Martian Finance reports that on June 5, Zcash founder Zooko Wilcox disclosed a critical forgery vulnerability in the Zcash Orchard pool, which could be exploited to generate an unlimited number of undetectable forged ZEC within the Orchard pool. The vulnerability was discovered on May 29 by security researcher Taylor Hornby during a targeted audit using the Anthropic Opus 4.8 model and was reported to the Zcash Open Development Lab (ZODL). ZODL subsequently coordinated an emergency response across the Zcash ecosystem, with the fix completed on June 2. Taylor Hornby developed a complete exploit program in a local regtest environment using Opus 4.8, capable of generating unlimited, undetectable forged ZEC during testing. If deployed on the Zcash mainnet, this tool could have generated unlimited, undetectable forged ZEC in mainnet Zcash wallets. The vulnerability stemmed from an insufficiently constrained element in the Orchard circuit, allowing attackers to input arbitrary false values into elliptic curve multiplication while still passing the multiplication verification check. This flaw had existed since the Orchard protocol was activated in May 2022 until its emergency patch was deployed on June 1, 2026. Due to Orchard’s privacy properties and the nature of the vulnerability, it is currently impossible to determine through cryptographic means alone whether the flaw was exploited prior to the fix. However, Shielded Labs believes the likelihood of prior exploitation was low and is exploring a network upgrade to deploy a new privacy pool and implement turnstile accounting for all tokens in the Orchard pool, enabling anyone to verify the integrity of Zcash’s supply and prove the absence of forged ZEC within the Orchard pool. Affected by the Orchard pool vulnerability, ZEC dropped over 31% in 24 hours according to market data, trading at $410.50.
ZEC price drops over 31% following critical infinite minting vulnerability in Orchard pool
MarsBitShare






Zcash (ZEC) dropped over 31% in 24 hours after Zooko Wilcox disclosed a critical infinite minting vulnerability in the Orchard pool. On-chain analysis revealed that the flaw, discovered by Taylor Hornby on May 29, permitted unlimited counterfeit ZEC. The vulnerability, stemming from a 2022 weakness in the Orchard circuit, was patched on June 2. On-chain data confirmed the exploit risk had been active for more than two years.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.