Loading prices…
🩸BEARISH

Zcash soundness bug forces emergency hard fork to fix Orchard flaw

The flaw sat in the zero-knowledge circuit behind Orchard's shielded pool, was found with Anthropic's Opus 4.8, and a five-day emergency response contained it; the harder question is whether privacy…

A soundness bug inside Orchard, Zcash's newest zero-knowledge shielded pool, allowed the proof system to accept a transaction it should have rejected — the exact mechanism that, in theory, lets a counterfeiter mint unlimited ZEC off-chain. Security researcher Taylor Hornby at Shielded Labs found the flaw on May 29 during a targeted review he ran with Anthropic's Opus 4.8, released the day prior, paired with a custom AI harness. Zcash executed an emergency soft fork at block 3,363,426 on June 2 at 02:00 UTC to disable Orchard actions, then completed the NU6.2 hard fork on June 3 at 00:05 EDT at block 3,364,600, replacing the circuit and restoring full functionality in under five days from discovery.

Why it matters

Orchard is not a smart contract or a DeFi vault — it is the cryptographic core of Zcash's private transaction system, and a soundness bug at that layer is a money-layer failure, not an app-layer one. Zcash's official position is that turnstile accounting detected no unauthorized value creation and the 21 million ZEC cap remains intact. Shielded Labs takes a harder line: Orchard's privacy guarantees make it cryptographically difficult to prove the negative, and the firm is pushing a follow-on upgrade that would route existing Orchard coins back through turnstile accounting so anyone can verify supply integrity on-chain. The pattern repeats — Octane's AI found a Nethermind execution-client bug in February 2026 that could have halted local block production for roughly 38% of Ethereum validators — and an arXiv paper from January reported a 63% success rate for AI-agent exploit generation against smart contract benchmarks. AI-assisted research is now reaching consensus clients, ZK circuits, and supply rules, a threat layer most base-layer systems were not designed against.

Related tokens
$ZEC $ETH

Frequently asked questions

  1. What was the Zcash Orchard soundness bug?

    A flaw in the zero-knowledge proof circuit powering Orchard, Zcash's newest shielded pool, that allowed the proof system to accept a transaction it should have rejected — the mechanism that, on mainnet, could have generated unlimited counterfeit ZEC without detection.

  2. How did the researcher find the flaw?

    Taylor Hornby of Shielded Labs found it on May 29 during a targeted review conducted with Anthropic's Opus 4.8, released the day prior, alongside a custom AI harness and prompts that produced a working local exploit in a regtest environment.

  3. How did Zcash respond to the bug?

    Zcash executed an emergency soft fork at block 3,363,426 on June 2 at 02:00 UTC to disable Orchard actions, then completed the NU6.2 hard fork on June 3 at 00:05 EDT at block 3,364,600, replacing the circuit and restoring full Orchard functionality in under five days from discovery.

  4. Was the 21 million ZEC supply cap actually breached?

    Zcash says no — turnstile analysis found no evidence of unauthorized value creation. Shielded Labs argues the privacy properties of Orchard make that negative cryptographically hard to prove and is pushing a follow-on upgrade to route existing Orchard coins through turnstile accounting for on-chain verification.

  5. How does this connect to the broader AI-exploit trend?

    Octane's AI surfaced a Nethermind execution-client bug in February 2026 that could have halted local block production for roughly 38% of Ethereum validators, and a January 2026 arXiv paper reported a 63% success rate for AI-agent exploit generation on smart contract benchmarks. AI-assisted research is now reaching…

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 45d ago
Open original →