Loading prices…
🩸BEARISH

Zcash Founder Warns of Critical Orchard Counterfeiting Vulnerability

The vulnerability was real, exploitable, and disclosed on May 29 — but Orchard’s privacy design makes it cryptographically impossible to prove the bug was never used before the June 2 patch.

Zcash founder Zooko Wilcox confirmed that security researcher Taylor Hornby discovered a critical counterfeiting vulnerability in Zcash’s Orchard shielded pool on May 29. The Zcash Open Development Lab coordinated an emergency response, with a fix completed on June 2 — roughly four days from disclosure to patch.

Shielded Labs verified the bug was real and exploitable, and demonstrated that a local test exploit could generate unlimited, undetectable counterfeit ZEC. Because Orchard’s privacy design hides transaction details, it cannot be cryptographically proven whether the flaw was ever weaponized in production before the fix. Shielded Labs has said prior exploitation was unlikely, but the inability to rule it out is the structural concern.

Why it matters

Shielded pools are Zcash’s marquee feature and the technical foundation of the “privacy coin” thesis. A counterfeiting bug at the cryptographic layer strikes at the core promise: that shielded ZEC supply can be trusted without trusting the issuer. The four-day disclosure-to-patch window was tight, but the post-mortem question — whether a sophisticated attacker could have minted coins silently before the fix — cannot be answered by the protocol itself. That uncertainty is what differentiates a patched bug from a clean one.

Market impact

Shielded Labs is exploring a network upgrade that would retroactively verify the integrity of the Orchard supply and prove no counterfeit ZEC was issued. ZEC is trading around $443, down 29% in the past 24 hours, with the drawdown coinciding with disclosure.

Related tokens
$ZEC

Frequently asked questions

  1. What exactly was the Zcash Orchard bug?

    A critical vulnerability in Zcash’s Orchard shielded pool, disclosed on May 29, that Shielded Labs confirmed was real and exploitable. A local test exploit showed it could generate unlimited, undetectable counterfeit ZEC before the fix shipped on June 2.

  2. Could the bug have been used to create fake ZEC before the fix?

    Cryptographically, no one can prove it either way. Orchard’s privacy design hides transaction details, so the protocol itself cannot verify historical supply integrity. Shielded Labs said prior exploitation was unlikely, but the uncertainty remains until a network upgrade resolves it.

  3. Who discovered the bug and who fixed it?

    Security researcher Taylor Hornby discovered the vulnerability on May 29. The Zcash Open Development Lab coordinated the emergency response, and a patch was completed on June 2 — roughly four days from disclosure to fix.

  4. Is a Zcash network upgrade planned to address the supply question?

    Shielded Labs is exploring a network upgrade that would retroactively verify the integrity of the Orchard pool and prove the non-existence of counterfeit ZEC. No timeline has been confirmed.

  5. How has ZEC reacted to the disclosure?

    ZEC was trading around $443, down 29% in the 24 hours following disclosure — a move that reflects both the technical severity of the bug and the unresolved question of whether any counterfeit ZEC entered circulation before the patch.

Source attribution
Aggregated from WuBlockchain · Verified · Last refreshed 46d ago
Open original →