Independent security researcher Taylor Hornby discovered a critical double-spending vulnerability in Zcash's Orchard shielded pool on May 29, 2026. Developers executed a two-stage fix: an emergency soft fork on June 2, 2026 halted Orchard activity at block 3,363,426, then the NU6.2 network upgrade on June 3, 2026 permanently restored functionality using a corrected cryptographic circuit. The Zcash Foundation urged node operators to upgrade to Zebra 5.0.0. No exploitation occurred.
Jun 6, 2026 · 8 sources
May 7, 2026 · 6 sources
Apr 13, 2026 · 2 sources
Jun 5, 2026 · 6 sources
Story comments
Loading comments…