Deploy ZEC on tiles
Every round opens a 16-tile board. Deploy ZEC on the tiles you choose. Your picks and amounts are encrypted — nobody sees the board until it closes.
Ironwoodis a mining game on Solana, played with ZEC, that mints a privacy coin. Deploy ZEC across a 16-tile board every round, win the losing side's ZEC, dig IRON out of hidden veins, and keep your winnings inside a shielded pool you can spend from privately — to any wallet, with nothing on-chain linking the two ends.
ZEC is the hardest privacy asset in crypto and it earns nothing. Solana has the liquidity and the speed but no shielded economy. Ironwoodconnects the two with Zcash's own rules: encrypted balances, public supply, a fixed cap with halvings, and the choice to shield or not. Mining deepens the pool; the pool pays the miners; everyone inside is part of the crowd.
Mine ZEC privately. Find the rich tile. Get paid for the crowd you're standing in.
Rounds run on a 16-tile board on a fixed slot clock of about a minute. Miners deploy ZEC on the tiles they choose; deploys are encrypted, so nobody can see where the crowd is or snipe an empty tile at the last second.
When the round closes, the winning tile is drawn by the Arcium multi-party computation network, where no one can read or steer it. Miners on the winning tile share the ZEC from losing tiles in proportion to their share of the tile. Every tile also digs its vein, and a rare Motherlode roll sits on top.
All winnings are minted straight into your shielded balance. The amount each round emits is public; who received it is not.
Every round opens a 16-tile board. Deploy ZEC on the tiles you choose. Your picks and amounts are encrypted — nobody sees the board until it closes.
Rounds run on a fixed slot clock (about a minute). When a round closes, the winning tile is drawn inside the Arcium MPC network, where no single party — including us — can see or steer the randomness.
ZEC on losing tiles flows to the miners on the winning tile, split by each miner's share of that tile. 13.5% is skimmed first: 10% buyback, 1% yield, 1.5% Motherlode, 1% into the veins.
Under each tile is a hidden vein of IRON and ZEC. Veins can pop on any round, on any tile — winner or not — and pay everyone standing on it.
Pot winnings, vein payouts, and Motherlode hits are minted directly into your encrypted balance inside the shielded pool. Supply is public; who received it never is.
IRONis never minted to a random winner. New supply is dropped into hidden veins under the 16 tiles, and the only way it comes out of the ground is when a tile pops. Veins are sixteen mini-jackpots that don't care which tile won.
Because vein sizes and payouts are encrypted, the only person who knows a tile is rich is someone who just mined it — and they can't be watched. Prospecting is private information you can use until the crowd catches on.
Each round, a vein fee (1% of the losing pot), a slice of IRON emission, and a share of buybacks are dropped into the 16 veins on a random, uneven split. Some tiles quietly get rich.
Vein balances live as encrypted state on Arcium. Nobody can read how rich a tile is — not miners, not bots, not the protocol.
Every round, every tile rolls to pop. The chance rises with the size of the vein, so fat veins can't sit forever and no one can prove a tile is "due" — only suspect it.
When a tile pops, its vein is paid pro-rata to the miners on that tile that round, regardless of which tile won. Pop events are public; amounts and recipients stay hidden.
Tiles that haven't popped in a while are probably fat. A fat vein split among five miners is huge; among two hundred it's nothing. Read the board, avoid the crowd, and your discovery stays yours.
The Motherlode is a single global jackpot layered on top of every round. It turns a slice of round activity into a growing ZEC and IRON pool that pays out in full whenever the jackpot lands.
Where veins are frequent and per-tile, the Motherlode is rare and tied to the winning tile. Together a single deploy has three ways to pay: the pot, the veins, and the Motherlode.
Every round sends 1.5% of losing ZEC and 11.5% of the round's IRON emission to the Motherlode. Unhit rounds carry the pool forward.
When the winning tile is revealed, the same randomness rolls the Motherlode chance for that round.
On a hit, the accumulated ZEC and IRON are credited to that round's winning-tile miners in proportion to their tile share — into their shielded balances.
Motherlode winnings sit in your mining balance alongside everything else: deploy them, withdraw them, or move them into the shielded pool.
A refining fee of 10% is applied to every IRON withdrawal from the mining balance (ZEC withdraws free) and redistributed to everyone still holding inside the pool. On top of that, pool holders receive a slice of every losing pot in ZEC. The net effect: the longer you hold, the more of the protocol's revenue you collect — without doing anything. Leaving the shielded pool itself is cheap (0.25%, also paid to holders) so private transfers stay usable.
Winnings land in your shielded balance as IRON and ZEC. Leave them there and they count toward every yield stream in the pool.
Withdrawing IRON pays a 10% refining fee (ZEC withdraws in full, free). It is redistributed pro-rata to everyone still holding inside the pool.
1 point of every losing pot is paid out in ZEC to pool holders. Mining pays the people who hold.
Every withdrawal from the shielded pool pays 0.25% to everyone still holding inside it. The more the pool is used for private transfers, the more holders earn — and your Statement shows exactly how much.
Moving winnings into the shielded pool pays the same 10% refining fee — taken inside MPC, revealed only as a per-round total, and paid to holders like every other refining fee.
Withdrawing IRON to a wallet applies the 10% refining fee to the full amount — winnings and yield together; ZEC withdraws in full, free. Leaving the shielded pool is separate and costs 0.25%.
Ironwood's pool is not a ledger of accounts. It is bearer cash: a note is an amount and a secret, authenticated by a key that exists only inside the MPC network and sealed to a one-time key of its owner. Spending a note proves you can open it; the network verifies it, retires it, and issues fresh notes. The link between a note being created and being spent exists nowhere but inside the computation.
The pool is an anonymity set: every unshield could be any note inside it, and the more value that moves through, the deeper the set. Miners are part of it: every deploy carries a hidden, usually-zero transfer from the mining balance into the pool, and notes can fund mining the same way, so nobody can tell which winnings became private or when. Shields and unshields are the only public edges — like Zcash's transparent and shielded sides. Zcash mainnet bridging lands in a later phase; today the pool holds wZEC and IRON on Solana.
A public transfer of wZEC or IRON into the pool vault. Inside the MPC network it becomes a note — an amount plus a spend secret only the network ever saw — sealed to a one-time key derived from your shielded address. The chain shows the deposit and a ciphertext; nothing ties the two to later activity.
Type an amount and a recipient — a Solana wallet or an iw… shielded address — and press send. A relay submits the spend so your wallet never signs. The network checks the note's authentication tag, publishes a nullifier so it can't be spent twice, and seals fresh notes: the recipient's and your change. Pool-to-pool sends pay only the relay fee; on-chain there is no sender, no receiver, and no amount.
Withdraw a note to any Solana wallet — including one that has never touched the pool. The amount and destination become public (that is the point of leaving). It costs 0.25% plus a small relay fee, the same schedule as Privacy Cash — but the 0.25% is paid to everyone still holding in the pool. The 10% refining fee is for leaving the mining game, not the pool. Round amounts are suggested because an odd amount is easier to match to an earlier deposit.
Your viewing key opens every note that was ever sealed to you — and nothing else. Share it with an auditor or counterparty; nobody else gets one.
The Arcium cluster running the computations sees plaintext while it computes, and if every node in it colluded it could read the graph or forge notes up to the vault balance — the same trust the mining ledger already carries. A relay sees only the public transaction it submits; the bundle it forwards is encrypted to the network, so it can neither read nor redirect your outputs. Timing and amount correlation between a shield and an unshield are mitigated only by the anonymity set and your own habits, exactly as with Zcash's t→z→t.
Balances are hidden; supply is not. The vault balance and the pool's accounted total are public and can only change by the net amount entering or leaving; a transaction that would take the pool negative is invalid. This is Zcash's turnstile rule, and it means a bug in the private logic can never secretly inflate the coin.
Most privacy pools are only as private as the number of people who deliberately deposit into them. Ironwood's pool is not a separate box bolted onto the game — it is the same vault, holding the same coins, with two different ways of remembering who they belong to. A miner's unrefined balance and a shielded note are claims on one pot, tracked by one public total that never says which side a coin is on.
The protocol owns exactly one wZEC account and one IRON account. Money deposited to mine, money shielded to send privately, the Motherlode and the veins all sit in the same place. An explorer shows one number: what Ironwood holds. How it splits between miners and senders is written down nowhere.
A mining balance is an encrypted number inside a Miner account your wallet owns — the chain sees the account, never the number. A note is bearer cash: an amount and a secret, sealed to a one-time address, with no account and no owner field anywhere. Same vault, two ledgers on top of it.
Every deploy you sign carries an extra encrypted field: also move this much into the pool. For almost everyone it is zero, but it is present in every deploy, so a bridging deploy and an ordinary one are identical on-chain. The 10% refining fee is taken inside MPC and only the round's total is ever published. A second cheap step seals the moved amount into a note — and a note holding zero is byte-for-byte indistinguishable from one holding 100 ZEC, so decoys are free.
Spending a note into your mining ledger writes an encrypted credit onto your Miner account, folded into your balance on your next deploy. On-chain it looks like any other note being spent: one nullifier, no amount, no “funded from the pool” flag.
An unshield could have come from any shield ever made, from any miner's bridged winnings, from an earlier private send, or from accrued yield — and nobody can even count how many miners have ever bridged. A deposit-only mixer has one of those sources. Every person who plays the game is part of the anonymity set whether or not they care about privacy.
The holders' index pays a mining balance and a note at exactly the same rate: pot share, refining fees and transfer fees accrue per unit held, wherever it sits. Moving between the two changes your privacy, not your return.
A single accounted figure covers mining balances and notes together. It rises on every deposit, shield and yield accrual and falls on every withdrawal and unshield, so anyone can check the protocol is not printing money — without learning how the money is split.
Ironwood is a Zcash application that settles on Solana. Today the ZEC inside is wZEC (bridged Zcash on Solana). The steps below — shielded deposits straight from Zcash mainnet, payouts to unified addresses, a treasury held on Zcash — are the planned next phase and are not part of the current release.
Send shielded ZEC on Zcash mainnet to the protocol's address with a memo and it becomes a deploy on Solana. You never have to leave Zcash to mine.
Winnings and yield can exit directly to a Zcash unified address. Every payout is a real shielded Zcash transaction and grows Zcash's shielded supply.
Each round settles inside the Arcium MPC network: the draw, the vein pops, and every payout are computed on encrypted state. Anchoring rounds to Zcash block hashes is a later upgrade, not part of the current release.
Protocol ZEC is held in a shielded Zcash address whose spending key exists only as threshold (FROST) shares. No single signer; pool supply on Solana is checked against reserves on Zcash.
Encrypted balances with a public supply. A fixed cap with halvings. Shield or don't — your choice, same coin. Viewing keys for selective disclosure. Pool rotation through a turnstile when cryptography needs to change. None of this is branding; each is a rule in the program.
IRON has a capped maximum supply of 21,000,000 tokens. Supply at launch is zero. There is no presale, no team allocation, and no airdrop: every token is mined. Emission follows a Zcash-style schedule — a slow start, then halvings — enforced by the program on Solana.
Each round's emission is dropped into the hidden veins rather than paid to a winner, with 11.5% reserved for the Motherlode. A fixed funding stream from emission goes to a protocol lockbox written into the code.
Transparent: IRON is a standard Solana token, tradeable on the AMM. Its canonical pool is paired against wZEC, so the chart is a ZEC chart.
Shielded: shield IRON into the pool at any time to make your balance invisible and start collecting refining fees and ZEC yield. Mined tokens are born inside an encrypted balance.
Protocol revenue is collected in ZEC. 10% of every losing pot goes to a buyback account that is earmarked for buying IRON on the open market; what gets bought is burned (buyback and burn, ~90% burned). Buybacks are run by the team for now, not by the program, and the account balance is public. Most of the rest is paid to pool holders as ZEC.
Below is a breakdown of fees charged or managed by the protocol. Roughly two-thirds of everything skimmed flows back to people holding inside the pool.
1% of every deploy is collected as an operations fee and routed to the protocol treasury.
13.5% of the ZEC on losing tiles is skimmed by the protocol: ~10 points buy back and burn the token, ~1 point is paid as ZEC yield to pool holders.
1.5% of the ZEC on losing tiles accrues to the Motherlode jackpot.
1% of the ZEC on losing tiles is dropped into the hidden veins and paid back to miners when tiles pop.
11.5% of each round's IRON emission accrues to the Motherlode jackpot.
Withdrawing IRON from the mining balance pays a 10% refining fee, redistributed to everyone still holding inside the pool; ZEC withdraws free.
0.25% of every withdrawal from the shielded pool is paid to everyone still holding inside the pool; private transfers inside the pool pay only the relay fee. Your Statement on the Pool page shows what you earned from each stream.
The board hides the crowd, the veins hide the supply, and payouts hide who won. That replaces last-second sniping with inference, and it gives bots an edge that can't be copied.
Mine when the cost to mine is below IRON's market price, sell on the AMM, repeat. Bots keep the two in line — that's the protocol's difficulty adjustment.
Deploy a fixed amount on every tile. You're on every winning tile and every vein pop; variance is low, edge is zero. The floor that smarter bots beat.
Probe tiles with small deploys, infer which veins are fat from your own private payouts, and concentrate before the crowd arrives. Your discoveries can't be copied because nobody can see them.
Fund an autominer and it deploys every round. Its strategy — tiles, sizing, rotation — is encrypted, so a winning bot stays a winning bot.
Don't withdraw. Refining fees, the losing-pot ZEC slice, and transfer fees all pay holders inside the pool. The longer you hold, the more of the network's fees you collect.
Hidden: your tiles, your amounts, your balance, your winnings, your strategy, and where you exit. Public: the total on the board, the winning tile, pop events, pool supply, and deposits and withdrawals at the edges. Withdraw to fresh wallets and let the relayer pay gas.
Use these pages to move from docs into the live app surfaces.