Behind ZEC's Over 30% Plunge: An 'Unlimited Minting' Vulnerability with No Way to Prove if It Was Ever Exploited

marsbitОпубликовано 2026-06-05Обновлено 2026-06-05

Введение

A critical vulnerability was discovered in Zcash's Orchard privacy pool, allowing for the theoretical creation of undetectable counterfeit ZEC. Researcher Taylor Hornby found the flaw on May 29th, 2024, within the Orchard circuit's cryptographic constraints, which could let an attacker bypass asset conservation rules. Although a rapid emergency fix was deployed within days via a coordinated soft and hard fork, a core uncertainty remains: due to Orchard's privacy features, it is impossible to cryptographically prove whether this "unlimited mint" flaw was exploited in the nearly four years since the pool's 2022 launch. This uncertainty, rather than the patched flaw itself, triggered a market panic, causing ZEC's price to drop over 30%. While the Zcash Foundation stated no evidence of exploitation was found, independent entity Shielded Labs emphasized the impossibility of definitively proving no counterfeit ZEC was ever created. The incident highlights the unique trust challenge in privacy systems. To address this, developers are proposing a new network upgrade with enhanced auditing to allow verifiable proof of supply integrity. Notably, the researcher utilized the newly released AI model Claude Opus 4.8 as a tool during the security review, signaling the growing role of advanced AI in uncovering complex cryptographic vulnerabilities.

On June 5th, Zcash founder Zooko Wilcox published a rare, detailed security retrospective.

The article disclosed that security researcher Taylor Hornby discovered a severe forging vulnerability in Orchard, Zcash's latest generation privacy pool, on May 29th. An attacker could construct a transaction that should not have passed validation, generating unlimited and undetectable counterfeit ZEC within Orchard.

This was not merely a theoretical risk. Taylor had already written a complete exploit program in a local test environment, successfully generating counterfeit ZEC. If the same program were deployed on the mainnet, an attacker could theoretically generate an unlimited quantity of counterfeit assets in their own mainnet wallet.

After the news became public, ZEC plunged by over 30%. Data from CoinMarketCap shows ZEC hit a 24-hour low of $408.39, down about one-third from its recent high of $610.47. Unfortunately, this was one of the few assets in the crypto space with excellent wealth effects recently, boasting a promising narrative favored by numerous industry leaders, now shattered by this vulnerability.

If one only looks at the outcome, this seems like another familiar crypto security incident: a vulnerability is discovered, developers rush to patch it, and the market panics.

However, the truly thorny aspect of the Orchard incident is that, while the vulnerability has been patched, the Zcash community cannot directly answer another, more sensitive question:

Has anyone exploited this vulnerability in the past four years?

Four-Day Emergency Patch, Orchard Briefly Suspended

Orchard is Zcash's next-generation privacy payment protocol launched in 2022 and one of the primary privacy pools currently used by Zcash. Users can hide balances, transaction amounts, and fund flows, while proving to the network via zero-knowledge proofs that transactions comply with the rules.

According to the timeline disclosed by Zooko, Shielded Labs, and the Zcash community, Taylor discovered anomalies during a targeted security audit of the Orchard circuit on May 29th and immediately privately disclosed the vulnerability to the Zcash Open Development Lab (ZODL). Shielded Labs is an independent, donation-funded Zcash ecosystem support organization based in Switzerland, long involved in Zcash's protocol development, security, and network sustainability efforts, and is not affiliated with the Zcash Foundation or ZODL.

ZODL engineers confirmed the issue was genuine within hours of receiving the report and began seeking a fix. To avoid exposing the vulnerability's details by directly releasing a code patch, the team first chose to temporarily shut down Orchard: prohibiting the creation of new Orchard outputs and the spending of funds already within Orchard.

After coordinating upgrades among developers, miners, node operators, exchanges, and infrastructure providers, an emergency soft fork took effect on June 2nd. Subsequently, Zcash performed a hard fork upgrade to update the verification key for the Orchard circuit and restored Orchard functionality on June 3rd. Transparent addresses and the Sapling privacy pool continued to operate during this period.

The entire process, from disclosure to remediation, took only a few days. In terms of emergency response speed, this was a remarkably successful handling.

But the market did not calm down because the vulnerability was fixed, as the fix addresses the future, not the past.

The Market Fears Not a Future Attack, But That an Attack May Have Already Happened

Ordinary security incidents usually have a relatively clear scale of loss. For a hacked smart contract, on-chain tracking can reveal how much the attacker moved; a cross-chain bridge vulnerability allows for tracking fund flows and affected addresses.

The Orchard incident is different.

According to Shielded Labs' explanation, this vulnerability could be used to generate unlimited and undetectable counterfeit ZEC within Orchard. Due to Orchard's inherent privacy properties, it is impossible for outsiders to cryptographically prove definitively whether this attack vector was exploited before the fix.

This means the market is not facing a determined loss figure but a kind of unquantifiable uncertainty:

If someone indeed found and exploited the vulnerability in the past, does counterfeit ZEC already exist within Orchard? If it exists, what is the scale? Do these assets remain in the privacy pool? Have they gradually leaked out through normal transactions?

More importantly, this risk window did not just open on May 29th. Shielded Labs stated that the vulnerability had existed since Orchard's launch in May 2022, until the emergency fix was completed in June 2026. In other words, the problem lay dormant for nearly four years.

What the market truly fears is not what happened between May 29th and June 2nd, but whether undetectable anomalies occurred during those past four years.

This is also the core reason behind ZEC's plunge of over 30%.

The market is selling off not just a vulnerability, but a repricing of the credibility of the supply.

How a Missing Mathematical Constraint Evolved into an 'Unlimited Minting' Risk

Seeing the words 'unlimited minting vulnerability,' our first thought might be that hackers gained admin privileges or some kind of protocol backdoor.

The reality is more fundamental.

Orchard's security relies on a zero-knowledge proof circuit (Orchard circuit). Users can hide specific transaction details but must prove to the network that their transaction satisfies protocol rules. One of the most important rules is asset conservation: a transaction cannot create new value out of thin air.

Simply put, users don't have to reveal how much ZEC they have or how much they send to whom, but the network must be able to confirm that:

The assets spent indeed come from legitimate inputs.

The problem Taylor discovered lies in an elliptic curve multiplication check within the Orchard circuit.

Shielded Labs describes it as an 'under-constrained element,' meaning a circuit element with incomplete constraints. Because the relevant mathematical relationship was not fully constrained, an attacker could input arbitrary erroneous data into the elliptic curve multiplication process, yet the verification process might still return a pass.

In other words, the attacker doesn't need to crack cryptographic algorithms or control network nodes.

They only need to construct a set of data that should not hold, tricking the system into erroneously believing the transaction still satisfies asset conservation.

Once this false proof is accepted by the network, the non-existent ZEC can be treated as legitimate assets, remaining within Orchard.

This is why Shielded Labs used extremely severe wording:

unlimited, undetectable counterfeit ZEC

The truly dangerous part is not just 'unlimited,' but 'undetectable.'

An Important Distinction Lies Between Two Statements

In its post-upgrade announcement, the Zcash Foundation stated that there is currently no evidence the vulnerability was exploited, no detection of unauthorized value creation, and user funds and privacy remain unaffected. The announcement also emphasized that Zcash's existing Turnstile Accounting mechanism can track value flows between different pools and protect the 21 million ZEC total supply cap.

Meanwhile, Shielded Labs clearly stated that it is impossible to cryptographically prove that counterfeit ZEC never appeared in Orchard's history.

These two statements may seem contradictory but actually address two different levels of the problem.

Zcash's original Turnstile Accounting can be understood as a 'gate' between different asset pools. The system can count how much legitimate asset entered Orchard and limit the scale of assets that can flow out of Orchard.

Suppose Orchard originally contained only 1 million legitimate ZEC; even if an attacker counterfeited more assets inside, the system would not allow assets exceeding the legitimate scale to flow out entirely. This helps prevent the total Zcash network supply cap from being easily breached.

But this mechanism cannot directly prove that counterfeit coins never appeared inside Orchard.

If counterfeit assets remain within Orchard, or gradually replace real assets within the legal outflow quota, the original statistical mechanism may not provide a definitive historical conclusion.

Regarding this arguably one of the oldest crypto privacy projects, all we know is that there is currently no evidence of abnormal minting, but the community still cannot directly prove that counterfeit assets never existed within Orchard.

This is precisely the type of risk the market finds hardest to handle.

The problem is not how many counterfeit coins have been discovered, but that no one can definitively confirm they never existed.

How Can Zcash Prove There Are No Counterfeit Coins in Orchard?

Patching the vulnerability is only the first step.

Shielded Labs has stated it is working with other Zcash developers on a new network upgrade proposal. The plan includes deploying a new privacy pool and enforcing Turnstile Accounting for all assets migrating out of Orchard.

This is akin to setting up a new migration gate for Orchard.

Assets in the old Orchard wishing to enter the new privacy pool would need to complete migration according to verifiable rules. The system could re-count the scale of legitimate assets flowing out and determine if there are any extra ZEC that cannot be migrated normally.

If the upgrade proceeds smoothly, anyone could verify Zcash's supply integrity and further prove no counterfeit assets exist in Orchard.

The significance of this plan is not just fixing code, but rebuilding market trust in Orchard.

Because in a privacy system, trust should not come from 'we think an attack didn't happen,' but from 'anyone can verify an attack didn't happen.'

Shielded Labs itself acknowledges the probability of prior malicious exploitation is low. The vulnerability was hidden for years and extremely difficult to discover; Taylor was actively searching for such issues in a dedicated security research project; after disclosure, the ecosystem quickly shut the attack window within days.

But Shielded Labs also emphasizes that users should not rely solely on the development team's subjective judgment.

The market needs proof.

Why Was a Four-Year-Old Vulnerability Discovered Now?

The Orchard incident has another detail easily overlooked by the market.

On May 28th, Anthropic released Claude Opus 4.8.

One day later, Taylor discovered the Orchard vulnerability.

According to the retrospective by Zooko and Shielded Labs, shortly after Opus 4.8's release, Taylor used it for a highly targeted audit of the Orchard circuit and discovered the issue on May 29th. Subsequently, with the assistance of Opus 4.8, he wrote a complete exploit program, generating unlimited, undetectable counterfeit ZEC in a local environment.

This detail is noteworthy not because AI can independently conduct cryptographic audits.

Public information does not support such an exaggerated conclusion.

Taylor himself is an experienced security researcher. Shielded Labs also mentioned he used a combination of traditional security research methods, a customized AI tool framework, and specifically designed prompts. Opus 4.8 was a crucial tool in the audit process, but not the only factor.

What is truly notable is that Taylor used not Anthropic's restricted-access, cybersecurity-focused model Claude Mythos Preview, but the newly publicly released general-purpose model Opus 4.8.

Anthropic positions Mythos Preview as an advanced model with significant vulnerability discovery and exploitation capabilities. Due to potential misuse risks, Anthropic did not release this model directly to the public but provides access to vetted partners via Project Glasswing.

In contrast, Opus 4.8 is a general-purpose model accessible to ordinary developers. Anthropic emphasized in its release notes its improvements in code analysis, complex task execution, and identifying code defects.

This makes the Orchard incident send an even more significant signal:

The capability to discover high-value vulnerabilities is diffusing from a few specialized security models to general-purpose models.

A general-purpose model released publicly for just one day, guided by a professional researcher, was able to participate in auditing a complex zero-knowledge proof circuit and help discover a critical vulnerability hidden for nearly four years.

This does not mean cryptography experts are no longer important.

On the contrary, Taylor's experience, choice of audit target, and ability to validate the model's output remain the core of the entire process.

But the combination of experts and AI is significantly lowering the cost of discovering complex vulnerabilities.

The Vulnerability is Closed, But the Market Still Awaits Answers

For Zcash, the most urgent attack window is closed.

Orchard functionality is restored, the verification circuit is updated, and there is currently no evidence the vulnerability was maliciously exploited.

But ZEC's plunge of over 30% indicates the market cares about more than just whether the code is fixed.

The market is still waiting for a more definitive answer:

In the past nearly four years, did counterfeit ZEC ever appear inside Orchard?

If the new privacy pool and Turnstile Accounting upgrade can be successfully implemented, the community will finally have a chance to prove supply integrity and rebuild market trust.

But until that proof is completed, the Orchard incident retains an unavoidable suspense:

Did those theoretically unlimited counterfeit ZEC never exist, or were they once hidden where no one could directly see?

Связанные с этим вопросы

QWhat is the primary reason the ZEC price dropped over 30% despite the Orchard vulnerability being quickly patched?

AThe primary reason for the price drop was not the vulnerability itself or the risk of future attacks, but the market's inability to determine whether the vulnerability had already been exploited in the past. The vulnerability existed for nearly four years, and due to Orchard's privacy features, there is no way to cryptographically prove whether undetectable counterfeit ZEC was created during that time. This created profound uncertainty about the true supply integrity of ZEC.

QWhat specific aspect of the Orchard circuit was flawed, and what did it allow an attacker to do?

AThe flaw was an "under-constrained element" in an elliptic curve multiplication check within the Orchard zero-knowledge proof circuit. This incomplete mathematical constraint allowed an attacker to input incorrect data. The verification process could incorrectly pass, making the system believe a transaction obeyed the conservation of assets (no new value creation) when it did not. This enabled the creation of unlimited, undetectable counterfeit ZEC within the Orchard pool.

QWhat is the key difference between the statements from Zcash Foundation and Shielded Labs regarding the historical exploitation of the vulnerability?

AThe Zcash Foundation stated there is no evidence the vulnerability was exploited and that the overall 21 million ZEC supply cap remains protected by the Turnstile Accounting mechanism. Shielded Labs, however, clarified that while the supply cap is protected, it is cryptographically impossible to prove that no counterfeit ZEC was *ever* created inside Orchard in the past. Their statements address different levels: one is about the lack of observed evidence and the outer supply limit, while the other is about the fundamental impossibility of proving a negative within the private pool.

QWhat role did Anthropic's Claude Opus 4.8 play in the discovery of the Orchard vulnerability?

AAnthropic's Claude Opus 4.8, a publicly released general-purpose AI model, was used as a key tool by security researcher Taylor Hornby. The day after its release, Hornby used it to assist in a targeted security review of the Orchard circuit, which led to the discovery of the vulnerability. He then used Opus 4.8 to help write the complete exploit program. This highlights how vulnerability discovery capabilities are diffusing from specialized, restricted security models to publicly available general AI models when guided by expert researchers.

QWhat is the proposed next step by Shielded Labs to rebuild trust in Zcash's supply integrity after the patch?

AShielded Labs is working on a proposal for a new network upgrade. This involves deploying a new privacy pool and enforcing Turnstile Accounting on all assets migrating out of the old Orchard pool. This creates a new 'gate' for migration. By verifying the rules during this process, the network can effectively audit the assets leaving Orchard. If successful, this would allow anyone to verify that no extra, illegitimate ZEC existed in Orchard, moving trust from subjective assurance to objective, verifiable proof.

Похожее

Near Returns to the AI Stage: Transformation into a Public Chain Due to 'Payroll Difficulties,' Agent and Privacy Emerge as New Growth Narratives

NEAR Returns to AI Origins: From Payroll Struggles to Blockchain, Now Focusing on AI Agents and Privacy NEAR Protocol's journey began not with grand blockchain ambitions, but from a practical hurdle: its AI startup founders, including Transformer paper co-author Illia Polosukhin, couldn't efficiently pay international developers in 2017. This led them to pivot and build a high-performance, scalable blockchain. After years navigating various crypto narratives like sharding and cross-chain interoperability, NEAR is now leveraging its AI roots to re-enter the AI arena. A key driver is its "NEAR Intents" layer, which abstracts complex cross-chain transactions. Users simply state their goal (e.g., swap BTC for ETH), and a solver network finds the optimal route. This system has processed over $20B in cross-chain volume, generating significant fee revenue. A major growth area is private transactions via "Confidential Intents/Swaps," which hide trade details until settlement to protect against MEV and front-running. Remarkably, private swaps recently accounted for over 40% of NEAR's transaction volume, highlighting strong demand but also potential regulatory scrutiny. With its AI-founder pedigree, NEAR is positioning itself at the intersection of blockchain, AI agents, and privacy, aiming to become infrastructure for the emerging agent economy while navigating the challenges of its rapid adoption.

marsbit38 мин. назад

Near Returns to the AI Stage: Transformation into a Public Chain Due to 'Payroll Difficulties,' Agent and Privacy Emerge as New Growth Narratives

marsbit38 мин. назад

From Ethereum to AI's 'CROPS': What Exactly is This Set of 'Slow Variables' That Vitalik Repeatedly Emphasizes?

In recent discussions, Vitalik Buterin has frequently emphasized the concept of "CROPS," a framework defining core values for Ethereum's development. CROPS stands for Censorship Resistance, Capture Resistance, Open Source, Privacy, and Security. Initially outlined in the Ethereum Foundation's "EF Mandate," it represents a commitment to user sovereignty, ensuring that the network resists external control, remains open, protects privacy, and prioritizes security. The relevance of CROPS extends beyond Ethereum's foundational principles, becoming crucial in the context of AI integration. As AI agents begin handling wallet operations and automated transactions, the risk increases that users may cede control over their digital assets, privacy, and intentions to centralized AI service providers. A "CROPS AI" would therefore emphasize local execution where possible, privacy-preserving remote model calls (e.g., using zero-knowledge proofs), and transparent, verifiable processes to maintain user agency. Vitalik highlights a significant convergence between "CROPS Ethereum access layer" and "CROPS AI." Both address the same fundamental challenge: how users can access powerful services—be it blockchain data via RPCs or AI models—without exposing sensitive information or relinquishing ultimate control. This intersection points toward a future digital entry point that is more private, secure, and user-controlled. Ultimately, CROPS is not merely an abstract ideal but a practical guidepost. It steers development—from protocol resilience and wallet design to AI agent safety—towards a future where users retain self-sovereignty even as digital systems grow more complex and powerful. In an era of accelerating AI adoption, these "slow variables" of censorship resistance, openness, privacy, and security may define Ethereum's enduring value.

marsbit49 мин. назад

From Ethereum to AI's 'CROPS': What Exactly is This Set of 'Slow Variables' That Vitalik Repeatedly Emphasizes?

marsbit49 мин. назад

Silicon Valley 'Startup Guru' Steve Hoffman: Web3 + AI Could Be a Trap

Silicon Valley investor and "Godfather of Startups" Steve Hoffman warns that combining Web3 with AI is likely a trap, not a promising venture. In an interview, Hoffman argues that while AI is a foundational technology touching all industries, Web3 adds complexity, friction, and regulatory risk without solving mainstream consumer or business needs. He advises founders to focus on deep, specialized applications where startups can out-iterate giants, rather than on generic features easily replicated by large tech companies. Hoffman observes that Silicon Valley will lead foundational AI research, while China excels at rapid, large-scale application and commercialization, particularly in robotics. He stresses that AI-driven autonomous agents capable of collaborative, multi-step tasks are 2-4 years away, which will cause significant job displacement. The solution is not to slow AI but to redesign business models around human-AI collaboration and reform social systems like education and retraining. For startups, Hoffman recommends focusing on vertical, expertise-heavy domains to build defensibility. He sees major opportunities in AI fraud detection and cybersecurity. Key founder mindsets include systemic thinking over feature-focus, relentless customer centricity, building adaptive teams, and deeply understanding AI's capabilities and limits. Hoffman is also leading a non-profit initiative to establish university centers aimed at training future leaders in responsible, human-value-aligned AI innovation.

marsbit2 ч. назад

Silicon Valley 'Startup Guru' Steve Hoffman: Web3 + AI Could Be a Trap

marsbit2 ч. назад

Token Inefficient, Economy Tokenless

The article "Tokens Aren't Economical, Economics Aren't Tokenized" analyzes a pivotal shift in the AI industry from a technology-driven narrative to one dominated by capital efficiency. It highlights two concurrent trends: a severe capital shortage due to the exorbitant and recurring costs of compute (e.g., OpenAI's high burn rate) and a wave of corporate spin-offs where major tech companies are separating their AI units (like Kuaishou's Kling and Baidu's Kunlunxin). The core argument is that AI's "anti-internet" business model, where user growth increases costs rather than profits, has created a disconnect between high valuations and actual cash flow. Spin-offs address this by allowing AI assets to be valued independently. Within a parent company, they are seen as cost centers, but as standalone entities, they are priced based on their growth potential and scarcity in the primary market, leading to massive valuation premiums (e.g., Kling's estimated value tripling post-spin-off). The industry is at an inflection point, moving from "model worship" to "value realization." The competition is evolving from a pure compute (GPU) race to a broader focus on systemic efficiency and full-stack engineering (involving CPUs and orchestration) to achieve viable commercialization. The year 2026 is framed as a critical moment where the industry must definitively answer how to economically translate AI capability into tangible business value, reshaping the sector's future power structure.

marsbit2 ч. назад

Token Inefficient, Economy Tokenless

marsbit2 ч. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить S

Добро пожаловать на HTX.com! Мы сделали приобретение Sonic (S) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Sonic (S).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Sonic (S)После приобретения вами Sonic (S) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Sonic (S)С легкостью торгуйте Sonic (S) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

1.4k просмотров всегоОпубликовано 2025.01.15Обновлено 2026.06.02

Как купить S

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

Он решает проблемы масштабируемости, совместимости между блокчейнами и стимулов для разработчиков с помощью технологических инноваций.

2.3k просмотров всегоОпубликовано 2025.04.09Обновлено 2025.04.09

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

HTX Learn — ваш проводник в мир перспективных проектов, и мы запускаем специальное мероприятие "Учитесь и Зарабатывайте", посвящённое этим проектам. Наше новое направление .

1.8k просмотров всегоОпубликовано 2025.04.10Обновлено 2025.04.10

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на S (S) представлены ниже.

活动图片