Back to Zcash Hub
Network upgrade

Zcash Ironwood Migration Guide for Keystone Users

Updated

Zcash completed the Ironwood (NU6.3) network upgrade on July 28, 2026, activating the new Ironwood shielded pool.

If your ZEC remains in the original Orchard shielded pool, the upgrade does not cause those funds to expire or disappear, and there is no deadline requiring immediate migration. Moving the funds into the new Ironwood pool does, however, require a migration transaction created by an Ironwood-compatible wallet.

For Keystone users, the software wallet synchronizes with the network, creates the transaction, and broadcasts it. Keystone keeps the private keys offline, lets you review the transaction, and signs it. You never need to enter your recovery phrase on a computer, phone, browser, or software wallet.

1. How Ironwood migration works

Moving funds from Orchard to Ironwood takes them through the Zcash turnstile:

Orchard → Turnstile → Ironwood

This process does not directly reveal:

  • the identity of the sender or recipient;
  • the shielded addresses involved; or
  • the full balance that remains in Orchard.

However, the cross-pool amount moving from Orchard to Ironwood is public for each transaction.

For example, if you migrate 10 ZEC from Orchard to Ironwood, the blockchain shows that 10 ZEC crossed between the pools. It does not show who sent it, who received it, or which shielded addresses were used.

Migration therefore does not directly expose shielded addresses, but distinctive amounts and timing can reduce privacy.

2. Choosing a migration approach

Migrate everything at once

Moving the complete balance in one transaction is the simplest and fastest approach.

The complete amount will be public as a single cross-pool transfer. A distinctive value such as 1.2114 ZEC, or an amount previously seen in an exchange withdrawal or public payment, may make correlation easier.

Migrate in stages

Splitting the funds across multiple transfers at different times avoids publishing the complete balance as one amount.

Each cross-pool amount is still public, however, and using several transactions does not guarantee that they cannot be linked.

Users who place a higher priority on privacy can:

  • avoid exact amounts that have already appeared publicly;
  • use common values, such as whole numbers;
  • spread transfers across different dates and times; and
  • keep Tor enabled when using Zodl.

Wait before migrating

Orchard funds do not expire or disappear, and there is no mandatory migration deadline.

If you do not need to use the funds now, you can wait. Zodl displays a migration prompt when it detects an Orchard balance; if you dismiss it, the app will remind you the next time you open it.

3. What Keystone users need

First update your device and chosen software wallet to versions that support Ironwood:

  • Keystone 3 Pro: Cypherpunk 3.0.2
  • Vizor Wallet: 0.0.39+
  • Zodl: 3.9.0+ (automatic migration on iOS and Android)
  • Noir Wallet: the latest Ironwood-compatible release

Keystone Cypherpunk 3.0.2 adds:

  • Zcash Ironwood support; and
  • batch PCZT signing for Zcash.

Version 3.0.2 applies only to the Cypherpunk firmware. After installing it, you currently cannot downgrade to the 3.0.0 Multi-Coin or Bitcoin-Only firmware. Confirm that you have selected the correct firmware edition before proceeding.

After updating, open the software wallet you plan to use and allow it to synchronize to the latest block.

4. Guided migration with Vizor

Vizor 0.0.39 introduced a complete desktop Ironwood migration flow, including guided QR signing for Keystone accounts.

Open the connected Keystone account in Vizor and wait for synchronization to finish. When the account has eligible Orchard funds, Vizor displays the Ironwood migration entry point.

Vizor's migration flow must be able to migrate at least 0.01 ZEC and also needs to reserve the fees required by the process.

In the current implementation, the migration entry point therefore does not appear when the available Orchard balance is below approximately 0.01095 ZEC. That balance can remain in Orchard and does not expire or disappear.

Steps

  1. Open the connected Keystone account in Vizor.
  2. Wait for synchronization to finish, then go to the Ironwood Migration page.
  3. Review the migration amount, plan, estimated duration, and privacy explanation.
  4. Follow the prompt and scan the unsigned QR code with Keystone. Because the device needs to batch-sign multiple transactions, the QR code contains a large amount of data and scanning may take up to approximately six minutes. Wait patiently and keep the device steady; use a stand to hold it in place if necessary.
  5. After scanning finishes, wait for Keystone to parse the transactions. Parsing may take up to approximately two additional minutes. Do not exit or restart the migration during this process.
  6. When parsing is complete, verify the migration amount and transaction information on the Keystone screen, then sign after confirming the details.
  7. Scan the signed QR code returned by Keystone with Vizor.
  8. Let Vizor broadcast the transactions and monitor progress on the migration page.

Vizor may split a migration into several transactions. Funds already confirmed in Ironwood remain available to use while the rest continue through the migration plan.

Depending on the balance and plan, the process may take several hours to several days. During migration, keep:

  • the computer powered on and unlocked;
  • Vizor running; and
  • the network connection stable.

If Vizor closes, the computer sleeps, or the connection is interrupted, reopen Vizor and continue from its recovery page. Do not create a new migration before confirming the status of the existing one.

5. Automatic migration with Zodl

Zodl 3.9.0 provides automatic Ironwood migration on iOS and Android, including support for connected Keystone accounts. Before starting, confirm that Zodl is updated to version 3.9.0 or later and that Keystone is running Cypherpunk 3.0.2 or later.

When Zodl detects an Orchard balance in the Keystone account, it displays a migration prompt. You can choose:

  • Migrate with Privacy (recommended): splits the balance into multiple standardized amounts and spreads their submission times to reduce amount and timing correlation. Each cross-pool amount is still public, and this approach cannot guarantee that the transactions are impossible to link.
  • Migrate Immediately: moves the full balance in one transaction. This is the fastest option, but the complete cross-pool amount becomes public on-chain.

Steps

  1. Open the connected Keystone account in Zodl and wait for synchronization to finish.
  2. Tap Migrate in the migration prompt.
  3. Select Migrate with Privacy or Migrate Immediately. The remaining steps describe the private migration option.
  4. Review the migration explanation and enable Tor when prompted. Zodl strongly recommends using Tor during migration so that a remote server cannot associate your IP address with the migration amounts.
  5. Enable Zodl notifications. On Android, also allow the app to run in the background so it can make a best effort to broadcast transactions according to the plan. On iOS, keep Zodl open and active whenever possible. Notifications report progress and tell you when the app needs to be reopened or the plan needs to be confirmed again.
  6. Review each migration transaction and its approximate submission time, then tap Start migration.
  7. Wait for Zodl to generate the unsigned QR code, then scan it with Keystone. The migration payload contains multiple transactions, so QR generation and scanning may take some time.
  8. If Zodl displays a label such as 1 of 3, the migration has been divided into several signing batches. Process them in order and complete all batches together at the start of the migration. Zodl will then broadcast the individual transactions according to the schedule, normally without reconnecting Keystone for each broadcast. If the migration plan changes, Zodl may ask you to confirm it again.
  9. On Keystone, review the initial split transaction and subsequent migration transactions across the paginated screens. Verify the amounts and transaction information carefully, then sign. Parsing and signing may take time because of the payload size.
  10. When Keystone displays the signed QR code, tap Get Signature in Zodl and scan the signed data for that batch. Repeat the scan-and-sign flow if the migration contains multiple batches.
  11. After all batches have been signed, wait while Zodl schedules the broadcasts. The scheduling screen may temporarily show no progress bar or appear blank. Be patient and do not exit or create another migration.
  12. Return to the Zodl home screen and monitor the persistent migration card. Tap More to view the status of each transaction.

Platform-specific delivery and recovery

On Android, Zodl makes a best effort to broadcast transactions on schedule when background delivery is allowed. Transactions may be delayed if the phone is offline, asleep, or in a battery-saving mode; this does not usually mean the migration has failed.

On iOS, keep Zodl open and active whenever possible so that each scheduled migration transaction can be sent. If you close the app, Zodl will notify you when the next transaction is ready and prompt you to reopen it.

Keep the phone powered on and connected during migration. If a notification says that a transaction is ready, delivery was delayed, or the plan needs confirmation again, open Zodl and follow the on-screen guidance. Progress is preserved when you reopen the app. Do not create a new migration before confirming the status of the existing one.

Handling the remaining Orchard funds

Because private migration uses standardized amounts, a small Orchard remainder may be left unmigrated by default. When migration finishes, Zodl offers two choices:

  • Sweep: move the remainder into Ironwood, with the tradeoff that the exact amount may be more identifiable;
  • Lock: locally lock the remainder in the current Zodl instance to prevent it from being spent inadvertently and preserve better privacy.

The lock exists only in the current Zodl instance. It does not follow the Keystone wallet if you connect or import it into another Zodl instance. According to Zodl's current guidance, the app cannot yet unlock these funds directly; that capability is planned for a future update. Choose Lock only if you do not currently need to use the remainder. After making this choice, tap the balance on the Zodl home screen to view the Orchard and Ironwood pool breakdown.

Security reminders

Keep these points in mind throughout migration:

  • Keep your recovery phrase offline. A legitimate migration never requires you to enter it anywhere.
  • Before signing, always verify the migration amount and transaction information on the Keystone screen.
  • Use only official Keystone, Vizor, Zodl, or Noir software and migration entry points.
  • Do not run alleged migration scripts or scan QR codes sent through direct messages or comments.

There is no urgent deadline for Ironwood migration. Understand the process and its privacy effects first, then choose the wallet and migration approach that fit your needs.

← Back to all updates Open the permanent page → 中文