Pay in Zcash. Claim with a code.

Zcash Ironwood · code-signed claim

Pay without showing your wallet.

Your browser makes a secret code before you pay. You send shielded ZEC with the code's public tag as the memo. Later the code signs your claim, and the piece goes to any wallet you name.

The ZEC door is closed. It opens only after a real Ironwood payment has been received, reserved and claimed from start to finish. Do not send ZEC yet.

Or buy $SHRIVE on Pons and claim the usual way.

Local demo. Buying and minting are not live.

Try a buy

Tap a piece behind the lattice to see what you could claim.

The line ignites.

Matte black lattice screen facing you, ember light glowing through the holes along its middle line.
Your simulated lattice

How the privacy works

Why this is private

Three steps, and your Zcash wallet never talks to this site.

  1. 1
    Your code comes first

    Before you pay, your browser makes a random secret code. You save it. It never leaves your device.

  2. 2
    You pay in shielded ZEC

    You send ZEC from your own wallet into Ironwood, the shielded pool Zcash opened with its NU6.3 upgrade. The memo carries only a hash tied to your code.

  3. 3
    The code signs your claim

    To claim, the code signs a message naming who sends the claim and where the piece goes. The secret is never published, so nobody can copy it and claim first.

Public observers cannot read an Ironwood payment's amount or memo. Our watcher can, because it holds a viewing key. When you claim, the tag, the sender, the recipient and the signature show on Robinhood Chain.

Every coin gives you a coin.

This one never asks your name.

One buy, one piece.

Press a button below and watch it happen.

You buy

The line lights

You hold the piece

Buy $SHRIVE, or send ZEC. No wallet, no signature, no address kept. On the ZEC path that is literal: nothing connects and nothing signs when you pay, and no payer address is stored. Your saved code signs once, later, when you claim. A Pons buy is an ordinary swap from your own wallet.

Confessional screensite simulation

Just trying it? Press a buy.

Try a buy

Pretend to buy some $SHRIVE. The screen lights from behind, then prints the slip you would claim with.

Demo values in $SHRIVE. More heat, bigger buy.

Demo minimum: 500K $SHRIVE. The 250K buy lights nothing.

0 buys, 0 pieces

Claim-code slipDemo

SHRV ---- ---- ---- ---- .. ----

A demo label, not a code. A real one is 32 random bytes your browser makes before you pay, shown once. Until you claim, only a hash tied to it is on chain.

Screen dark. Press a buy.

Your piece shows up here.

How is my piece decided?

Four facts about a buy decide the piece: which pool, which wallet, which buy it is, and how much. They are hashed into a seed; the seed picks the five traits.

Demo values in $SHRIVE.

Sample wallet for this demo.

The seed for this buy

This is a demo. Buying and minting are not live.

The ledger

What others can see.

Read it like a receipt: what anyone can look up, and what only the watcher sees.

Anyone can see

  • A Pons buy and its normal claim
  • Your code's tag and the amount reserved for it, on Robinhood Chain
  • At claim time: the tag, who sent the claim, the recipient and the signature

Kept out of view

  • Your code itself. It never leaves your browser
  • Your Zcash wallet. It never connects here
  • The Ironwood payment's amount and memo, hidden from public observers. Only our watcher reads them

The watcher is trusted: Robinhood Chain does not check a Zcash proof, it trusts the watcher's signer to reserve only after a real payment. Timing and network data can still link a payment to a claim.

Build a piece.

Light one hole in each row and see the piece those five traits make. The swap picks for real; this is a study.

Trait studynot a buy

Rank

This exact mix: 1 in 0

Pay in Zcash

The Zcash door is closed.

SHRIVE is built for Ironwood, the shielded pool Zcash opened when its NU6.3 upgrade sealed the old Orchard pool. The door stays shut until one real payment has been received, reserved and claimed from start to finish, and an outside review has passed.

  1. Save your code. Your browser makes it. Nobody else ever sees it.
  2. Send shielded ZEC. One Ironwood payment, with your code's tag as the memo.
  3. The watcher reserves. It sees the payment and sets your piece aside on Robinhood Chain under that tag.
  4. Your code claims. It signs a claim to any wallet you pick. You pay the small network fee.

No ZEC yet? Zodl, a Zcash wallet, swaps other coins into shielded ZEC through NEAR Intents, where market makers compete to fill the order. That swap happens in your wallet, outside this site, and has not been tested with this door.

Claim a piece with a code

GET MY PIECES

Get the pieces from your token buys, wherever you traded.

Use the wallet you traded with. No connection needed.

Paste a wallet address to find its pieces.

Same swap, same piece.

THE RAIL

Each new piece joins your rail. Try another buy to add one.

site simulation

Browse the collection.

Explore 48 sample pieces. Find a mix you like.

site simulation
48 pieces

THE ODDS

Each seed picks one option from each group. Your pick lights ember.

Site piece and chain piece.

Same traits. The image on the right is what the contract draws.

On the site
Drawn by the contract, same traits

How the piece reaches your wallet

No contract published yet.

  1. You buy $SHRIVE, or pay in ZEC.
  2. For ZEC, you save your code before payment.
  3. You claim with the code, to any wallet, any time.
  4. You pay the small network fee. Nobody mints it for you.
How it works

What runs when you buy.

Built and tested locally. Not deployed. No address.

The tech

In plain words: you pay inside Zcash's Ironwood shielded pool, a watcher with a read-only key confirms the payment, and a code only you hold signs the claim. The rows below are the exact parts.

Where you pay
Zcash's Ironwood shielded pool. The NU6.3 upgrade (mainnet block 3428143) sealed the old Orchard pool for new payments and opened Ironwood, which still uses the Orchard protocol. Old Orchard, Sapling and transparent payments do not count.
Your code
32 random bytes made in your browser before you pay. They work as a private signing key. The public tag is the keccak256 hash of that key's 20 byte address, and only the tag goes in the memo and on chain.
The watcher
Built on librustzcash. It holds a viewing key, not a spending key, so it can read payments to SHRIVE but cannot move funds. It checks pool, amount, memo and confirmations, then its signer calls reserve(codeHash, amount) on Robinhood Chain.
Claiming
Your code signs an EIP-712 message naming the caller and the recipient. claimWithCode(codeHash, to, signature) checks the signer matches the tag and mints once. A copied signature does not work for anyone else.
Pons buyers
The ordinary claim for $SHRIVE bought on Pons uses the EIP-712 Shrive Collection v1 signature.
Door status
Closed on the site and on the server. The Rust watcher has not been compiled here, and no real Ironwood payment has been received, reserved and claimed yet.
Built on
ShriveCollection on Robinhood Chain (id 4663): Solidity 0.8.24, OpenZeppelin 5.1.0 ERC-721, art drawn fully on chain as SVG, built on Pons.

Trust limit: Robinhood Chain does not check a Zcash proof. It trusts the watcher's signer to reserve only after a real payment. The watcher sees amounts and memos, never who paid. Phala attestation for the watcher host is planned, not built.

The proposed rule

The line ignites.

Four rules connect your payment to your piece.

One buy, one piece. Or one Zcash payment, one code.

Buy $SHRIVE on Pons as usual for one piece, or send ZEC through the door below for one claim code. Either path, one piece.

Pay in ZEC from your own wallet. We keep no address, only a hash tied to your code.

The site does not connect to your Zcash wallet or ask for its address. The watcher sees the received amount and memo hash. Save your code before sending an Ironwood note.

Claim with the code to any wallet, any time. The claimer pays the small network fee.
Your minimum

Bring the code to Get my pieces and claim to any wallet, any time. You pay only the small Robinhood network fee to receive it.

Ironwood shields the payment on chain, with limits.

A prior transparent input can still be linked to later activity. The watcher sees amounts and memo hashes, and timing or network metadata can correlate the later public claim.

No pool, collection or deposit address is published.

The minimum buy, supply and launch date are unpublished; the minimum here is your own number.

Read the arithmetic

Questions.

Do I need to claim my piece?

Yes. Open Get my pieces, connect the wallet you bought with, and claim. Your wallet pays the small network fee for the mint, and the piece lands in the wallet that bought.

Does every buy get a piece?

Only a buy at or above the collection's minimum. Smaller buys are ordinary swaps like any other, and never bring a piece.

Can I sell the piece?

Once minted, it is an ordinary ERC-721 in your wallet, so yes, the same way as any other NFT. Nothing about it is restricted or soulbound.

Is there a contract yet?

No. Nothing is deployed, and no address exists on any network yet.

Is paying in Zcash private?

The site does not connect to a Zcash wallet. An Ironwood transfer hides its amount and memo from public observers, but the watcher sees both and prior transparent activity can remain linkable.

What decides what my piece looks like?

A seed built from the pool, the buyer's wallet, which numbered buy it was, and the amount, all packed together and hashed. The same four inputs always give the same seed and the same piece.

All questions

Every swap has a look.

48 buys from the sample wallet. One piece at a time.

site simulation

Confess nothing.

Try a buy

Built and tested locally. Not deployed. No address.

Zcash Ironwood · viewing-key watcher · code-signed claim