Zcash Bug Could Have Minted Unlimited ZEC Undetected

bitcoinistОпубліковано о 2026-06-05Востаннє оновлено о 2026-06-05

Анотація

A critical vulnerability in Zcash's Orchard shielded pool, discovered by researcher Taylor Hornby on May 29, 2026, could have allowed an attacker to create an unlimited amount of undetectable counterfeit ZEC. The flaw, involving an under-constrained element in the Orchard circuit, existed from the pool's 2022 activation until an emergency fix was deployed by June 2, 2026. Hornby identified the bug using AI-assisted auditing tools and confirmed its exploitability in a test environment. Due to Orchard's privacy features, which hide transaction amounts and history, there is no cryptographic way to prove whether the vulnerability was exploited before the fix. While Shielded Labs assesses prior exploitation as unlikely, this uncertainty has sparked a debate on proving supply integrity in privacy-preserving systems. In response, Shielded Labs and other developers are exploring a network upgrade, potentially involving a new shielded pool and formal verification of the circuit rules to prevent future vulnerabilities and allow verification of the ZEC supply's integrity. ZEC's price fell nearly 45% following the disclosure.

A critical vulnerability in Zcash’s Orchard shielded pool could have allowed an attacker to create an unlimited amount of counterfeit ZEC without detection, according to a new disclosure from Zooko Wilcox, Jason McGee and security researcher Taylor Hornby. The flaw was discovered on May 29, remediated through an emergency ecosystem response completed by June 2, and has now triggered a broader debate over how Zcash can prove supply integrity in a privacy-preserving system.

Orchard Flaw Puts Zcash Supply Integrity Under Scrutiny

The vulnerability was found by Hornby, an experienced security engineer hired by Shielded Labs in April 2026 to conduct ongoing security research on the Zcash protocol. According to the disclosure, the mandate was straightforward: find protocol-level weaknesses before adversaries did. Hornby began reviewing Zcash with a combination of traditional security research and newer AI-assisted auditing methods.

The timing was unusually compressed. Shortly after Anthropic released its Opus 4.8 model on May 28, Hornby used it in a targeted review of the Orchard circuit. One day later, he found a critical counterfeiting flaw and disclosed it to Zcash Open Development Lab, or ZODL, whose engineers coordinated the emergency response with other ecosystem participants.

“The vulnerability could have been exploited to undetectably create an unlimited amount of counterfeit ZEC within Orchard,” the Shielded Labs post said. “Because of the privacy properties of Orchard, there is no way to cryptographically prove whether the vulnerability was exploited before it was remediated. However, a network upgrade can be deployed to protect users and prove the integrity of the Zcash supply.”

The disclosure states that the bug was “real and exploitable.” Hornby, with the help of Opus 4.8, wrote a complete exploit and tested it in a local regtest environment, where it generated unlimited counterfeit ZEC that could not be detected. The authors said that had the same tool been run on mainnet, it would have generated unlimited, undetectable counterfeit ZEC in Hornby’s mainnet wallet.

Technically, the issue involved an under-constrained element of the Orchard circuit. That made it possible to feed arbitrary false inputs into an elliptic curve multiplication while still passing the multiplication check. The vulnerability existed from Orchard’s activation in May 2022 until the emergency fix was deployed on June 1, 2026.

That timeline is central to the concern. In a transparent ledger, supply irregularities can generally be audited by inspecting public balances and transaction values. Orchard is different by design: it hides amounts and transaction history. That privacy model means the system depends heavily on the correctness of the circuit rules that define valid shielded transactions.

Josh Swihart, founder and CEO of Zcash Open Development Lab, the team behind the creation and launch of Zcash and builder of the Zodl wallet, framed the issue in those terms in a separate post. “A shielded Zcash transaction includes a proof that it followed the protocol’s rules, as defined in the rulebook (the circuit) that defines what constitutes a valid transaction. The Orchard vulnerability was in one of the rules, written loosely enough that it would accept false information and still pass. As a result, the engine could be convinced that a fake transaction was valid.”

Swihart added that the flaw was not in Zcash’s underlying cryptography or the proof engine itself, but in the handwritten rules. In his words, “This was a flaw in the handwritten rules, not in the underlying cryptography or the engine that creates proofs.”

Shielded Labs said prior exploitation appears unlikely, while emphasizing that users should not be asked to rely on that assessment alone. The authors pointed to several reasons for their view: the flaw had evaded years of scrutiny by leading cryptographers, Hornby was specifically hired to find such vulnerabilities, and the response window after discovery was sharply narrowed by the speed of ZODL and the broader Zcash ecosystem.

“The discovery was not accidental—it was the result of a deliberate effort to identify vulnerabilities of this kind before malicious actors could,” the post said. “Taylor is one of the most skilled people in the world at this. He used the most recent AI tools, available only to white-hat security researchers, along with a sophisticated custom-built AI harness and prompts, and worked hard to outrace the attackers. We think he probably succeeded.”

Still, the authors acknowledged the unresolved cryptographic uncertainty. Because of Orchard’s privacy properties and the nature of the bug, they said there is no definitive way to prove solely through cryptography whether the vulnerability was exploited before the fix.

Shielded Labs Eyes New Pool And Formal Verification

To address that, Shielded Labs is exploring a proposed network upgrade with other Zcash developers. The plan would deploy a new shielded pool and enforce turnstile accounting on coins moving from the existing Orchard pool, with the goal of allowing anyone to verify the integrity of the Zcash supply and prove the non-existence of counterfeit ZEC in Orchard. A follow-up post is expected next week with more details, including tradeoffs and implementation mechanics. Any major upgrade would still need community support and the standard governance process before activation.

Swihart said a second Orchard pool could, in principle, be targeted for NU7 at the end of July, though he did not take a fixed position on whether that path should be pursued. He argued that the larger issue is preventing this class of failure from recurring, with formal verification as the strongest answer.

“Formal verification fixes this,” Swihart wrote. “A mathematical proof can be constructed to reduce the parts humans must review to a concise, readable statement of the rules. A computer then checks the entire rulebook to ensure it matches. AI tools can now do the work of writing these proofs.”

Shielded Labs said it is already accelerating proactive security work with Hornby and Anthropic, initiating a project to formally verify the Orchard circuit, and opening searches for a Head of Security and a Cryptographer. The episode leaves Zcash with a difficult but clear path: repair the trust assumptions around Orchard, prove supply integrity where possible, and move future shielded design closer to machine-checked guarantees rather than human-reviewed complexity.

Over the past 24 hours, ZEC has fallen nearly 45% amid the uncertainty. At press time, it was trading at $337.

ZEC trades below the 1.618 Fib again, 1-week chart | Source: ZECUSDT on TradingView.com

Трендові криптовалюти

Пов'язані питання

QWhat was the nature of the critical vulnerability discovered in Zcash's Orchard shielded pool?

AThe vulnerability was a critical counterfeiting flaw. An under-constrained element in the Orchard circuit allowed an attacker to feed arbitrary false inputs into an elliptic curve multiplication while still passing the multiplication check, potentially enabling the creation of an unlimited amount of counterfeit ZEC that could not be detected.

QWho discovered the vulnerability, and what tools aided in its discovery?

AThe vulnerability was discovered by security researcher Taylor Hornby, who was hired by Shielded Labs. He used a combination of traditional security research and newer AI-assisted auditing methods, specifically employing Anthropic's Opus 4.8 model released on May 28 in a targeted review of the Orchard circuit, which led to the discovery the next day.

QWhy is it impossible to cryptographically prove whether the Orchard vulnerability was exploited before it was fixed?

ADue to the privacy properties of the Orchard shielded pool, which hides transaction amounts and history by design. This means supply irregularities cannot be audited by inspecting public data, unlike transparent ledgers. The system relies on the correctness of the circuit rules, and the bug's nature leaves no definitive cryptographic trace of prior exploitation.

QWhat proposed solution is Shielded Labs exploring to address the supply integrity concerns raised by the Orchard bug?

AShielded Labs is exploring a proposed network upgrade to deploy a new shielded pool. This plan would enforce turnstile accounting on coins moving from the existing Orchard pool, with the goal of allowing anyone to verify the integrity of the Zcash supply and prove the non-existence of counterfeit ZEC in Orchard.

QAccording to Josh Swihart, what is the strongest long-term solution to prevent this class of failure from recurring?

AJosh Swihart identified formal verification as the strongest answer. This involves constructing a mathematical proof to reduce the human-reviewed parts to a concise statement of the rules, and then using a computer to check that the entire rulebook matches those rules, with AI tools now capable of writing these proofs.

Пов'язані матеріали

Tidal Investment: We Remain Bullish on the AI Industry Chain, But for Different Reasons Now

Tidal Investments remains optimistic about the AI industry chain, but the rationale has shifted. The market is concerned about massive concurrent fundraising by tech giants like SpaceX, OpenAI, Alphabet, and Meta, fearing an AI peak. However, the authors argue this signals the next act of AI development, not its end. Capital expenditure (Capex) from major cloud providers (Alphabet, Amazon, Meta, Microsoft, Oracle) continues to surge aggressively into 2026. This investment cycle is more resilient than past hardware cycles due to its scale and complexity. Bottlenecks have shifted from chips to critical physical infrastructure like power grids, transformers, cooling, and data center construction—areas with long lead times and limited capacity for rapid expansion. Supply chain data (e.g., Eaton's orders) confirms substantial, tangible progress. Key market concerns are addressed: 1. **ROI vs. Capex Growth**: While Capex growth outpaces revenue, the authors note cloud giants have historically overcome similar phases through scale. The cycle will only be in danger if Capex guidance is cut, orders are canceled, or AI product demand falters—none of which are currently observed. 2. **Comparison to the 2000 Dot-com Bubble**: Unlike the telecom bubble, where cheap, oversupplied fiber crashed prices, AI infrastructure (especially power) is constrained, customized, and subject to lengthy approvals, making a similar supply glut and crash unlikely. In conclusion, the wave of fundraising reflects the immense, ongoing capital needs for AI's next phase, constrained by slow-moving physical bottlenecks. The AI cycle is not over; the script has simply changed.

链捕手9 хв тому

Tidal Investment: We Remain Bullish on the AI Industry Chain, But for Different Reasons Now

链捕手9 хв тому

Grayscale: These 15 Profitable Crypto Protocols Are Severely Undervalued

Grayscale Research identifies 15 top-revenue crypto protocols trading at significant valuation discounts, with many at single-digit or even 1x revenue multiples. Protocols like Pump.fun, PancakeSwap, and Meteora have market capitalizations roughly equal to their annual revenue. The report argues these financially-focused protocols (DEXs, lending, staking) are fundamentally undervalued and could benefit from the potential passage of the CLARITY Act, expected as soon as next month. This legislation aims to clarify digital asset regulation, potentially reducing institutional barriers and driving on-chain activity. The analysis breaks down the protocols into three groups: the "1x Club" (market cap ≈ revenue), mid-tier protocols with 3-9x multiples (e.g., Aave, Lido, Jupiter), and high-multiple protocols like Hyperliquid (15x) and Uniswap (37x), where valuation reflects future potential rather than current cash flows. Grayscale applies a traditional DCF model to Aave, suggesting a one-year price target of ~$175, representing ~130% upside from current levels. The report notes a risk-off macro environment since the Iran conflict has further compressed valuations, creating a potential entry window. The conclusion highlights that while the valuation data presents an intriguing opportunity, the investment thesis is contingent on the CLARITY Act's passage and subsequent institutional capital flows. Investors are cautioned to consider Grayscale's inherent conflict of interest as a crypto asset manager with products tied to these assets.

marsbit36 хв тому

Grayscale: These 15 Profitable Crypto Protocols Are Severely Undervalued

marsbit36 хв тому

Sam Altman's Personal Alchemy of Wealth: Investing in 400 Companies, Over 10 Deeply Tied to OpenAI

The article investigates Sam Altman's personal wealth strategy, centered around his investments in approximately 400 companies while serving as OpenAI's CEO. Despite not holding direct equity in OpenAI, Altman has built a vast portfolio, with at least 10 of his investments having commercial ties or ongoing negotiations with OpenAI. This creates a complex network of potential conflicts of interest, drawing scrutiny from U.S. congressional committees and state attorneys general. Key investments highlighted include the anti-aging startup Retro Biosciences (valued at $258 million for his stake as of late last year) and the chipmaker Cerebras, whose value soared following an OpenAI procurement deal. His most significant financial gain is linked to the nuclear fusion company Helion, where a recent funding round reportedly increased his stake's value to at least $4.1 billion. The article details a decade-long relationship between Altman, Helion, and OpenAI, including a controversial non-binding power purchase agreement and Altman's efforts to secure investments from OpenAI and its backer SoftBank for Helion. Other points include internal investigations at Tools for Humanity (developer of Worldcoin) and OpenAI's massive contracts with tech giants like Nvidia. According to Forbes, Altman's net worth is around $3.4 billion, ranking him 1251st globally—a rise of over 1400 places since 2024. OpenAI's board states that Altman's external dealings are transparent and potential conflicts are carefully managed.

Odaily星球日报57 хв тому

Sam Altman's Personal Alchemy of Wealth: Investing in 400 Companies, Over 10 Deeply Tied to OpenAI

Odaily星球日报57 хв тому

Former SpaceX Engineer Reconstructs Financial Execution System Using First Principles

Former SpaceX engineer Lex Li applies "First Principles Thinking" to financial infrastructure with Plan Execution Lab, recently raising angel funding at a $50M post-money valuation. The team argues that the core function of finance is capital allocation, and the critical gap is not in trading but in execution, which remains highly manual and fragmented. While assets, liquidity, and settlement have migrated on-chain, execution workflows (monitoring, risk management, liquidity coordination) are still human-native. In an era of accelerating AI agents, strategy decay is rapid, shifting the competitive edge from having the best strategy to having the most robust execution network. Plan Execution Lab introduces two core components: 1. **PlanX**: A Financial Execution Protocol designed as infrastructure for the migration from CEX to DEX, providing on-chain execution capabilities, liquidity access, risk management, and capital orchestration. 2. **Xgent**: An Autonomous Financial Runtime. Users define investment intents, risk preferences, and constraints; Xgent automatically constructs an execution graph, verifies it, and handles ongoing execution and optimization—streamlining the process from Intent to Autonomous Execution. The long-term vision is to create the "Bloomberg Terminal for Autonomous Finance"—a shared operating environment and execution network built collectively by participants like execution nodes, liquidity providers, and autonomous agents. The future of finance, they contend, belongs not to isolated algorithms but to open, collaborative execution networks.

marsbit1 год тому

Former SpaceX Engineer Reconstructs Financial Execution System Using First Principles

marsbit1 год тому

Торгівля

Спот
Ф'ючерси

Популярні статті

Як купити ZEC

Ласкаво просимо до HTX.com! Ми зробили покупку Zcash (ZEC) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити Zcash (ZEC).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої Zcash (ZEC)Після придбання Zcash (ZEC) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля Zcash (ZEC)Легко торгуйте Zcash (ZEC) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

561 переглядів усьогоОпубліковано 2024.12.12Оновлено 2026.06.02

Як купити ZEC

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни ZEC (ZEC).

活动图片