Four Questions on the Zcash Orchard Vulnerability: Was it Exploited? Can Funds Be Recovered? Is the Supply Verifiable? Are There Others?

Odaily星球日报Publicado em 2026-06-15Última atualização em 2026-06-15

Resumo

**Summary: Zcash Orchard Vulnerability Analysis** A critical forgery vulnerability was recently discovered in Zcash's Orchard shielded pool, raising concerns about the coin's supply and user funds. The developers, led by Zcash Open Development Labs, acted swiftly to temporarily freeze the pool and deploy a fix. The article addresses four key questions: 1. **Was the vulnerability exploited?** While unknown, the developers believe it is unlikely for several reasons: the bug was difficult to find, using advanced AI tools; the fix was deployed quickly; and typical crypto exploits are fast, with no evidence of abnormal outflows. 2. **Can legitimate Orchard funds be recovered?** If the bug was not exploited, all funds are safe. If exploited, a mechanism limits total withdrawals from the pool to the amount legitimately entered, potentially blocking some legitimate funds. The developers deem this unlikely but advise cautious users to consider moving funds, noting the privacy and risk trade-offs of moving to transparent or Sapling pools. 3. **Can users verify Zcash's total supply?** Not currently. The vulnerability temporarily broke the ability for users to independently verify that no extra ZEC was created. 4. **Are there other forgery bugs?** Ongoing audits by multiple teams, including using advanced AI analysis, have so far found no others, increasing confidence. The proposed "Ironwood" network upgrade is the core solution. It will **seal** the Orchard pool, preventing ne...

Original Authors: Jason McGee, CEO of Shielded Labs, and Zooko Wilcox, Founder of Zcash

Compiled by|Odaily Planet Daily Qin Xiaofeng (@QinXiaofeng 888 )

Editor's Note: On June 5th, Beijing time, privacy project Zcash was revealed to have had a critical counterfeiting vulnerability in its new-generation privacy pool, Orchard. The Zcash token, ZEC, briefly plummeted by half, hitting a low near $250. After about ten days of developments, market panic has somewhat subsided, ZEC's price has recovered somewhat, and it returned to $500 today.

This morning, Zcash founder Zooko Wilcox once again published a lengthy post responding to market concerns. He stated that the Orchard vulnerability was likely not previously exploited, and legitimate Orchard funds can be recovered; currently, users cannot independently verify whether the Zcash supply has been inflated, but the Ironwood upgrade will seal the Orchard pool, restoring this verification capability; ongoing audits have not discovered other counterfeiting vulnerabilities, but more work is needed to be completely certain.

The following is the original text by Zooko Wilcox, compiled by Odaily Planet Daily, enjoy~

————————————

The recent Orchard vulnerability has raised important questions about Zcash's supply and the safety of user funds. The discussion has mingled several distinct issues, making it difficult to understand the actual impact of the vulnerability on users. This article attempts to separate these questions and explain what they each mean for users.

The Orchard vulnerability raises four important questions:

  1. Was the Orchard vulnerability ever exploited?
  2. Can legitimate Orchard funds be recovered?
  3. Can users verify that Zcash's supply has not been inflated?
  4. How do we know there are no other counterfeiting vulnerabilities?

Was the Orchard vulnerability ever exploited?

Unknown. We believe it's unlikely to have been exploited before, though we cannot rule it out entirely. We think the vulnerability was likely *not* exploited for three reasons:

Despite years of ongoing review by many of the world's top cryptographers and security researchers, the vulnerability was not previously discovered. Its eventual discovery was not accidental; it was found by Taylor Hornby of Shielded Labs with the explicit purpose of proactively identifying such security vulnerabilities before a malicious attacker could. Taylor used advanced AI-assisted security research techniques and custom-built tools specifically designed to find subtle flaws that others might miss. Doing this would be even more difficult for someone not deeply familiar with the Zcash codebase.

Once the vulnerability was discovered, Zcash developers (led by the Zcash Open Development Labs team) quickly coordinated with mining pools to temporarily freeze the Orchard pool and deployed a fix, thereby limiting the opportunity window for any attack.

Cryptocurrency exploits are common, and attackers typically seek to cash out as quickly as possible, especially after a vulnerability becomes public. For an attacker to profit from this vulnerability, they would need to exchange counterfeit ZEC for valuable assets, which would typically involve ZEC leaving the Orchard pool via the turnstile mechanism. If the vulnerability had been exploited before the fix, we would expect to have seen evidence by now. Historically, cryptocurrency exploits are usually "smash-and-grab" operations, not "4D chess" strategies hidden for months or years.

Can legitimate Orchard funds be recovered?

We believe so, because we believe the vulnerability was never exploited. If this assessment is correct, all legitimate Orchard funds remain fully recoverable.

On the other hand, if counterfeiting *did* occur in Orchard, the existing turnstile mechanism would limit the total amount migrated to the amount of ZEC that legitimately entered the pool. Therefore, if counterfeit funds were migrated ahead of legitimate funds, users would be unable to recover some or all of their legitimate Orchard funds.

We consider this scenario unlikely. However, for more cautious users, moving their ZEC out of Orchard is still advised. But before doing so, they should understand the following:

  • Moving funds to a transparent pool (i.e., to a t-address) reveals both the amount and the timing of the transfer, and these funds become publicly linked to that t-address.
  • Moving funds from the Orchard pool to the Sapling pool reveals the amount and timing of the transfer, but unlike moving to a t-address, it does not link these funds to a specific address or transaction history.
  • The Sapling pool relies on a trusted setup ceremony performed in 2018. Relying on the security of that trusted setup is an additional risk users should note.
  • To our knowledge, YWallet and Zkool are currently the only widely used, self-custody Zcash wallets that support the Sapling pool.
  • Moving funds to a new wallet or a custodial service introduces additional risks, including user error, software bugs, custodian risk, or other unforeseen problems.

Overall, we consider the above risks moderate. If your funds are currently in a shielded, self-custody wallet, leaving them there is a reasonable choice given our assessment that prior counterfeiting was unlikely. If you have a secure way to move them elsewhere, that could also be reasonable. Users may reasonably reach different conclusions based on their circumstances.

Can users verify that Zcash's supply has not been inflated?

Not yet. The prior existence of this vulnerability meant users could not independently verify that the ZEC circulating in the current shielded pools did not exceed the correct amount.

However, as we noted in a previous post, the Ironwood upgrade restores this capability. The diagram below illustrates why.

The proposed network upgrade addresses this by adding the guarantee that "no more unknown counterfeiting vulnerabilities exist" and by sealing the Orchard pool. New funds can no longer enter, and funds within the pool can no longer circulate. The only remaining path is to leave via the existing turnstile mechanism, which ensures that no more ZEC can leave the Orchard pool than legitimately entered it.

This change restores the ability to verify the soundness of the Zcash supply.

Currently, if counterfeit funds exist in the Orchard pool, they can continue to circulate within the pool. After the upgrade, this is no longer possible. Regardless of whether counterfeiting ever happened, anyone running a node will be able to verify that no more ZEC is in circulation than the correct amount.

Users won't need to wait for funds to migrate out of Orchard, or infer what attackers or other users might have done. The protocol itself provides a verifiable guarantee that excess ZEC cannot continue circulating within Orchard and inflating the supply.

This is important because Zcash's long-term credibility depends on users being able to independently verify the soundness of its supply. Ironwood restores users' ability to independently verify that the protocol's supply limit is being enforced.

How do we know there are no other counterfeiting vulnerabilities?

We are not yet completely certain, but we have reasons to believe there are none. Shielded Labs and multiple other teams have been carefully reviewing the Zcash protocol for additional counterfeiting vulnerabilities. This includes using a yet-to-be-released Mythos AI model to search for additional vulnerabilities, with help from Anthropic, shortly before Mythos was paused. We plan to share more details about this review and its findings in a follow-up blog post.

So far, no other counterfeiting vulnerabilities have been found. The high level of expertise, effort, and advanced AI-assisted analysis involved in this search gives us greater confidence that no similar vulnerabilities remain undiscovered.

Furthermore, we are working with projects like the Tachyon Project to provide additional assurance that there are no more counterfeiting vulnerabilities in Zcash. We will elaborate on this in future blog posts as well.

Conclusion

The Orchard vulnerability presents four important questions: Was the vulnerability exploited, can legitimate Orchard funds be recovered, can users verify that Zcash's supply has not been inflated, and are there other undiscovered counterfeiting vulnerabilities.

We believe it was likely not exploited previously, and therefore legitimate Orchard funds are recoverable and the current Zcash supply is safe. We are also increasingly confident, based on ongoing reviews by multiple independent researchers and teams, that there are no other undiscovered counterfeiting vulnerabilities. However, users currently cannot verify the safety of the Zcash supply, and they should not have to rely on our assessment—or anyone else's.

The proposed network upgrade solves this. By sealing the Orchard pool, it restores users' ability to independently verify the safety of the Zcash supply. Users no longer need to judge whether counterfeiting occurred in order to verify that the protocol's supply limits are being upheld.


Perguntas relacionadas

QAccording to the article, why is it unlikely that the Orchard forgery vulnerability was exploited before its discovery?

AThe article cites three main reasons. First, the bug evaded detection by top cryptographers for years and was only found using advanced AI-assisted tools by a dedicated researcher. Second, developers reacted swiftly to freeze the pool and deploy a fix, limiting any potential attack window. Third, crypto exploits are typically 'smash-and-grab' operations for immediate profit, and no evidence of such activity (like ZEC exiting the pool) has been observed.

QWhat action does the proposed Ironwood network upgrade take regarding the Orchard pool?

AThe Ironwood upgrade will seal the Orchard pool. This means no new funds can enter it, and funds already inside cannot circulate. The only remaining action is for funds to exit through the existing turnstile mechanism.

QHow does sealing the Orchard pool restore users' ability to verify Zcash's supply integrity?

ASealing the pool prevents any potential forged ZEC from continuing to circulate and inflate the supply. After the upgrade, anyone running a node can verify that the total ZEC in circulation does not exceed the correct amount, as no extra ZEC can remain active within Orchard.

QWhat are the potential privacy implications for a user moving funds out of the Orchard pool to a transparent (t-address) or Sapling pool?

AMoving to a transparent (t) address exposes both the transaction amount and timing, and publicly links those funds to that address. Moving to the Sapling pool exposes the transaction amount and timing, but does not link the funds to a specific address or transaction history. However, Sapling relies on a 2018 trusted setup ceremony, which is an additional security consideration.

QWhat is the current state of knowledge regarding other undiscovered forgery vulnerabilities in Zcash, as stated in the article?

AThe article states that ongoing, intensive reviews by multiple teams using high-level expertise and advanced AI analysis have not found any other forgery bugs so far. This provides increased confidence, but they cannot be completely certain until more work is done. Collaborations are underway to provide further guarantees.

Leituras Relacionadas

Wall Street's Most Famous 'Cassandra' Now Has His Sights Set on Nvidia

Michael Burry, the famed "Big Short" investor, has once again captured Wall Street's attention with a series of short positions against major tech and semiconductor stocks, most notably Nvidia. In late June and July, through his "Cassandra Unchained" newsletter, Burry disclosed short bets against Nvidia, Tesla, Applied Materials, Caterpillar, the SOXX semiconductor ETF, and later, Micron Technology. His core thesis revolves around potential distortions in the AI infrastructure boom, specifically questioning whether extended depreciation schedules (e.g., 6 years vs. a realistic 2-3 years for AI chips) by cloud giants like Microsoft and Google artificially inflate profits. He also raises concerns about possible "off-balance-sheet circular financing," where chip demand might be propped up by vendor-backed funding to clients. Nvidia's stock experienced volatility following these disclosures, briefly dipping but largely holding near Burry's reported entry points, leaving his positions roughly flat or slightly underwater as of late July. This move is part of a pattern for Burry, whose track record since his legendary 2008 bet is mixed. He has faced notable losses, such as on Tesla in 2021, while scoring on broader market turns like the 2020 pandemic crash. His methodology focuses intensely on free cash flow and scrutinizing original financial documents to spot overvaluation and structural risks, but it often struggles with timing the market. The article contrasts Burry's stance with other prominent investors. Steve Eisman, another "Big Short" figure, is not shorting Nvidia, citing strong fundamentals but expressing nervousness about sustainability. Jim Chanos agrees with the broad "accounting mismatch" concern—comparing it to the dot-com bubble—but targets financial leverage in private equity firms rather than the chip stocks themselves. While Nvidia's short interest remains relatively low at 1.3-1.4% of float, the massive stock size means absolute short losses have been significant, exceeding $5 billion earlier this year. The piece concludes that for ordinary investors, the key takeaway is not replicating specific short bets but learning from the critical frameworks these investors use: questioning rosy accounting, identifying structural vulnerabilities, and maintaining skepticism during market euphoria, even if pinpointing the exact catalyst for a downturn remains elusive.

marsbitHá 26m

Wall Street's Most Famous 'Cassandra' Now Has His Sights Set on Nvidia

marsbitHá 26m

Weekly Selection丨Epic Stock Market Volatility, Changxin Tech's IPO Reshapes Storage Landscape, Saylor Aims to Re-Anchor STRC Around September 8th

PANews Weekly Digest: Market Turmoil, Tech Breakthroughs, and Crypto Developments. The week saw significant volatility across global markets. South Korea's KOSPI index experienced extreme turbulence, including multiple trading halts, largely driven by sharp declines in AI hardware stocks like SK Hynix. In contrast, China's Changxin Xinqiao (CXC) achieved a landmark IPO with a market cap surpassing 4 trillion yuan, marking a major success for the domestic DRAM industry after a decade of losses. In the crypto and Web3 space, several key narratives emerged. AI is driving demand for new infrastructure, with projects like AI agent wallets and programmable payments gaining traction, attracting interest from firms like Coinbase. The Bitcoin mining sector is pivoting, with companies like MARA focusing on energy management as electricity becomes a core AI-era asset. Meanwhile, the RWA (Real World Assets) sector faces a "utilization puzzle," with hundreds of billions in on-chain assets remaining dormant. Notable market movements included a historic single-day surge of over 17% for the KOSPI index and a significant migration of $16.5 billion in staked ETH within the Lido ecosystem. Michael Saylor announced a target to re-peg the STRC stablecoin around September 8th. Other highlights include discussions on Ethereum's ambitious 2030 roadmap for scaling and privacy, analysis showing high protocol revenues not always translating to token price gains, and warnings from Citi about potential extreme commodity price shocks by late 2026.

marsbitHá 31m

Weekly Selection丨Epic Stock Market Volatility, Changxin Tech's IPO Reshapes Storage Landscape, Saylor Aims to Re-Anchor STRC Around September 8th

marsbitHá 31m

When the Market Begins to Question AI Capex: A Full Analysis of Q2 Earnings Reports from Five Tech Giants

In late July 2026, five major US tech giants—Alphabet, Intel, Microsoft, Meta, and Apple—released their Q2 earnings reports. While all companies exceeded revenue and profit expectations, driven by strong AI-related business growth, investor reactions diverged sharply due to concerns over escalating AI capital expenditures (capex) and their impact on free cash flow. Alphabet reported strong revenue growth and a surging cloud business, but its stock fell after announcing a doubled year-on-year capex and negative quarterly free cash flow for the first time. Intel posted its strongest revenue growth in over 15 years, but its stock experienced volatile trading after significantly raising its full-year capex guidance. Microsoft saw its stock surge after beating estimates and, crucially, lowering its capex forecast while projecting positive free cash flow. Meta faced the most severe sell-off as its profits declined despite revenue beats, with free cash flow plunging over 90% and its capex guidance raised. Apple reported record June-quarter results, but its stock plummeted after providing Q4 revenue guidance that fell short of expectations, citing supply chain constraints and forex headwinds. The overall takeaway is that the market's focus has shifted from validating AI demand to scrutinizing the timeline for returns on massive AI investments. Companies demonstrating a clearer path to managing capex and preserving free cash flow, like Microsoft, were rewarded, while those signaling continued aggressive spending faced investor skepticism.

Odaily星球日报Há 41m

When the Market Begins to Question AI Capex: A Full Analysis of Q2 Earnings Reports from Five Tech Giants

Odaily星球日报Há 41m

a16z: From Companies to DAOs, DUNA May Become the Next Generation Organizational Form

This article, "From Companies to DAOs: How DUNA Could Become the Next Organizational Form," traces the 500-year evolution of business collaboration. It begins with medieval structures like the *commenda* and Florentine *compagnia*, which exposed partners to personal risk. The modern corporation, exemplified by the Dutch East India Company (VOC), was a revolutionary leap, enabling large-scale, capital-intensive ventures by offering limited liability and reducing coordination costs. However, corporations introduced new challenges like principal-agent problems and bureaucratic overhead. The piece argues that software and internet-native protocols are now reducing these traditional overheads. Decentralized Autonomous Organizations (DAOs) emerged as a new model for coordination without centralized management. Yet, DAOs face a significant legal vacuum: they lack legal recognition, leaving members exposed to unlimited personal liability, and their tokens are vulnerable to being classified as securities under unclear regulations (e.g., the Howey Test). This has forced projects into suboptimal workarounds like offshore foundations. The article identifies the Decentralized Unincorporated Nonprofit Association (DUNA) as a potential solution. Recently legalized in states like Wyoming, the DUNA provides a legal wrapper for decentralized networks. It grants key protections—legal personality, limited liability, and perpetual existence—to a group without imposing a traditional hierarchical management structure. This allows token-holder communities to govern, hold assets, and contract as a single legal entity, aligning with their decentralized nature. While DUNA doesn't solve all governance challenges or magically resolve securities law questions, it represents a crucial step. It fills the legal recognition gap, offering a native legal form for internet-scale, decentralized collaboration and extending the separation of personal risk from organizational venture into a new domain.

marsbitHá 1h

a16z: From Companies to DAOs, DUNA May Become the Next Generation Organizational Form

marsbitHá 1h

2026 Mid-Year Report On-Chain RWA: Tokenized Stock Market Cap Doubles in a Year, But 90% of Rights Are Hollow Shells

The 2026 Mid-Year Report on On-Chain RWA highlights a significant growth in tokenized stock market capitalization, which nearly doubled from $951 million in March to $1.89 billion by July. However, the report reveals a fundamental contradiction in this "layer 2.5" ecosystem: products with the strongest legal foundation (like regulated U.S. infrastructure) lack liquidity and distribution, while freely tradable offshored wrapper products often lack substantive ownership rights. The increase is driven largely by a few products (SECZ, FGRS, STRCx) and platforms (Ondo, xStocks, Securitize collectively hold over 85% share). While distributed value across networks like Ethereum, Solana, and BNB Chain has grown, the market remains fragmented. Products referencing the same underlying asset (e.g., Apple stock) are distinct legal liabilities with different intermediaries and jurisdictional rules, offering varying degrees of legal claim. The report cautions that headline numbers are misleading, as they reflect changes in distributed token value—driven by issuance, conversions, and price movements—not pure investor inflows. True "canonical shares" with legal ownership, wide wallet distribution, institutional liquidity, and independent on-chain price discovery do not yet exist at scale. Tokenized treasuries show stronger product-market fit, and ETFs may be easier to scale than single stocks. The core takeaway is a trade-off: legal certainty versus liquidity and composability.

marsbitHá 2h

2026 Mid-Year Report On-Chain RWA: Tokenized Stock Market Cap Doubles in a Year, But 90% of Rights Are Hollow Shells

marsbitHá 2h

Trading

Spot
活动图片