The Zcash Foundation released Zebra 4.5.3 and 5.0.0 to patch a critical soundness bug in the Orchard Action circuit. Zebra 4.5.3 deployed an emergency soft fork at mainnet block height 3,363,426 that temporarily disabled Orchard actions, while Zebra 5.0.0 activated the NU6.2 hard fork at block 3,364,600 and re-enabled Orchard with the corrected circuit.
The Foundation said the vulnerability was caught before any known exploitation, with no evidence of unauthorized value creation. User privacy was unaffected, and Sapling and transparent transactions continued to operate normally. Zebra node operators are strongly urged to upgrade to 5.0.0.
Why it matters
A soundness bug in a shielded-pool circuit is the worst-case category for a privacy chain — an attacker exploiting it could mint ZEC outside the protocol's rules without detection, silently breaking the supply cap the entire asset rests on. That the Foundation coordinated a mainnet soft fork to freeze the affected circuit, then pushed the fix through a scheduled hard fork roughly 1,200 blocks later, is the textbook response: halt first, patch second, no drama in between.
Market impact
$ZEC price action was muted through the disclosure, and the lack of any known exploit removes the near-term tail risk that usually follows a shielded-pool vulnerability. The longer read is for other privacy-coin teams: the window between soft-fork freeze and hard-fork reactivation is now a worked template for how to handle a circuit-level bug without compromising user funds or chain history.
Frequently asked questions
-
What was the Zcash Orchard bug?
A critical soundness bug in the Orchard Action circuit that, if exploited, could have allowed unauthorized value creation outside the protocol's rules. The Zcash Foundation says it was caught before any known exploitation.
-
How did the Zcash Foundation fix the Orchard vulnerability?
It shipped Zebra 4.5.3, which deployed an emergency soft fork at mainnet block 3,363,426 to temporarily disable Orchard actions, followed by Zebra 5.0.0, which activated the NU6.2 hard fork at block 3,364,600 and re-enabled Orchard with the corrected circuit.
-
Was any ZEC stolen or minted in the Orchard bug?
No. The Zcash Foundation said there is no evidence of unauthorized value creation and that the vulnerability was caught before any known exploitation.
-
Did the Orchard bug affect Zcash user privacy?
No. User privacy was unaffected, and Sapling and transparent transactions continued to operate normally throughout the incident.
-
Do Zcash node operators need to upgrade?
Yes. The Zcash Foundation is strongly urging Zebra node operators to upgrade to Zebra 5.0.0 to receive the corrected Orchard circuit and stay on the post-NU6.2 chain.
WuBlockchain