Search

Search for projects by name or address

ZK Catalog

Zcash Orchard logo
Zcash OrchardElectric Coin Company

About

Orchard is the shielded protocol of the Zcash PoW blockchain, with its latest pool called Ironwood. Its circuit is proven with Halo 2, a PLONKish proof system with a transparent IPA commitment over the Pasta curves, and verified by every Zcash full node.


  • Total Value SecuredTVS
    No data

  • Trusted Setups

    Verifiers

    N/A

    Verifiers

    N/A

    Tech Stack

    zkVM
    Halo2
    IPA
    Pallas
    Vesta
    App-specific circuits
  • Total Value SecuredTVS
    No data
  • About

    Orchard is the shielded protocol of the Zcash PoW blockchain, with its latest pool called Ironwood. Its circuit is proven with Halo 2, a PLONKish proof system with a transparent IPA commitment over the Pasta curves, and verified by every Zcash full node.


    Description

    Orchard is the shielded protocol of Zcash, activated with NU5 in May 2022. Every shielded spend and output is an Action whose validity is proven with Halo 2, a PLONKish proof systemThe infrastructure that allows projects to verify their state transitions. It is composed by onchain verifiers and offchain provers. The main two flavors are optimistic and ZK proof systems, but they can be combined in a hybrid model. In general though, if a system is able to accept state roots optimistically, even if it has a ZK component, it is considered an optimistic proof system. developed by the Electric Coin Company. HaloThe first recursive proof composition without a trusted setup. A proof verifies the correctness of another instance of itself, meaning that the latest mathematical output (one single proof) contains within it a proof that all prior claims to the relevant secret knowledge have themselves been sufficiently proven through a similar process. It allows any amount of computational effort and data to produce a short proof that can be checked quickly. 2 uses an inner product argument (IPA) polynomial commitmentA commitment scheme that commits to a polynomial and allows generating the proof of opening the polynomial at a given point against the commitment. over the Pasta curve cycle instead of a pairing-based commitment, so the Orchard circuitA program written for the purpose of being proven within a proving system. A circuit is a mathematical representation of the computation to be executed, arithmetic circuits and zkVM execution trace are examples of circuits. Circuits can be written in different languages, ranging from low-level to high-level. needs no trusted setupGeneration of a piece of data that must then be used for some cryptographic protocol to run. Generating this data requires some secret information. The "trust" comes from the fact the secret must be destroyed after the ceremony, otherwise cryptographic properties of the protocol could be broken. Once the data is generated, and the secrets are forgotten, no further participation from the creators of the ceremony is required. There are two types of trusted setups for SNARKs: (i) trusted setup per circuit where it is generated from scratch for each circuit, (ii) trusted universal setup per proving system where it can be used for several circuits.. The older Sprout and Sapling pools use Groth16A zk-SNARK proving system introduced by Groth in 2016 that proves arithmetic circuits and requires a separate trusted setup for each circuit. It allows extremely efficient proof verification. with parameters from multi-party ceremonies.

    Proofs are verified by every Zcash full nodeA software client that participates in the network. as part of its consensusAn agreement on the latest and correct state of a blockchain. Unlike L1 blockchains which coordinate participating nodes with consensus rules, rollups rely on L1s for reaching consensus by checking the state of the rollup smart contract deployed thereon. and there currently is no verifying smart contract light node or trust-minimized bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. on Ethereum.

    Proof system

    The Orchard Action circuit proves, for one spent note and one new note, that the spent note exists in the note commitment tree, that its nullifier is derived correctly, that the spender holds the spend authority, and that the value commitments balance. It is implemented with the halo2_gadgets library over 2^11 rows, using custom gates and lookup arguments for Sinsemilla hashes, Poseidon and elliptic curve arithmetic.

    Following ZIP 224, Orchard uses the Pasta curve cycle: Pallas is the application curve on which keys, commitments and RedPallas signatures are defined, and Vesta is the circuit curve whose scalar field (the base field of Pallas) is the native word type of the circuit. Polynomial commitments and the IPA opening proof are Vesta points. Verifying an IPA proof takes time linear in the circuit size. An Orchard transaction bundles all of its Actions into a single Halo 2 proof. The bundle also carries the RedPallas spend authorization and binding signatures.

    Verification

    Nodes such as zebra and zcashd derive the verifying key deterministically from the circuit description at startup, so unlike Sapling there are no proving or verifying parameters to download and trust. Because the circuit has changed twice, nodes keep three verifying keys and select one by blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. height: the original NU5 circuit for historical blocks, the fixed circuit from NU6.2, and the NU6.3 circuit that additionally enforces the cross-address restriction.

    Circuit history

    On 2026-05-29 a soundness bug was reported in the variable-base scalar multiplication gadget of halo2_gadgets: a missing copy constraint left the multiplication base under-constrained, which would have allowed creating counterfeit ZEC inside the Orchard pool. Orchard was disabled by an emergency soft fork at Mainnet block 3363426 and re-enabled with the corrected circuit at the NU6.2 activation, block 3364600, as documented in ZIP 257. The fix shipped in halo2_gadgets 0.5.0 and orchard 0.14.0.

    NU6.3 (Mainnet block 3428143, 2026-07-28) created the Ironwood pool, which uses the Orchard protocol with quantum-recoverable notes, and restricted the legacy Orchard pool to same-address transfers so that value migrates to Ironwood. Both pools are proven with the same NU6.3 Action circuit and the same Halo 2 proving system.

    NU6.3 creates the Ironwood pool

    2026 Jul 28th

    Mainnet blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. 3428143 activates NU6.3, which opens the Ironwood pool with quantum-recoverable notes (ZIP 2005) and restricts the legacy Orchard pool to same-address transfers. Both pools use the Orchard Action circuitA program written for the purpose of being proven within a proving system. A circuit is a mathematical representation of the computation to be executed, arithmetic circuits and zkVM execution trace are examples of circuits. Circuits can be written in different languages, ranging from low-level to high-level..

    Learn more

    [Disclosed vulnerability] Orchard Action circuit soundness bug

    2026 Jun 3rd

    A missing copy constraint in the halo2_gadgets variable-base scalar multiplication left the Orchard Action circuitA program written for the purpose of being proven within a proving system. A circuit is a mathematical representation of the computation to be executed, arithmetic circuits and zkVM execution trace are examples of circuits. Circuits can be written in different languages, ranging from low-level to high-level. under-constrained, allowing counterfeiting inside the pool. Orchard was disabled by an emergency soft fork at blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. 3363426 (2026-06-02) and re-enabled with a fixed circuit at NU6.2, block 3364600.

    Learn more

    Transparent setup

    Halo2

    Detailed description

    Transparent proving systems require no trusted setups and have no additional setup-related trust assumptions.

    List of different onchain verifiers for this proving system. Unique ID distinguishes different deployments of the same verifier from different verifiers (e.g. different versions).