Pay in Zcash. Claim with a code. Nobody on file.
Zcash Ironwood · code-signed claim
Pay without showing your wallet.
Your browser makes a secret code before you pay. You send shielded ZEC with the code's public tag as the memo. Later the code signs your claim, and the piece goes to any wallet you name.
The ZEC door is closed. It opens only after a real Ironwood payment has been received, reserved and claimed from start to finish. Do not send ZEC yet.
Or buy $SHRIVE on Pons and claim the usual way.
Local demo. Buying and minting are not live.
Tap a piece behind the lattice to see what you could claim.
The line ignites.

How the privacy works
Why this is private
Three steps, and your Zcash wallet never talks to this site.
- 1Your code comes first
Before you pay, your browser makes a random secret code. You save it. It never leaves your device.
- 2You pay in shielded ZEC
You send ZEC from your own wallet into Ironwood, the shielded pool Zcash opened with its NU6.3 upgrade. The memo carries only a hash tied to your code.
- 3The code signs your claim
To claim, the code signs a message naming who sends the claim and where the piece goes. The secret is never published, so nobody can copy it and claim first.
Public observers cannot read an Ironwood payment's amount or memo. Our watcher can, because it holds a viewing key. When you claim, the tag, the sender, the recipient and the signature show on Robinhood Chain.
Every coin gives you a coin.
This one never asks your name.
One buy, one piece.
Press a button below and watch it happen.
You buy
The line lights
You hold the piece
Buy $SHRIVE, or send ZEC. No wallet, no signature, no address kept. On the ZEC path that is literal: nothing connects and nothing signs when you pay, and no payer address is stored. Your saved code signs once, later, when you claim. A Pons buy is an ordinary swap from your own wallet.
Confessional screensite simulation
Just trying it? Press a buy.
Try a buy
Pretend to buy some $SHRIVE. The screen lights from behind, then prints the slip you would claim with.
Demo values in $SHRIVE. More heat, bigger buy.
Demo minimum: 500K $SHRIVE. The 250K buy lights nothing.
0 buys, 0 pieces
The real door, shut for now
Pay in ZEC
Save your code, then send one shielded Ironwood payment with the code's tag as the memo. No Zcash wallet connects here.
The door stays shut until a real Ironwood payment has been received, reserved and claimed from start to finish. Do not send ZEC yet.
See the Zcash doorClaim-code slipDemo
SHRV ---- ---- ---- ---- .. ----
A demo label, not a code. A real one is 32 random bytes your browser makes before you pay, shown once. Until you claim, only a hash tied to it is on chain.
Screen dark. Press a buy.
Your piece shows up here.
This exact mix: 1 in 0
How is my piece decided?
Four facts about a buy decide the piece: which pool, which wallet, which buy it is, and how much. They are hashed into a seed; the seed picks the five traits.
The seed for this buy
This is a demo. Buying and minting are not live.
The ledger
What others can see.
Read it like a receipt: what anyone can look up, and what only the watcher sees.
Anyone can see
- A Pons buy and its normal claim
- Your code's tag and the amount reserved for it, on Robinhood Chain
- At claim time: the tag, who sent the claim, the recipient and the signature
Kept out of view
- Your code itself. It never leaves your browser
- Your Zcash wallet. It never connects here
- The Ironwood payment's amount and memo, hidden from public observers. Only our watcher reads them
The watcher is trusted: Robinhood Chain does not check a Zcash proof, it trusts the watcher's signer to reserve only after a real payment. Timing and network data can still link a payment to a claim.
Build a piece.
Light one hole in each row and see the piece those five traits make. The swap picks for real; this is a study.
Trait studynot a buy
This exact mix: 1 in 0
Pay in Zcash
The Zcash door is closed.
SHRIVE is built for Ironwood, the shielded pool Zcash opened when its NU6.3 upgrade sealed the old Orchard pool. The door stays shut until one real payment has been received, reserved and claimed from start to finish, and an outside review has passed.
- Save your code. Your browser makes it. Nobody else ever sees it.
- Send shielded ZEC. One Ironwood payment, with your code's tag as the memo.
- The watcher reserves. It sees the payment and sets your piece aside on Robinhood Chain under that tag.
- Your code claims. It signs a claim to any wallet you pick. You pay the small network fee.
No ZEC yet? Zodl, a Zcash wallet, swaps other coins into shielded ZEC through NEAR Intents, where market makers compete to fill the order. That swap happens in your wallet, outside this site, and has not been tested with this door.
Not open yet.
The deposit address and claim code appear here once the Zcash door is wired. Buy $SHRIVE on Pons in the meantime, or come back later.
GET MY PIECES
Get the pieces from your token buys, wherever you traded.
You pay only the small network fee to claim.
Paste a wallet address to find its pieces.
Sample piece
Check a buy.
A transaction hash is all the mint route needs. Built and tested locally. Not deployed. No address.
Same swap, same piece.
THE RAIL
Each new piece joins your rail. Try another buy to add one.
site simulationBrowse the collection.
Explore 48 sample pieces. Find a mix you like.
site simulationNo piece matches that mix. Remove a filter.
THE ODDS
Each seed picks one option from each group. Your pick lights ember.
Site piece and chain piece.
Same traits. The image on the right is what the contract draws.
How the piece reaches your wallet
No contract published yet.
- You buy $SHRIVE on Pons. ZEC is closed.
- You get a claim code, shown once.
- You claim with the code, to any wallet, any time.
- You pay the small network fee. Nobody mints it for you.
What runs when you buy.
Built and tested locally. Not deployed. No address.
The tech
In plain words: you pay inside Zcash's Ironwood shielded pool, a watcher with a read-only key confirms the payment, and a code only you hold signs the claim. The rows below are the exact parts.
- Where you pay
- Zcash's Ironwood shielded pool. The NU6.3 upgrade (mainnet block 3428143) sealed the old Orchard pool for new payments and opened Ironwood, which still uses the Orchard protocol. Old Orchard, Sapling and transparent payments do not count.
- Your code
- 32 random bytes made in your browser before you pay. They work as a private signing key. The public tag is the keccak256 hash of that key's 20 byte address, and only the tag goes in the memo and on chain.
- The watcher
- Built on librustzcash. It holds a viewing key, not a spending key, so it can read payments to SHRIVE but cannot move funds. It checks pool, amount, memo and confirmations, then its signer calls
reserve(codeHash, amount)on Robinhood Chain. - Claiming
- Your code signs an EIP-712 message naming the caller and the recipient.
claimWithCode(codeHash, to, signature)checks the signer matches the tag and mints once. A copied signature does not work for anyone else. - Pons buyers
- The ordinary claim for $SHRIVE bought on Pons uses the EIP-712 Shrive Collection v1 signature.
- Door status
- Closed on the site and on the server. The Rust watcher has not been compiled here, and no real Ironwood payment has been received, reserved and claimed yet.
- Built on
- ShriveCollection on Robinhood Chain (id 4663): Solidity 0.8.24, OpenZeppelin 5.1.0 ERC-721, art drawn fully on chain as SVG, built on Pons.
Trust limit: Robinhood Chain does not check a Zcash proof. It trusts the watcher's signer to reserve only after a real payment. The watcher sees amounts and memos, never who paid. Phala attestation for the watcher host is planned, not built.
The proposed rule
The line ignites.
Four rules connect your payment to your piece.
One buy, one piece. Or one Zcash payment, one code.
Buy $SHRIVE on Pons as usual. The Ironwood ZEC door is closed pending external validation. Either path, one piece.
Ironwood ZEC payments are closed. Only a public identifier would be reserved.
The Zcash payment moves through your own wallet. The site never sees a wallet, an address or a name, only the hash of the code you are given.
Claim with the code to any wallet, any time. The claimer pays the small network fee.
Bring the code to Get my pieces and claim to any wallet, any time. You pay only the small Robinhood network fee to receive it.
The Zcash hop is not private on its own. Shield in your own wallet first. We will not pretend otherwise.
Zcash's transparent addresses are not private by themselves. Shield your funds in your own wallet before you send them. We say this plainly instead of pretending otherwise.
No pool, collection or deposit address is published.
The minimum buy, supply and launch date are unpublished; the minimum here is your own number.
Read the arithmeticQuestions.
Do I need to claim my piece?
Yes. Open Get my pieces, connect the wallet you bought with, and claim. Your wallet pays the small network fee for the mint, and the piece lands in the wallet that bought.
Does every buy get a piece?
Only a buy at or above the collection's minimum. Smaller buys are ordinary swaps like any other, and never bring a piece.
Can I sell the piece?
Once minted, it is an ordinary ERC-721 in your wallet, so yes, the same way as any other NFT. Nothing about it is restricted or soulbound.
Is there a contract yet?
No. Nothing is deployed, and no address exists on any network yet.
Is paying in Zcash private?
The site never sees a wallet, an address or a name, and keeps only a hash of your code. The transfer itself moves through transparent addresses. Shielding is your own wallet's job before the funds leave it.
What decides what my piece looks like?
A seed built from the pool, the buyer's wallet, which numbered buy it was, and the amount, all packed together and hashed. The same four inputs always give the same seed and the same piece.
Every swap has a look.
48 buys from the sample wallet. One piece at a time.
site simulation