Zero
connecting · ironwood poolok
syncing anchor ok
verifying proofs · halo2valid
rooting assets into ZEC
Zcash · Orchard protocol · Ironwood pool

Zero

Launch assets into Zcash's shielded economy. Every asset is born with an Asset ID, proven with Halo 2 and rooted in a ZEC reserve.

ZEC rooted
—ZEC
Assets
—rooted
——
Bloom · innerRootSeed · outer
01ZCASHL1 · PoW
02ORCHARDprotocol · Ironwood
03ASSET ID—
04ZEC RESERVE—
05SHIELDED MARKET—
01 · ZSAs · Zcash Shielded Assets

The protocol underneath.

Custom assets on Zcash are specified in ZIP 226 and ZIP 227, and the circuit that carries them is being built in the official Orchard repo right now.

Zcash shielded pools · read from the chain

Where shielded ZEC lives today.

4,937,732 ZEC29.1% of supply, shielded

Ironwood went live on 28 July 2026 with NU6.3 at block 3,428,143. It runs the same Orchard protocol, now formally verified, after a flaw was found in the original pool's circuit in May. The original Orchard pool is closed to new deposits and funds leave it through a turnstile. The Orchard protocol, and PR #546 with it, carries Zcash's shielded future. Block 3,508,470.

Inside PR #546 · 37 files · +35,488 −2,109

What the ZSA circuit changes, file by file.

Notes, value commitments and the Action circuit are now parameterised by an asset type. A new ZSA circuit sits beside the current one, now called Vanilla internally. Each row links to the diff.

See the 14 files, line by line +
FileLinesWhat it doesIn the Orchard
src/note/asset_base.rsnew+82New AssetBase type: the point that says which asset a note holds.Asset ID + DNA on every card src/note.rs+140 −7Notes gain an asset field and rseed_split_note.Note stream: every note names its asset src/note/commitment.rs+58 −17NoteCommitment::derive now takes the asset.Commitment tree leaves (cmx) src/note/nullifier.rs+14 −3Nullifier::derive takes is_split_note, offset by a fixed point.Nullifier set + feed src/constants/nullifier_l.rsnew+44That fixed point, L, for split-note nullifiers.Nullifier set src/constants/zatoshi_asset_base.rsnew+49ZEC's own asset base: zatoshi is the native asset.The ZEC root src/value.rs+13 −4ValueCommitment::derive_with_asset binds value to an asset.Per-asset reserves in the root map src/circuit/value_commit_orchard.rsnew+391In-circuit value commitment with the asset as base point.Per-asset reserves src/circuit/note_commit.rs+1,120 −147Note commitment gadget evaluated per asset (zatoshi or not).Commitment tree src/circuit/circuit_zsa.rsnew+1,685The ZSA Action circuit, beside the current one (now "Vanilla").Proof monitor src/circuit_version.rsnew+61OrchardCircuitVersion: Vanilla or ZSA, each with its own proof size.Proof monitor · terminal zsa src/bundle.rs+89 −24A zsa_enabled flag in bundle Flags.Waits for NU7 src/builder.rs+39 −6split_flag on spends, asset on outputs. Still pinned to zatoshi for now.Genesis + launch src/circuit_data/circuit_description_zsanew+28,969The fixed description of the ZSA circuit: most of the PR's line count.Proof monitor
Spec ↔ code ↔ the Orchard

How our tech lines up with ZSAs.

Every part of the Orchard maps to a section of ZIP 226 or ZIP 227 and to the code in zcash/orchard.

On this siteToday on pump.funWith NU7
Asset IdentifierZIP 227 · AssetId := (issuer, assetDescHash)
note/asset_base.rs
Every Asset ID and DNA on this site is computed with the exact ZIP 227 hashes: BLAKE2b with the spec's personalisations and a BIP-340 issuer key.
On this site
Asset in every noteZIP 226 · Note structure
note.rs · Note.asset
The note stream tags each note with its asset as it is created, spent and nullified.
On this site
Commitments per assetZIP 226 · Note commitment
NoteCommitment::derive(asset)
The commitment tree appends one leaf per note and re-hashes the path to the anchor.
On this site
Nullifiers + split notesZIP 226 · Split Notes
Nullifier::derive(is_split_note)
The nullifier set grows with every spend; a note is never spent twice.
On this site
Balance per assetZIP 226 · Value commitment
ValueCommitment::derive_with_asset
Each asset's reserve is tracked on its own and summed into one ZEC root.
On this site
ZSA circuit + proofsZIP 226 · Circuit statement
circuit/circuit_zsa.rs
The proof monitor verifies every action: Halo 2, no trusted setup.
On this site
Final supplyZIP 227 · finalize · MAX_ISSUE 2^64 − 1
issued_assets.final
Genesis issues a final supply. Coins launched on pump.fun mint a fixed 1,000,000,000 too.
Today on pump.fun
Transparent issuanceZIP 227 · supply tracked in public
Issuance bundle
Every launch is public on Solana and listed in Your seeds and the terminal.
Today on pump.fun
Fees in ZECZIP 227 · fee rationale
ZIP 317 changes
ZEC stays the base asset. Every coin here is paired with ZEC and rooted in it.
Today on pump.fun
BurnZIP 226 · assetBurn · MAX_BURN_VALUE 2^63 − 1
next PR
Burning removes supply in public, per asset.
With NU7
enableZSA switchZIP 226 · enableZSA flag
Flags.zsa_enabled
Public constructors still pass false, so nothing changes until activation.
With NU7
Native issuance on ZcashZIP 226 · Deployment: NU7
zcashd · librustzcash · orchard
Seeds launched today carry the same asset description hash a native ZSA would.
With NU7
Live · ZIP 227 in your browser

Derive an Asset ID yourself.

Type an asset description and the Orchard runs ZIP 227 step by step: a BIP-340 issuer key, a BLAKE2b hash of the description, the encoded Asset ID and its Asset Digest. Copy the Python and check every byte.

The fingerprint beside it is the asset's DNA: 64 nibbles of the Asset Digest set the grid, 32 bytes set the bars. Same ID, same DNA. A fingerprint you can't design.

isk—issuance authorizing key · secret
ik—BIP-340 PubKey(isk) · secp256k1
issuer—0x00 || ik
assetDescHash—BLAKE2b-256 · "ZSA-AssetDescCRH"
EncodeAssetId—0x00 || issuer || assetDescHash
AssetDigest—BLAKE2b-512 · "ZSA-Asset-Digest"
AssetBaseGroupHashP("z.cash:OrchardZSA", AssetDigest)the Pallas point stored in each note

        
ZIP 227 · fees

ZEC stays the root. The spec says so.

ZIP 227 keeps ZEC as the token that pays every ZSA fee, "similar to how ETH is needed for ERC20 transactions". Fees in a custom asset were considered and dropped, because lifting value out of a shielded transaction would leak information about it.

That is the Orchard's model: many assets bloom, one asset is the root.

The path

Launch today. Native with NU7.

Today

Launch on pump.fun, paired with ZEC

Coins launch from your own wallet. Zero computes each coin's ZIP 227 asset description hash and writes the ZEC pairing into its description.

Launch a seed →
In review

The ZSA circuit in zcash/orchard

PR #546 parameterises notes, commitments and value commitments by asset and adds the ZSA circuit, with the builder still pinned to zatoshi.

Read the PR ↗
NU7

Zcash Shielded Assets activate

ZIP 226 schedules ZSAs for Network Upgrade 7: issuance, transfer and burn of custom assets inside the shielded pool, with fees in ZEC.

ZIP 226 ↗
02 · Live Orchard

Every asset is a branch rooted into ZEC.

Branches carry notes, notes become actions, actions settle as proofs. New launches sprout at the top.

ZECROOT—
03 · Notes, nullifiers, proofs

Created, spent, nullified. Then the next one.

Values never leave the pool. All the network sees is a commitment going in and a nullifier coming out.

  1. 01
    Note createdA commitment (cmx) is appended to the Orchard tree. Value stays shielded.
  2. 02
    Action executedOne Orchard action spends an old note and creates a new one under a single proof.
  3. 03
    Nullifier consumedThe spent note's nullifier is published. Same note, never again.
Nullifier set0
Orchard · note feed—
Proof monitor

$GHOST

Orchard proofVALID
Asset supplyFINAL
Issuer stateLOCKED
Reserve— ZEC
Shielded stateACTIVE
Asset ID—
Anchor—
Last verify—

halo2 · pallas/vesta · no trusted setup · 0 verified

Orchard commitment tree

Every note is a leaf. The root is the anchor.

epoch 1
anchor ——depth 5 · sinsemilla
04 · Seed → Root → Bloom

Launch a seed.

Zero derives an Asset ID, issues a final supply, generates the proof and roots the asset in a ZEC reserve. Then it grows. To launch a real coin on pump.fun, paired with ZEC, launch a seed →

Stage one
Seed
0assets
Reserveunder 50 ZEC
EventGenesis
  • Asset ID derived
  • Final supply issued
  • Proof generated
Stage two
Root
0assets
Reserve50 – 400 ZEC
EventReserve grows
  • Shielded market open
  • Notes flowing
  • Nullifiers consumed
Stage three
Bloom
0assets
Reserve400 ZEC and up
EventBloom
  • Inner orbit
  • Deepest root in ZEC
  • Top of the root map
orchard genesisIDLE
Zero's own geneses, live. Launch a real coin on pump.fun, paired with ZEC:Launch a seed →
05 · ZEC root map

Whatever blooms above, the roots are ZEC.

Every market reaches down into one layer.

ZEC
Total rooted in ZEC—
06 · Markets & rewards

Technical cards, not memecoin cards.

Explore all markets →
07 · Orchard terminal

Inspect the Orchard from a prompt.

Read any asset's state, verify a proof, list the nullifier set or run a genesis. Tap a step to open it in the terminal.

Open the terminal →
08 · Field guide

Zero, in Zcash's own words.

What is the Orchard?+
The environment. Orchard is Zcash's shielded protocol, live since NU5. Since NU6.3 in July 2026 its shielded activity runs in the Ironwood pool, formally verified, while the original Orchard pool is closed to new deposits. Every action carries a Halo 2 proof, which needs no trusted setup.
What is Ironwood?+
Zcash's active shielded pool since 28 July 2026 (NU6.3, block 3,428,143). It runs the same Orchard protocol with formal verification and new audits, after a soundness flaw was found in the original Orchard pool's circuit. Funds move from the old pool through a turnstile that never lets out more ZEC than went in, and the same addresses keep working.
What is an Asset ID?+
Each coin's identity. It is derived from the issuer's key and the asset description, so two issuers can never collide and one issuer can never fake another.
What are shielded notes and actions?+
Notes are assets moving privately: amount, sender and receiver stay inside the pool. An action spends one note and creates another under one proof.
What is a nullifier?+
When a note is spent its nullifier is published. The network keeps the set and rejects any nullifier it has seen before, so a note can never be spent twice.
Why does every asset root in ZEC?+
ZEC is the base asset. Every market's reserve is held in ZEC, which is why every branch on this page runs back to one root.
What do Seed, Root and Bloom mean?+
The lifecycle. Seed is genesis and a reserve under 50 ZEC. Root is 50 to 400 ZEC. Bloom is 400 ZEC and up.
Where do ZSAs come from?+
Zcash Shielded Assets are specified in ZIP 226 (transfer and burn) and ZIP 227 (issuance), both in Draft. The circuit is being built in the official zcash/orchard repository, pull request #546 "Add ZSA circuit".
Can supply change after genesis?+
No. Issuance is created with finalize set, so the asset's supply is final and the issuer state is locked.