"Unlimited Money Printing" Bug Lurked for Four Years, Privacy Coin ZEC Plummets 50% in One Day

Odaily星球日报Publicado a 2026-06-05Actualizado a 2026-06-05

Resumen

A critical "unlimited, undetectable counterfeit" vulnerability existed for nearly four years in the Orchard privacy pool of Zcash (ZEC), a privacy-focused cryptocurrency. The bug, which could theoretically allow attackers to create unlimited fake ZEC, was disclosed by founder Zooko Wilcox on June 5th. While officially patched and deemed low-probability for exploitation, the news triggered a market panic. ZEC's price plummeted over 50% in a single day. The core crisis stems from the inability to prove whether any counterfeit ZEC was created during the vulnerability's active period, as Orchard's design inherently hides transaction details. This casts severe doubt on ZEC's total supply integrity. The sell-off accelerated after prominent investor and ZEC narrative supporter Arthur Hayes announced he had sold his entire position, citing the inability to cryptographically prove the impossibility of extra minting. Community trust eroded further upon learning the bug was discovered with AI-assisted auditing, raising questions about Zcash's development and security review processes. The incident has evolved from a price correction into a fundamental crisis of confidence regarding the network's core security promises.

Original | Odaily Planet Daily (@OdailyChina)

Author | Asher (@Asher_0210)


In the early hours of June 5th, Zcash founder Zooko Wilcox published a statement confirming that Orchard, Zcash's next-generation privacy pool enabled in 2022, once contained a critical counterfeiting vulnerability. Although Zcash officials emphasized that the bug has been fixed and believe the probability of its exploitation is low, it still couldn't stop the spread of market panic.

After the news broke, the Zcash token ZEC quickly nosedived, plummeting over 30% in a short time; by the afternoon, the sell-off didn't stop, panic continued to spread, and the price once fell to around $250, with the intraday loss widening to over 50%.

Security researcher Taylor Hornby discovered the issue on May 29th and has completed vulnerability verification in a local environment, generating test counterfeit ZEC, further validating that the vulnerability is an executable attack path. Currently, the two biggest controversies surrounding Zcash are: First, whether counterfeit ZEC has ever appeared in the privacy pool over the past four years; Second, how can officials prove that no counterfeit ZEC has flowed into the privacy pool, an extremely difficult task to disprove.

Where Did the "Unlimited Minting" ZEC Come From?

The security of Orchard (Zcash's privacy-protecting "shielded pool") relies on zero-knowledge proof circuits, with the core rule being asset conservation: the spend of each transaction must come from legitimate inputs, and ZEC cannot be created out of thin air. Users can hide balances and transaction amounts, but the system must verify the transaction's legitimacy.

Security researcher Taylor Hornby discovered that a constraint in the Orchard circuit was incomplete (under-constrained), allowing attackers to input data that should not have passed, yet verification could still return as successful. In other words, without needing administrator privileges or controlling nodes, and not being a backdoor, as long as the system mistakenly deems a transaction legitimate, originally non-existent ZEC could be recorded as legitimate assets within Orchard.

Shielded Labs called it "unlimited, undetectable counterfeit ZEC".

The Bug is Fixed, but Historical Issues Remain Unresolved

For ordinary security incidents, the biggest fear is large losses, but the most troublesome aspect of Zcash's current crisis is that the losses cannot be directly quantified.

If an attack occurred on the transparent chain, the market could at least see the attack address, fund flows, and affected assets. However, Orchard's transaction amounts, balances, and fund paths are inherently hidden. Once counterfeit ZEC might have appeared in the pool, it's difficult for outsiders to judge whether it's still lingering in Orchard or has gradually flowed out through normal transactions.

More critically, Orchard is not a completely isolated black box. Users can migrate assets between different fund pools, and both real ZEC and potential counterfeit ZEC could mix within the pool.

The Zcash ecosystem can emphasize that there is currently no evidence of the vulnerability being exploited and can explain that the probability of malicious exploitation is low. But for traders, "no anomalies have been found" and "it has been proven that nothing happened" are not the same thing.

This is the core reason for ZEC's expanding decline. Until the question of whether counterfeit ZEC ever appeared in Orchard is proven, ZEC's supply credibility will remain under a shadow.

Arthur Hayes Liquidates Position, Igniting Market Confidence Crisis

After the ZEC vulnerability was exposed, BitMEX co-founder Arthur Hayes's public liquidation further amplified market panic.

Arthur Hayes stated on platform X that he has sold his entire ZEC holdings. Hayes said he learned about the attack yesterday but did not realize its conflict with his narrative framework. ZEC's 30% drop prompted him to reconsider and decide to take full profits on that position. He added that while he believes the possibility of additional minting is extremely low, he cannot formally prove its impossibility at the cryptographic level; he will continuously reassess his judgment and, if his assumption is disproven, will repurchase, hoping to build a position at a lower price; privacy is priceless, and he wouldn't mind repurchasing at a higher price.

This was quite damaging for ZEC. Over the past period, Arthur Hayes has been one of the key narrative drivers for ZEC. His bullish view was based on the long-term logic of privacy assets regaining pricing power in the context of AI, government surveillance, and big tech expansion. Therefore, his liquidation wasn't just a major holder taking profits; it resembled a public downgrade of ZEC's current narrative.

When a top narrative supporter chooses to exit first, long positions originally supported by belief and expectations are more likely to turn into collective profit-taking and risk aversion.

Community Sentiment Spiral, ZEC Transforms from Price Correction to Trust Crisis

Perhaps influenced by Arthur Hayes's liquidation, community discussions about ZEC quickly shifted from "whether to buy the dip" to "whether it can still be trusted."

On one hand, the community repeatedly emphasized the severity of the vulnerability itself. Compared to short-term price drops, many users were more concerned that a vulnerability theoretically capable of creating unlimited counterfeit coins had lurked in Orchard for nearly four years. For them, the price drop was just the surface; what truly shook confidence was the question mark placed on Zcash's core security assumptions.

On the other hand, the process of AI-assisted vulnerability discovery further exacerbated distrust. Taylor Hornby, with the aid of AI tools, conducted a targeted review of the Orchard circuit, ultimately discovered the vulnerability, wrote an exploit program, and generated counterfeit ZEC in a local environment. Although AI did not perform the audit independently, what the community more easily remembered was the narrative that "a key vulnerability existing for years was assisted in being found by AI in a short time," which quickly gained traction.

This turned public criticism towards Zcash's development and audit systems. The community questioned why a vulnerability existing since 2022 could go undetected on the mainnet for years? If even the core privacy pool could have constraint omissions, how can users trust Zcash's promises on supply and privacy security again?

Therefore, this decline is no longer just profit-taking. Before Zcash provides more convincing proof, no one is really willing to hold ZEC long-term.

Criptos en tendencia

Lecturas Relacionadas

This Strategy Earned Hefei One Trillion Yuan

This article analyzes the "Hefei Model" that enabled a municipal state-owned investment to generate paper profits exceeding one trillion yuan through the 2026 IPO of ChangXin Memory Technologies (CXMT). It argues against framing this success as a "lucky gamble," instead presenting it as the result of a deliberate institutional system designed to enable long-term industrial investment. The system comprises three core components. First, a **quantified risk-tolerance mechanism**, including a 40% loss allowance for venture funds and a clear "duty-fulfilled exemption" list, decouples project failure from personal career risk for decision-makers, allowing them to focus on industrial potential rather than personal liability. Second, **strategic investment in critical supply chain gaps**: Hefei doesn't just invest in "good" projects, but targets "missing" links essential for its key industries (appliances, displays, cars). The investment in CXMT aimed to fill the critical DRAM memory chip gap, subsequently attracting over 450 upstream and downstream firms and creating a full semiconductor cluster. Third, **institutional authorization for counter-cyclical investment**: Protected by the risk-tolerance framework, Hefei supported CXMT with increased investment during the 2023 global memory industry downturn, enabling it to scale production and capitalize on the 2025 AI-driven demand surge. The article concludes that the true lesson is not the specific investment but building the institutional infrastructure—quantified risk tolerance, deep industry chain analysis, and counter-cyclical mandates—that makes such long-term, strategic bets possible. It notes the final challenge is perfecting the exit mechanism to complete the investment cycle and transform paper gains into sustainable fiscal returns and reinvestment capacity.

marsbitHace 14 min(s)

This Strategy Earned Hefei One Trillion Yuan

marsbitHace 14 min(s)

Silicon Valley VC's On-the-Ground Observations of Chinese Entrepreneurship: A Harsher Capital Environment Breeding Fiercer Companies

A Silicon Valley VC's on-the-ground observations of China's startup ecosystem reveal a harsher capital environment forging more aggressive and execution-driven companies. Unlike Silicon Valley's patient capital focused on long-term growth, China's venture landscape is characterized by intense pressure for exits. Startups often face "equity in name, debt in reality" terms with strict timelines and personal founder liability, pushing IPO as the nearly mandatory exit path due to a virtually non-existent M&A market. This high-stakes system, while potentially fostering short-termism, cultivates extreme cost discipline, rapid execution, and formidable commercialization skills—traits evident as these companies expand overseas. The funding ecosystem comprises three main pools: local RMB funds (often government-backed with economic development mandates), domestic USD funds (more founder-friendly, like Sequoia China), and dwindling direct foreign capital. Financial Advisors (FAs) play a crucial intermediary role, packaging deals and navigating China's opaque, relationship-based business networks where platforms like LinkedIn haven't taken root. Underpinning it all is significant state influence through industrial policy, directing capital and incentives toward strategic sectors like semiconductors and AI. The result is a distinct, parallel innovation model—less forgiving than Silicon Valley's, but capable of concentrating resources, accelerating iteration, and producing fiercely competitive companies in targeted industries.

marsbitHace 19 min(s)

Silicon Valley VC's On-the-Ground Observations of Chinese Entrepreneurship: A Harsher Capital Environment Breeding Fiercer Companies

marsbitHace 19 min(s)

SharpLink's Helm: Buying Only, Never Selling, Making ETH Generate Profits Through the Cold Winter

SharpLink co-CEO Joseph Chalom shares his bullish outlook on Ethereum during the recent "Injective Summit 2026." Despite prevailing negative market sentiment, Chalom argues that fundamentals and data tell a different story: Ethereum dominates with over 50% of stablecoin transaction volume, nearly 60% of tokenized real-world assets (RWA), and remains the uncontested leader in DeFi. He attributes the communication gap and lack of confidence partly to the Ethereum Foundation's restructuring. In response, SharpLink, alongside ConsenSys and Bitmain, is funding three key spin-off teams from the Foundation: ETH Labs (for institutional-scale scalability), Ethereum Institutional (for business development and marketing), and EthSystems (for next-gen privacy and compliance solutions). Chalom emphasizes these are critical for accelerating institutional adoption. Regarding SharpLink's strategy, Chalom details a conservative, yield-focused approach. The firm holds 886,725 ETH, acquired with zero leverage or debt. They generate revenue by staking ETH and strategically deploying capital into DeFi protocols via a dedicated fund, aiming for returns above the native staking yield. This contrasts with some Bitcoin-focused firms that have become net sellers. On the broader institutional adoption of tokenization, Chalom sees current progress as just the beginning. He breaks it down into layers: stablecoins as the currency/value layer, tokenized assets as the exposure layer, and DeFi as the execution layer. He predicts regulatory clarity, like the potential Clarity Act, will be a major catalyst. A key future inflection point will be when fiduciary managers prefer tokenized, 24/7 tradable digital assets over traditional "analog" versions due to their programmability and instant settlement. In conclusion, Chalom positions SharpLink not just as an ETH accumulator and yield generator, but as an active "ecosystem steward," funding essential development and marketing initiatives to support Ethereum's long-term growth, which he believes is directly aligned with shareholder interests.

Odaily星球日报Hace 20 min(s)

SharpLink's Helm: Buying Only, Never Selling, Making ETH Generate Profits Through the Cold Winter

Odaily星球日报Hace 20 min(s)

Ten European Banks Launch Blockchain Initiative RL1

On July 28, 2026, ten European financial institutions launched the Regulated Layer One (RL1) initiative. This open, neutral, and compliance-focused blockchain network is specialized for institutional digital asset operations. The founding members include ABN AMRO, Cecabank, Chartered Investment, Crédit Mutuel Alliance Fédérale, DekaBank, DZ BANK, LBBW, Natixis CIB, SC Ventures, and Seturion, formed as a European cooperative society (SCE) and led by Henning Voelkel, former head of SWIAT. The network is open to new participants, with NatWest currently in discussions to join. RL1 is built on the SWIAT blockchain, which will remain its software and services provider. The underlying SWIAT network, operational for three years, has processed 50 transactions totaling €700 million. The initiative is described as a collective European effort to create a foundation for a shared, openly and trustworthily managed distributed ledger. Its primary goal is to overcome fragmentation in the regulated financial sector by establishing a neutral, participant-owned, pan-European DLT infrastructure for tokenized assets, digital money, and next-generation financial services. The move responds to growing EU demand for scalable real-world asset (RWA) infrastructure, evidenced by projects like Pontes and Appia. This launch aligns with broader sector growth expectations, including Standard Chartered's forecast for DeFi and RWA market capitalization to reach $2 trillion.

cryptonews.ruHace 25 min(s)

Ten European Banks Launch Blockchain Initiative RL1

cryptonews.ruHace 25 min(s)

Trading

Spot

Artículos destacados

Cómo comprar ZEC

¡Bienvenido a HTX.com! Hemos hecho que comprar Zcash (ZEC) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar Zcash (ZEC) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu Zcash (ZEC)Después de comprar tu Zcash (ZEC), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear Zcash (ZEC)Tradear fácilmente con Zcash (ZEC) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

394 Vistas totalesPublicado en 2024.12.12Actualizado en 2026.06.02

Cómo comprar ZEC

Discusiones

Bienvenido a la comunidad de HTX. Aquí puedes mantenerte informado sobre los últimos desarrollos de la plataforma y acceder a análisis profesionales del mercado. A continuación se presentan las opiniones de los usuarios sobre el precio de ZEC (ZEC).

活动图片