A security researcher hired by Shielded Labs uncovered a critical vulnerability in Zcash's Orchard shielded transaction pool that could have been exploited to mint "unlimited, undetectable counterfeit ZEC," the organization disclosed Thursday. Engineer Taylor Hornby found the flaw on May 29 using Anthropic's newly released Opus 4.8 model after a months-long review of the protocol, and the bug was patched on June 1 — but it had been live since Orchard activated in May 2022.
The vulnerability stemmed from an "under-constrained" element of the Orchard zero-knowledge circuit, which made it possible to feed arbitrary false inputs into an elliptic-curve multiplication and still pass proof verification. Hornby built a complete exploit and confirmed it in a local regtest environment, Shielded Labs said. Zcash (ZEC) fell 31% to $409.64 in the 24 hours after the disclosure, with most of the drop concentrated in the five hours following the post.
Why it matters
Orchard is Zcash's flagship privacy primitive — the shielded pool that lets users send and receive ZEC with full zero-knowledge confidentiality. A bug in its circuit is not a peripheral software defect; it is a flaw in the cryptographic core that guarantees the pool's supply integrity. The disclosure lands as Zcash developers have been working to reinvigorate the protocol after years of declining usage share, and the optics of a near-three-year-old flaw in the privacy stack are likely to weigh on that narrative regardless of the patch timeline.
The discovery also marks one of the first high-profile instances of a frontier AI model being used to crack production-grade zero-knowledge cryptography. Hornby paired Opus 4.8 with a custom-built harness and prompt engineering — a workflow that, by Shielded Labs' own framing, may have outraced malicious actors who now have access to the same tools.
Market impact
The 31% price slide is the sharpest single-day move ZEC has registered in recent memory and reflects the market treating disclosure of an unexploited-but-exploitable supply-integrity bug as a near-miss rather than a clean save.
Frequently asked questions
-
What was the Zcash Orchard vulnerability?
A flaw in Zcash's Orchard zero-knowledge circuit allowed arbitrary false inputs to an elliptic-curve multiplication to pass proof verification, which Shielded Labs said could have been exploited to mint "unlimited, undetectable counterfeit ZEC" in the shielded pool.
-
How long was the Zcash bug live before it was patched?
The vulnerability was present since Orchard activated in May 2022 and was not patched until June 1, 2026 — nearly four years after the shielded pool went live.
-
Who discovered the Zcash vulnerability and how?
Security engineer Taylor Hornby, hired by Shielded Labs to review the protocol, found the bug on May 29 using Anthropic's Opus 4.8 model paired with a custom-built AI harness and prompt engineering.
-
Was the Zcash vulnerability actually exploited before the patch?
Shielded Labs said exploitation before discovery is unlikely because the flaw sat under the radar of top cryptographers for years, but the privacy properties of Orchard make any historical exploitation difficult to rule out.
-
What is Zcash proposing to do in response to the bug?
Shielded Labs is exploring a network upgrade that would allow anyone to verify the integrity of Zcash's supply, deploy a new shielded pool, and enforce turnstile accounting on all coins in the Orchard pool.
TheBlock