The price of Zcash (ZEC) plunged 38% after the disclosure of a critical counterfeiting vulnerability in its Orchard shielded pool that went undetected for four years. Discovered by a security researcher using an AI model, the bug could have allowed unlimited, untraceable ZEC minting. While an emergency patch was deployed, Zcash's privacy architecture makes it impossible to prove non-exploitation, prompting prominent investors to sell their holdings.
Orchard pool counterfeiting vulnerability
- ▪The flaw was present from Orchard's activation in May 2022 until an emergency fix was deployed in June 2026, a period of nearly four years
- ▪A critical vulnerability in Zcash's Orchard shielded pool could have allowed an attacker to create an unlimited number of undetectable counterfeit ZEC tokens
AI-assisted security audit discovery
- ▪Hornby wrote a complete working exploit that generated unlimited counterfeit ZEC in a local test environment
- ▪Security engineer Taylor Hornby discovered the vulnerability on May 29, 2026, using Anthropic's Opus 4.8 AI model one day after its release
ZEC price collapse
- ▪ZEC's price fell from a high of around $635 to an intraday low of $309
- ▪The price of Zcash (ZEC) plunged by as much as 38% in the 24 hours following the public disclosure of the vulnerability
- ▪Investor Arthur Hayes announced he sold his entire Zcash position, stating the privacy thesis "demands perfection" and unresolvable supply doubt was disqualifying
Supply uncertainty debate
- ▪Bitcoin developer Peter Todd cited the incident to argue against integrating Zcash-style privacy into Bitcoin, stating the cryptographic risk profile is too high
- ▪The Zcash Foundation stated its "turnstile" mechanism confirmed no unauthorized value was created, protecting the total supply cap from inflation
- ▪Due to Zcash's privacy design, it is cryptographically impossible to determine whether the vulnerability was exploited during its four-year window
- ▪Shielded Labs proposed a network upgrade to deploy a new shielded pool with "turnstile accounting" to allow for independent supply verification
Zero-knowledge proof soundness failures
- ▪The vulnerability was a "soundness bug" in the Halo2 proving system, which allows an invalid transaction to generate a proof that passes verification
- ▪The bug went undetected through at least four rounds of review by expert zero-knowledge cryptographers
- ▪The specific flaw was an under-constrained element in the elliptic-curve multiplication gadget of the halo2_gadgets Rust crate
Emergency NU6.2 patch deployment
- ▪An emergency soft fork on June 1, 2026, temporarily disabled Orchard transactions
- ▪The patch was the second security-driven protocol upgrade in Zcash's history since its launch in 2016
- ▪A hard fork, Network Upgrade 6.2 (NU6.2), activated on June 3, 2026, deploying a corrected circuit that permanently closed the vulnerability
Story comments
Loading comments…