"Unlimited Money Printing" Bug Lurked for Four Years, Privacy Coin ZEC Plummets 50% in One Day

Odaily星球日报Опубліковано о 2026-06-05Востаннє оновлено о 2026-06-05

Анотація

A critical "unlimited, undetectable counterfeit" vulnerability existed for nearly four years in the Orchard privacy pool of Zcash (ZEC), a privacy-focused cryptocurrency. The bug, which could theoretically allow attackers to create unlimited fake ZEC, was disclosed by founder Zooko Wilcox on June 5th. While officially patched and deemed low-probability for exploitation, the news triggered a market panic. ZEC's price plummeted over 50% in a single day. The core crisis stems from the inability to prove whether any counterfeit ZEC was created during the vulnerability's active period, as Orchard's design inherently hides transaction details. This casts severe doubt on ZEC's total supply integrity. The sell-off accelerated after prominent investor and ZEC narrative supporter Arthur Hayes announced he had sold his entire position, citing the inability to cryptographically prove the impossibility of extra minting. Community trust eroded further upon learning the bug was discovered with AI-assisted auditing, raising questions about Zcash's development and security review processes. The incident has evolved from a price correction into a fundamental crisis of confidence regarding the network's core security promises.

Original | Odaily Planet Daily (@OdailyChina)

Author | Asher (@Asher_0210)


In the early hours of June 5th, Zcash founder Zooko Wilcox published a statement confirming that Orchard, Zcash's next-generation privacy pool enabled in 2022, once contained a critical counterfeiting vulnerability. Although Zcash officials emphasized that the bug has been fixed and believe the probability of its exploitation is low, it still couldn't stop the spread of market panic.

After the news broke, the Zcash token ZEC quickly nosedived, plummeting over 30% in a short time; by the afternoon, the sell-off didn't stop, panic continued to spread, and the price once fell to around $250, with the intraday loss widening to over 50%.

Security researcher Taylor Hornby discovered the issue on May 29th and has completed vulnerability verification in a local environment, generating test counterfeit ZEC, further validating that the vulnerability is an executable attack path. Currently, the two biggest controversies surrounding Zcash are: First, whether counterfeit ZEC has ever appeared in the privacy pool over the past four years; Second, how can officials prove that no counterfeit ZEC has flowed into the privacy pool, an extremely difficult task to disprove.

Where Did the "Unlimited Minting" ZEC Come From?

The security of Orchard (Zcash's privacy-protecting "shielded pool") relies on zero-knowledge proof circuits, with the core rule being asset conservation: the spend of each transaction must come from legitimate inputs, and ZEC cannot be created out of thin air. Users can hide balances and transaction amounts, but the system must verify the transaction's legitimacy.

Security researcher Taylor Hornby discovered that a constraint in the Orchard circuit was incomplete (under-constrained), allowing attackers to input data that should not have passed, yet verification could still return as successful. In other words, without needing administrator privileges or controlling nodes, and not being a backdoor, as long as the system mistakenly deems a transaction legitimate, originally non-existent ZEC could be recorded as legitimate assets within Orchard.

Shielded Labs called it "unlimited, undetectable counterfeit ZEC".

The Bug is Fixed, but Historical Issues Remain Unresolved

For ordinary security incidents, the biggest fear is large losses, but the most troublesome aspect of Zcash's current crisis is that the losses cannot be directly quantified.

If an attack occurred on the transparent chain, the market could at least see the attack address, fund flows, and affected assets. However, Orchard's transaction amounts, balances, and fund paths are inherently hidden. Once counterfeit ZEC might have appeared in the pool, it's difficult for outsiders to judge whether it's still lingering in Orchard or has gradually flowed out through normal transactions.

More critically, Orchard is not a completely isolated black box. Users can migrate assets between different fund pools, and both real ZEC and potential counterfeit ZEC could mix within the pool.

The Zcash ecosystem can emphasize that there is currently no evidence of the vulnerability being exploited and can explain that the probability of malicious exploitation is low. But for traders, "no anomalies have been found" and "it has been proven that nothing happened" are not the same thing.

This is the core reason for ZEC's expanding decline. Until the question of whether counterfeit ZEC ever appeared in Orchard is proven, ZEC's supply credibility will remain under a shadow.

Arthur Hayes Liquidates Position, Igniting Market Confidence Crisis

After the ZEC vulnerability was exposed, BitMEX co-founder Arthur Hayes's public liquidation further amplified market panic.

Arthur Hayes stated on platform X that he has sold his entire ZEC holdings. Hayes said he learned about the attack yesterday but did not realize its conflict with his narrative framework. ZEC's 30% drop prompted him to reconsider and decide to take full profits on that position. He added that while he believes the possibility of additional minting is extremely low, he cannot formally prove its impossibility at the cryptographic level; he will continuously reassess his judgment and, if his assumption is disproven, will repurchase, hoping to build a position at a lower price; privacy is priceless, and he wouldn't mind repurchasing at a higher price.

This was quite damaging for ZEC. Over the past period, Arthur Hayes has been one of the key narrative drivers for ZEC. His bullish view was based on the long-term logic of privacy assets regaining pricing power in the context of AI, government surveillance, and big tech expansion. Therefore, his liquidation wasn't just a major holder taking profits; it resembled a public downgrade of ZEC's current narrative.

When a top narrative supporter chooses to exit first, long positions originally supported by belief and expectations are more likely to turn into collective profit-taking and risk aversion.

Community Sentiment Spiral, ZEC Transforms from Price Correction to Trust Crisis

Perhaps influenced by Arthur Hayes's liquidation, community discussions about ZEC quickly shifted from "whether to buy the dip" to "whether it can still be trusted."

On one hand, the community repeatedly emphasized the severity of the vulnerability itself. Compared to short-term price drops, many users were more concerned that a vulnerability theoretically capable of creating unlimited counterfeit coins had lurked in Orchard for nearly four years. For them, the price drop was just the surface; what truly shook confidence was the question mark placed on Zcash's core security assumptions.

On the other hand, the process of AI-assisted vulnerability discovery further exacerbated distrust. Taylor Hornby, with the aid of AI tools, conducted a targeted review of the Orchard circuit, ultimately discovered the vulnerability, wrote an exploit program, and generated counterfeit ZEC in a local environment. Although AI did not perform the audit independently, what the community more easily remembered was the narrative that "a key vulnerability existing for years was assisted in being found by AI in a short time," which quickly gained traction.

This turned public criticism towards Zcash's development and audit systems. The community questioned why a vulnerability existing since 2022 could go undetected on the mainnet for years? If even the core privacy pool could have constraint omissions, how can users trust Zcash's promises on supply and privacy security again?

Therefore, this decline is no longer just profit-taking. Before Zcash provides more convincing proof, no one is really willing to hold ZEC long-term.

Трендові криптовалюти

Пов'язані матеріали

Funding Weekly | Crypto.com Secures $400M Investment, CeFi and Stablecoin Sectors Continue to Attract Capital

Crypto Weekly Investment Recap: Funds Converge on CeFi, Stablecoins, and AI Last week's crypto and AI investment landscape saw significant capital concentration, with a few large deals dominating. **Crypto/Web3 Highlights (July 13-19):** Total investment exceeded **$812 million** across 17 deals. Key trends: * **Centralized Finance (CeFi) & Stablecoins** remained a major magnet, led by **Crypto.com**'s massive **$400 million** raise from Citadel Securities, valuing the exchange at $20B. * **Infrastructure & Tools** saw 7 deals, including **Cyclops** ($20M for stablecoin payments) and **ADI Chain** ($50M for stablecoin settlement infrastructure). * **DeFi** had 2 deals, such as AI-native DEX **Quote Trade** ($4M). * Other notable raises: API broker **Alpaca** ($135M), cross-border platform **Flex** ($70M), treasury firm **ORANGE JUICE** ($40M), and prediction market **Pascal** ($9M). * **Acquisitions:** Keyrock bought BlockFills' trading unit, SBI Holdings acquired Singapore exchange Coinhako, and MoonPay bought startup Glide. **AI & Robotics Highlights:** Investment momentum in AI remained very strong. * Nvidia-backed AI cloud service **Fireworks** raised a massive **$1.5 billion** at a $17.5B valuation. * In robotics, **Walden Robotics** (spun out from Toyota) secured **$300 million**, and Chinese humanoid firm ****逐际动力** **(Climax Dynamics) raised nearly **$200 million** in a Pre-IPO round. * Other significant AI raises included Indian programming platform **Emergent** ($130M) and drone company **Brinc** ($125M), backed by Sam Altman. Overall, the trend shows capital flowing heavily into established crypto financial services, stablecoin infrastructure, and large-scale AI/robotics commercialization.

marsbit55 хв тому

Funding Weekly | Crypto.com Secures $400M Investment, CeFi and Stablecoin Sectors Continue to Attract Capital

marsbit55 хв тому

The Gentlest Bear Market? BTC Bears Exit, ARK and Bitwise Collectively Bullish

**Title: The Mildest Bear Market? BTC Shorts Exit, ARK and Bitwise Collectively Bullish** Bitcoin continues to consolidate around $75,000 while Ethereum struggles near $1,900. Market data shows $116 million in liquidations over 24 hours, with $62.7 million from short positions, and the Fear & Greed Index remains at 35 (Fear). According to Polymarket, there's a 33% probability BTC falls below $50,000 this year. ARK Invest's Q2 2026 Bitcoin report notes technical weakness but identifies potential bottoming signals, including a record high in long-term holder supply, suggesting selling exhaustion. Bitwise's Juan Leon calls this the "structurally mildest bear market" on record, with a ~50% drawdown from highs, less severe than past cycles. He highlights institutional accumulation and a shift in investor dialogue from survival to entry points. Technical analysis from Bit suggests a potential C-wave low may have formed, with an ideal bottoming range between $50,000-$55,000. However, glassnode's CryptoVizArt warns that failure to break $66,000 could signal a local top, as new buyer accumulation is concentrated there. Analyst Darkfost identifies a critical support band between $59,000-$70,000, where 50% of BTC's circulating supply has changed hands. Notably, trader Doctor Profit announced closing all crypto short positions—including BTC shorts from $115k-$125k and over 100 altcoin shorts—for significant profit. He has begun a phased accumulation of Bitcoin spot starting at $64,000, reversing his previous $40k-$50k target, citing structural positives like regulatory clarity and institutional adoption. He argues the anticipated September/October bottom may arrive earlier than the herd expects.

Foresight News1 год тому

The Gentlest Bear Market? BTC Bears Exit, ARK and Bitwise Collectively Bullish

Foresight News1 год тому

The Evolution of Order in the AI & Web3 Era: The Competitive Dimensions and Exploratory Path of m&W

The article explores the evolution of order in the AI & Web3 era, framing the competition around establishing new foundations for human-AI collaboration. It argues that as AI Agents become core economic participants, the existing Web3 infrastructure—focused on assets, identity, and decentralized governance—is insufficient. The core challenge shifts to building trust, assessing complex contributions, and creating fair value distribution among diverse human and AI actors. The analysis positions the m&WDAO project within this landscape by comparing it to existing paradigms: Colony (human-centric DAO governance), SingularityNET (AI service exchange), Gitcoin Passport (Sybil-resistant identity), and Farcaster/Lens (open social graphs). m&W's distinct path, termed EcoFi (Ecological Finance/Order), aims to integrate these layers. Its three-phase evolution is outlined: 1) **m&W 1.0: Credit Anchoring** - filtering high-quality "Builder" nodes and converting their contributions into non-transferable SBTs (Soulbound Tokens) as a bedrock of trust. 2) **m&W 2.0: Collaborative Economy** - deploying the EcoFi protocol to enable verified, complex task collaboration with a hybrid AI/human judgment system for valuation and dispute resolution, creating a closed-loop value system. 3) **m&W 3.0: Intelligent Order** - where human-originated SBT credit enables trusted AI Agent "digital twins" to participate in a mature human-AI co-creation economy. The conclusion asserts that while other projects solve discrete problems (proving identity, governing contributions, exchanging AI capabilities), m&W's ultimate mission is to address the foundational question of a new socio-economic order for the coming era of human-AI collaborative networks.

链捕手1 год тому

The Evolution of Order in the AI & Web3 Era: The Competitive Dimensions and Exploratory Path of m&W

链捕手1 год тому

Торгівля

Спот

Популярні статті

Як купити ZEC

Ласкаво просимо до HTX.com! Ми зробили покупку Zcash (ZEC) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити Zcash (ZEC).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої Zcash (ZEC)Після придбання Zcash (ZEC) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля Zcash (ZEC)Легко торгуйте Zcash (ZEC) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

586 переглядів усьогоОпубліковано 2024.12.12Оновлено 2026.06.02

Як купити ZEC

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни ZEC (ZEC).

活动图片