ZEC Co-Founder Responds to Orchard Vulnerability: No Signs of Theft, Orchard Pool to Be Sealed

Foresight NewsPublished on 2026-06-15Last updated on 2026-06-15

Abstract

ZEC Co-Founder Addresses Orchard Vulnerability: No Signs of Theft, Plans to Sunset Orchard Pool A security vulnerability was recently discovered in Zcash's Orchard shielded pool, raising key concerns. The primary questions are whether the flaw was exploited, if user funds are safe, whether users can verify the total ZEC supply, and if other similar vulnerabilities exist. Analysis suggests the vulnerability was likely not exploited prior to its discovery. It was found proactively by a researcher using specialized tools, not due to an active breach. The development team and mining pools acted quickly to contain the issue. Typical financially-motivated attacks would likely have left visible on-chain evidence, which has not been observed. User funds in Orchard are considered safe and should be recoverable, assuming no prior exploitation. If the flaw was never used, all legitimate funds can be withdrawn. The article outlines risks associated with moving funds to transparent addresses or other pools, but concludes that leaving assets in place is a reasonable option. Currently, users cannot independently verify that the total ZEC supply hasn't been inflated due to this bug. However, the planned Ironwood network upgrade is designed to resolve this. It will permanently close the Orchard pool to new deposits and internal transfers, allowing only withdrawals. This mechanism will cap total withdrawals at the amount of legitimately deposited funds, enabling anyone to cryptographically...


Authors: Zooko Wilcox, Jason McGee

Compiled by: Luffy, Foresight News


Recently, a security vulnerability was exposed in Zcash's Orchard module, raising two major concerns for the community: Is the total supply of ZEC tokens abnormal? Are user assets safe?


Current discussions intertwine several different topics, making it difficult for many to understand the actual impact of this vulnerability on ordinary users. This article will address these issues, explaining the underlying meanings one by one.


This Orchard vulnerability primarily raises four key questions:


  1. Has the vulnerability been exploited by hackers?
  2. Can users' legitimate assets stored in Orchard be withdrawn normally?
  3. Can users independently verify that the total supply of Zcash has not been artificially inflated?
  4. How can we confirm that the project does not contain other similar token forgery vulnerabilities?


Has the Vulnerability Been Exploited?


Currently, there is no definitive conclusion. Overall, the likelihood of the vulnerability being maliciously exploited previously is low, but we cannot rule it out with 100% certainty. There are three main reasons:


  • For many years, numerous top global cryptographers and security researchers have been reviewing the Zcash code, and this vulnerability remained undiscovered. This vulnerability was proactively found by Shielded Labs' Taylor Hornby during targeted investigations, not accidentally exposed. He leveraged AI-powered security detection technology and custom tools specifically designed to uncover this type of hidden flaw. Such vulnerabilities have a high technical barrier; it would be difficult for individuals not specialized in the Zcash codebase to find and exploit them.
  • Upon the vulnerability's exposure, the Zcash development team immediately collaborated with major mining pools to temporarily freeze the Orchard pool and push a fix, significantly narrowing the window of opportunity for attackers.
  • Most attacks in the cryptocurrency space aim for quick profits. Once a vulnerability is public, hackers typically cash out immediately. To profit from this vulnerability, a hacker would need to transfer the forged ZEC out of the Orchard pool and exchange it for other assets. Such operations generally leave traces. If the vulnerability had been exploited long ago, evidence should have emerged by now. Throughout industry history, hackers' modus operandi is typically "strike and disappear quickly," not deliberately hiding for months or even years.


Can Legitimate Assets in Orchard Be Withdrawn?


We believe they can be withdrawn normally, provided the vulnerability has never been exploited. If this assessment holds true, all legitimate assets users have deposited into Orchard can be successfully transferred out.



Conversely, if hackers have already used the vulnerability to create counterfeit tokens and transferred them into the pool, the existing withdrawal channels would cap the total withdrawal amount. The withdrawal limit would equal the total amount of legitimate tokens initially deposited. In this scenario, if counterfeit tokens are withdrawn first, some users' legitimate assets might not be fully recovered.



We consider the likelihood of this extreme scenario to be low. If users still have concerns, they can move their assets out of the Orchard pool. However, before doing so, it's important to understand the potential risks of different withdrawal methods:


  • Transferring to a transparent address (t-address): The transfer amount and time will be fully public, and the assets will become publicly associated with that address, completely losing privacy.
  • Transferring to the Sapling shielded pool: The transfer amount and time will still be recorded, but it won't link the assets to a specific address or transaction history, offering better privacy than transparent addresses. Note that Sapling relies on a trusted setup ceremony completed in 2018, which itself carries additional security considerations.
  • Wallets: Among mainstream self-custody wallets, currently only YWallet and Zkool support the Sapling pool.
  • Other wallets or custodial platforms: There may also be risks of operational errors, software faults, platform risk controls, and other unexpected issues.


Overall, these risks are manageable. Combined with the assessment that "the vulnerability was most likely not exploited," keeping assets in the original shielded wallet is a prudent choice. If users can ensure operational safety, withdrawing assets is also a viable option. Users should decide based on their individual circumstances.


Can Users Independently Verify That Zcash's Total Supply Has Not Been Inflated?


Currently, this is not possible. Due to the existence of this vulnerability, ordinary users cannot independently verify whether the total token supply within the shielded pools has been inflated.



However, the planned Ironwood network upgrade will address this issue. The logic is as follows:



This upgrade will permanently close the Orchard pool, disallowing new asset deposits. Tokens within the pool will no longer be able to move internally; all assets can only be withdrawn through the original channels. The total withdrawal amount from these channels strictly equals the amount of legitimate tokens originally deposited, fundamentally preventing any excess outflow of tokens.


After the upgrade is complete, anyone running a node will be able to verify that the total token supply is compliant. Even if counterfeit tokens were created in the past, they will no longer be able to circulate within the Orchard pool, artificially inflating the total supply. Users won't need to speculate about the actions of hackers or other users; the protocol itself will guarantee that token over-issuance cannot occur.


This point is crucial. Zcash's long-term credibility is built on users' ability to independently verify the total token supply. The Ironwood upgrade will restore this capability to users.


How to Confirm the Project Has No Other Token Forgery Vulnerabilities?


At this stage, we cannot give an absolute answer, but we have reason to believe no similar vulnerabilities currently exist.


Shielded Labs, in collaboration with several teams, conducted a comprehensive review of the Zcash protocol, specifically searching for token forgery vulnerabilities. During this process, the team also utilized Anthropic's not-yet-publicly-released Mythos AI model for auxiliary detection. We will publish a follow-up article detailing the process and results of this review.


To date, the team has not discovered any new forgery vulnerabilities. This review assembled experienced technical personnel, professional security teams, and advanced AI analysis tools, which further strengthens our confidence that there are currently no undisclosed high-risk vulnerabilities of the same type.


Simultaneously, we are collaborating with partners like the Tachyon project to conduct additional inspections, further strengthening our security defenses. Related progress will also be announced later.


Summary


This Orchard vulnerability raises four core questions: whether the vulnerability was exploited, whether legitimate assets can be withdrawn, whether the total token supply can be verified, and whether other forgery vulnerabilities exist.


Based on the current investigation results, we assess that the likelihood of the vulnerability being exploited previously is low. Therefore, user assets are safe, and the total token supply currently remains normal. After repeated inspections by multiple independent teams, we are increasingly confident that the project currently has no other undiscovered forgery vulnerabilities.


However, one point is unavoidable: currently, users cannot independently verify the total token supply. The upcoming network upgrade will completely solve this problem. After the upgrade, the Orchard pool will be permanently closed, allowing users to independently verify the total token supply without needing to judge whether token forgery has ever occurred.

Related Questions

QWhat are the four key questions raised by the Orchard security vulnerability?

AThe four key questions are: 1) Has the vulnerability been exploited? 2) Can legitimate user assets stored in Orchard be withdrawn normally? 3) Can users independently verify that the total Zcash supply has not been artificially increased? 4) How can we confirm there are no other similar token counterfeiting vulnerabilities in the project?

QWhat is the primary reason why the authors believe the Orchard vulnerability likely hasn't been exploited?

AThe authors believe exploitation is unlikely primarily because the vulnerability was discovered through proactive investigation by Shielded Labs using specialized AI detection tools, not due to a public exposure. They argue that exploiting it requires deep expertise and that typical cryptocurrency attackers would likely have cashed out already, leaving detectable traces, which haven't been observed.

QHow does the planned Ironwood network upgrade aim to restore users' ability to verify the Zcash supply?

AThe Ironwood upgrade will permanently close the Orchard pool, preventing new deposits and internal transfers. All assets can only be withdrawn via the original channels, whose total withdrawal amount is strictly capped at the amount of legitimate tokens originally deposited. This prevents any excess tokens from leaving the pool, allowing anyone running a node to verify the total supply compliance.

QWhat risks do users face if they choose to transfer their assets out of the Orchard pool?

ATransferring to a transparent address (t-address) reveals the amount, timing, and links the assets to that address, losing all privacy. Transferring to the Sapling pool offers better privacy but relies on a 2018 trusted setup ceremony, which introduces its own security considerations. Additionally, users may face risks from operational errors, software bugs, or platform restrictions when using wallets or custodial services.

QWhat measures have been taken to search for other potential token counterfeiting vulnerabilities in Zcash?

AShielded Labs, in collaboration with other teams, conducted a comprehensive audit of the Zcash protocol specifically for token counterfeiting vulnerabilities. They utilized advanced tools including an unreleased AI model from Anthropic called Mythos. So far, no new such vulnerabilities have been found, increasing confidence that no other high-risk, undisclosed vulnerabilities of this type exist.

Related Reads

As the US and Japan Hike Interest Rates, Which Asset Class is Most at Risk?

This week, global markets face two major events: the Bank of Japan's likely interest rate hike and the US Federal Reserve's FOMC meeting. For risk assets, it is a pivotal and volatile week. In the US, expectations for rate cuts have faded dramatically. May's higher-than-expected CPI and resilient jobs data have shifted the Fed's focus from potential cuts to the possibility of future hikes. New Fed Chair Wash is unlikely to raise rates at this meeting, but any hawkish shift in communication, the dot plot, or the policy statement could lead markets to price in tighter policy, pushing up short-term Treasury yields and strengthening the dollar. High-valuation growth stocks, AI-related assets, and small-cap stocks reliant on cheap funding are most vulnerable to rising rates. In Japan, a 25 basis point hike is almost fully priced in (98.3% probability), which would bring the policy rate to 1%, its highest since 1995. The concern is not the hike itself, but its potential to unwind the massive "carry trade," where investors borrowed low-yielding yen to invest globally. Historically, Japan's rate hikes have coincided with global market stress (2000, 2007, 2024). While this well-telegraphed hike may be digested smoothly, two key factors increase uncertainty: 1) Governor Ueda's absence due to illness, putting communication in the hands of less-familiar deputies, and 2) the Fed meeting occurring just days later, creating potential for a compounded market reaction if both central banks sound hawkish. Asset implications: * **Bonds:** US short-term yields sensitive to Fed signals. Japan's rate hike could pressure its massive US Treasury holdings. * **Currencies:** Dollar likely supported by Fed; Yen's reaction hinges on BoJ's forward guidance. * **Equities:** US growth stocks, small-caps most at risk. Japanese stocks face pressure from a stronger yen. * **Crypto:** Assets like Bitcoin face headwinds from higher rates and tighter liquidity; high-beta altcoins are even more vulnerable. The convergence of these two central bank meetings amplifies market volatility risks, with potential spillovers across asset classes globally.

marsbit9m ago

As the US and Japan Hike Interest Rates, Which Asset Class is Most at Risk?

marsbit9m ago

Data Decrypts the BTC Cycle: Three Major Bottom Signals Illuminate Simultaneously, Q4 Could Be a Crucial Turning Point Window?

"Decoding the Bitcoin Cycle: Three Bottom Signals Flash Simultaneously, Is Q4 the Key Turning Point?" The article analyzes Bitcoin's current market position, comparing it to historical cycles. BTC has corrected over 52% from its October 2025 peak of $126,198 to around $59,100 in June 2026. While significant, this drawdown is milder than the 77-86% declines seen in past bear markets. The analysis is framed within Bitcoin's four-year halving cycle. Past cycles show a pattern: prices peak 12-18 months post-halving, bottom 12-14 months after the peak, with lows typically occurring roughly 17 months before the next halving. Following the April 2024 halving and the October 2025 peak, this pattern suggests a potential bottoming window around Q4 2026, ahead of the expected 2028 halving. Three key on-chain metrics are signaling undervaluation: The MVRV Z-Score has dropped near 0.27, approaching historic bottom zones. The market price is only about 9% above the network's average realized price of ~$53,600, a rare low premium. Bitcoin's price recently touched its 200-week moving average (~$62,200), a level that aligned with bottoms in 2015, 2018, and 2020. While US spot Bitcoin ETFs saw record outflows in May/June 2026, indicating retail panic, whale addresses (holding 100+ BTC) reached a yearly high. Entities like MicroStrategy resumed buying, and long-term holders control a near-record 78% of the supply, suggesting accumulation. A major macro overhang was partially removed with a US-Iran ceasefire agreement in mid-June 2026, which eased oil prices and triggered a sharp BTC rally. However, persistent inflation means high-interest rates remain a constraint. The conclusion notes that genuine investment opportunities often arise when confidence is lowest, amidst narratives that "this time is different." While not guaranteeing an immediate bottom, the confluence of cycle timing, undervaluation signals, and shifting macro risks suggests late 2026 may be a critical period for reassessing risk/reward and patient accumulation for long-term believers.

marsbit9m ago

Data Decrypts the BTC Cycle: Three Major Bottom Signals Illuminate Simultaneously, Q4 Could Be a Crucial Turning Point Window?

marsbit9m ago

The Shutdown of Claude Mythos Revealed the True Cost of Renting AI to Me

The sudden shutdown of Claude Mythos this week starkly highlights a critical, often overlooked risk for founders: when your core capability relies entirely on someone else's platform, your fate is not in your own hands. The key question becomes: who truly owns the intelligence your product depends on? For years, the debate around open-source models focused on cost. Now, the evidence is clear: fine-tuned open-source models can achieve frontier-level quality for specific, mission-critical tasks at a fraction of the cost. However, the deeper issue is control. Relying on a third-party API is like renting; it works until the landlord changes the rules, raises the rent, or asks you to leave—as Mythos experienced. The lesson is not to stop using frontier models—they are incredible infrastructure. The goal is ownership. Ownership means starting with a powerful open-source model and shaping it around what makes your company unique: your data, workflows, domain expertise, and definition of "good." Over time, the model becomes less generic and more reflective of your business, creating durable value. The optimistic conclusion is that AI's future doesn't hinge on one superior model. There is no single frontier. The frontier includes proprietary models, models fine-tuned on company-specific knowledge, specialized models for narrow problems, and intelligent routers orchestrating model ensembles. The most interesting development is not models getting smarter, but intelligence becoming increasingly customizable. The winning companies will be those that transform intelligence into a unique, owned asset. Looking ahead, the vision is not one model dominating all, but many teams owning the part of the frontier that matters most to them.

marsbit57m ago

The Shutdown of Claude Mythos Revealed the True Cost of Renting AI to Me

marsbit57m ago

Tiger Research: U.S. Strategic Bitcoin Reserve - Should the Market Be Happy or Disappointed?

Tiger Research analyzes the evolution of U.S. legislative efforts regarding a strategic Bitcoin reserve, concluding the market impact is limited in the short term but potentially positive long-term. The core event was a March 2025 executive order by former President Trump, which designated confiscated Bitcoin as a strategic reserve and promised not to sell existing holdings (approx. 190k BTC). As it contained no mandate to purchase new Bitcoin, the market reacted negatively, with prices dropping 5.7%. Legislative history shows a significant retreat from initial ambitions. The 2024 "BITCOIN Act" proposed mandatory purchases of 1 million BTC over five years. Reintroduced in 2025, it stalled due to high fiscal costs, concerns over dollar hegemony, and opposition from the Treasury Secretary. The current frontrunner, the 2026 "American Retirement and Monetary Advancement (ARMA) Act," is a compromise. It lacks any purchase requirement, instead focusing on consolidating existing government-held Bitcoin and legally prohibiting its sale for at least 20 years. While ARMA has higher passage odds due to bipartisan support and no purchase mandate, its immediate market effect is neutral. It eliminates potential government selling pressure but creates no new demand. The long-term significance is that formally establishing Bitcoin as a national reserve asset in law could later reignite debates on mandatory purchases. Therefore, the path to a government buyer is longer than initially priced by the market, but the directional narrative remains intact.

marsbit59m ago

Tiger Research: U.S. Strategic Bitcoin Reserve - Should the Market Be Happy or Disappointed?

marsbit59m ago

Trading

Spot
Futures

Hot Articles

How to Buy ZEC

Welcome to HTX.com! We've made purchasing Zcash (ZEC) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Zcash (ZEC) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Zcash (ZEC)After purchasing your Zcash (ZEC), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Zcash (ZEC)Easily trade Zcash (ZEC) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

3.4k Total ViewsPublished 2024.03.29Updated 2026.06.02

How to Buy ZEC

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ZEC (ZEC) are presented below.

活动图片