Zcash Confirms Critical Vulnerability in Privacy Pool, ZEC Drops 43%

icon币界网
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
Zcash confirmed a critical vulnerability in its Orchard privacy pool that could allow attackers to mint unlimited ZEC. The flaw, discovered by Taylor Hornby on May 29, 2026, was patched on June 1. It remains unclear whether it was exploited between May 2022 and June 2026. ZEC dropped to $250, down 43% intraday. The vulnerability bypassed a key validation check, enabling the creation of forged tokens. Hornby reported the issue to ZODL without triggering it on the mainnet. Zcash plans a network upgrade featuring a new privacy pool and a turnstile accounting system to verify token legitimacy. On-chain analysis shows the flaw allowed fake ZEC indistinguishable from genuine tokens.
CoinDesk reports:

The Zcash ecosystem has confirmed a critical vulnerability in its privacy transaction pool, Orchard, that allows for the forging of an unlimited number of ZEC. The associated fix was completed on June 1. However, due to Orchard’s privacy-preserving design, it is currently impossible to verify on-chain whether the vulnerability was exploited between May 2022 and June 2026. After the announcement, ZEC dropped to around $250, recording a intraday peak decline of 43%.

Vulnerability allows bypassing validation

The vulnerability was discovered by security researcher Taylor Hornby on May 29. Hornby, commissioned by the Zcash team to conduct security research, developed a fully functional exploit code with the assistance of Anthropic’s Claude Opus.

The issue lies in Orchard's validation logic for transaction inputs. Although this check appears to verify that inputs comply with the rules, it fails to properly enforce the constraints. An attacker could construct fraudulent inputs that still pass the zero-knowledge proof verification, thereby generating ZEC out of thin air—fraudulent tokens that are indistinguishable from legitimate ones.

Repair completed

Hornby stated that he only completed verification in a local environment and immediately disclosed the issue to ZODL, responsible for coordinating Zcash development, without executing any attack on the mainnet. The Zcash ecosystem deployed an emergency patch on June 1 to prevent further exploitation of this vulnerability.

However, the team also acknowledged that the vulnerability may have been exploitable for approximately four years. The challenge lies in the fact that Orchard is a privacy pool, designed to conceal transaction amounts and participant information, which also means it is impossible to determine through cryptographic means whether covert minting occurred in the past.

The community proposes to proceed with the upgrade.

To address subsequent risks, Shielded Labs is proposing a network upgrade. The proposal includes deploying a new privacy pool and implementing a "turnstile accounting" verification mechanism for tokens from Orchard.

Following this approach, existing Orchard tokens must pass through a verifiable checkpoint to identify any forged supply. This proposal still requires community governance approval and must go through Zcash’s standard network upgrade process. A more detailed proposal is expected to be released next week.

AI auditing capabilities are gaining attention

In addition to the upgrade plan, Shielded Labs stated that it will initiate mathematical verification of the entire Orchard circuit and hire a security lead and cryptography researchers. This incident has also drawn market attention to AI's capabilities in security research.

Claude Opus 4.8 was publicly released on May 28, and researchers discovered this long-existing critical vulnerability within approximately 24 hours after the model went live. As more powerful models continue to be released, the pace of attacks and defenses facing crypto protocols may accelerate further.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.