly that: it's provably sound, quantum proof, and is coming by end of year.
Really excited to audit the Orchard pool's supply with a very elegant and wonderful approach @ShieldedLabs suggested. More about that later today.
But it's funny that the whole time we're fixing it I'm going be paying bills etc. with my Orchard funds! I love it. 😆
someone make a polymarket on whether they think the zcash bug was exploited so we can see who actually believes it vs baiting engagement
you will be able to definitely prove whether it was or not with the next network upgrade so oracle for it exists
There's a lot of confusion about the recently patched Zcash bug. Here's how to actually understand it.
If the bug had been exploited before the patch (very unlikely it was), it would have looked like the shielded pool getting drained. Whoever minted the counterfeit shielded ZEC would want to sell fast, before anyone else found the same bug. And remember, the market for ZEC is almost entirely transparent ZEC, not shielded. You can't dump freshly minted shielded ZEC on Binance or Coinbase without unshielding it first.
The losers in that scenario are shielded holders who sit still. The transparent portion of Zcash is fully visible, so it's trivial to enforce that transparent ZEC never exceeds max supply. If you try to unshield more than the cap, you'll get stopped at the door.
So if you hold transparent ZEC (anyone trading, on an exchange, or doing price discovery on ZEC) there's no marginal effect on you. The loss falls entirely on shielded holders.
The team's next step is a new turnstile and a fresh shielded pool in the coming upgrade, which will confirm the shielded pool was not inflated. Think of it as taking headcount at the end of the field trip--that will make sure no extra kids snuck onto the bus.
But while AI found this bug, AI will also deliver the fix for the whole category: formal verification. I'm very bullish on this as the path to harden all software across the industry. Formally verified cryptography can't have implementation bugs by construction.
Right now AI is surfacing vulnerabilities across all our software--browsers, OSes, and blockchains are no exception. We're in the awkward adolescence where every wart is getting magnified and put on full display. But formally verified software is the only path forward for mission-critical software, and Zcash has put it front and center on their roadmap to deliver.
Privacy is too important not to.
(Dragonfly holds $ZEC and continues to. I'm personally an investor in ZODL.)
There is very strong evidence there wasn't any exploit, the supposed attacker would have had to:
1. Out-audit every Zcash core security contributor combined.
2. Sit on counterfeit ZEC through a massive bull run instead of cashing out.
3. Then still not cash out even after hearing the proposal to replace the Orchard pool and force all coins through the turnstile.
Meanwhile the shielded pool is not budging.
Market is down, everyone is unhappy. But has anything materially changed?
No.
Exit taxes. Asset seizures dressed as wealth taxes. Rising authoritarianism. Infinite fiat inflation. Capital controls. Surveillance states.
Those are all coming soon if not already happening.
The thesis is intact.
Bitcoin can't help here: it's fully transparent and has no roadmap to tackle quantum attacks. Dalio won't touch it because "all transactions are public", making it a non-starter for central banks.
Gold can't help here either: it's physical, cumbersome and easy to seize. Try crossing a border with it or sending it to someone online.
What's left?
Zcash.
🚨Confirmation of a massive potential ZEC exploit
TLDR:
- ZCASH hired a security researcher to try to find exploit vectors
- The researcher (Taylor Hornby) found one that would let him create unlimited counterfeit ZEC in a shielded pool
- The exploit is now fixed as of June 1
- There is no way to know if the pool was exploited BUT the team feels that it is unlikely
- They're proposing a network upgrade with new accounting that would prove whether any counterfeit ZEC was created or not
Market clearly spooked with ZEC down 25%
Read the chart for yourself. #Zcash finally joined the rest of the nose-diving crypto market after Hype dumped. Read the trend, Fib, volume profile, and price support ranges. I see nothing but accumulation opportunities. That's always been my play. #ZODL and #DCA is your safest play. Track the Daily/Weekly charts to know where the best opportunities are to load up on your future #private Wealth. If you felt like you missed out on this last run, your next accumulation chances are coming. You've already been shown that this asset is a true performer. $400s, $360s, $300s will be great buying opportunites.
🛡️ⓩ $ZEC ⓩ🛡️
🚨 BREAKING
SATOSHI ERA WHALE JUST DUMPED $350,000,000.00 $BTC AFTER 16 YEARS OF HODLING.
HE SURVIVED THE MT. GOX HACK, COVID CRASH, LUNA & FTX COLLAPSES, BUT SOLD ALL HIS BITCOIN TODAY.
LOOKS LIKE HE KNOWS EVEN MORE BAD NEWS IS COMING SOON...
"Decentralized digital money that is private by design is good for the world" @BarrySilbert
Tune in to hear the thesis behind our long-term conviction in Zcash zcash:native and why we are doubling down on financial privacy in the latest ep from @NetworkMedici
https://t.co/JcDxZstjMv