ZEC Co-Founder Responds to Orchard Vulnerability: No Signs of Theft, Orchard Pool to Be Sealed

Foresight NewsОпубліковано о 2026-06-15Востаннє оновлено о 2026-06-15

Анотація

ZEC Co-Founder Addresses Orchard Vulnerability: No Signs of Theft, Plans to Sunset Orchard Pool A security vulnerability was recently discovered in Zcash's Orchard shielded pool, raising key concerns. The primary questions are whether the flaw was exploited, if user funds are safe, whether users can verify the total ZEC supply, and if other similar vulnerabilities exist. Analysis suggests the vulnerability was likely not exploited prior to its discovery. It was found proactively by a researcher using specialized tools, not due to an active breach. The development team and mining pools acted quickly to contain the issue. Typical financially-motivated attacks would likely have left visible on-chain evidence, which has not been observed. User funds in Orchard are considered safe and should be recoverable, assuming no prior exploitation. If the flaw was never used, all legitimate funds can be withdrawn. The article outlines risks associated with moving funds to transparent addresses or other pools, but concludes that leaving assets in place is a reasonable option. Currently, users cannot independently verify that the total ZEC supply hasn't been inflated due to this bug. However, the planned Ironwood network upgrade is designed to resolve this. It will permanently close the Orchard pool to new deposits and internal transfers, allowing only withdrawals. This mechanism will cap total withdrawals at the amount of legitimately deposited funds, enabling anyone to cryptographically...


Authors: Zooko Wilcox, Jason McGee

Compiled by: Luffy, Foresight News


Recently, a security vulnerability was exposed in Zcash's Orchard module, raising two major concerns for the community: Is the total supply of ZEC tokens abnormal? Are user assets safe?


Current discussions intertwine several different topics, making it difficult for many to understand the actual impact of this vulnerability on ordinary users. This article will address these issues, explaining the underlying meanings one by one.


This Orchard vulnerability primarily raises four key questions:


  1. Has the vulnerability been exploited by hackers?
  2. Can users' legitimate assets stored in Orchard be withdrawn normally?
  3. Can users independently verify that the total supply of Zcash has not been artificially inflated?
  4. How can we confirm that the project does not contain other similar token forgery vulnerabilities?


Has the Vulnerability Been Exploited?


Currently, there is no definitive conclusion. Overall, the likelihood of the vulnerability being maliciously exploited previously is low, but we cannot rule it out with 100% certainty. There are three main reasons:


  • For many years, numerous top global cryptographers and security researchers have been reviewing the Zcash code, and this vulnerability remained undiscovered. This vulnerability was proactively found by Shielded Labs' Taylor Hornby during targeted investigations, not accidentally exposed. He leveraged AI-powered security detection technology and custom tools specifically designed to uncover this type of hidden flaw. Such vulnerabilities have a high technical barrier; it would be difficult for individuals not specialized in the Zcash codebase to find and exploit them.
  • Upon the vulnerability's exposure, the Zcash development team immediately collaborated with major mining pools to temporarily freeze the Orchard pool and push a fix, significantly narrowing the window of opportunity for attackers.
  • Most attacks in the cryptocurrency space aim for quick profits. Once a vulnerability is public, hackers typically cash out immediately. To profit from this vulnerability, a hacker would need to transfer the forged ZEC out of the Orchard pool and exchange it for other assets. Such operations generally leave traces. If the vulnerability had been exploited long ago, evidence should have emerged by now. Throughout industry history, hackers' modus operandi is typically "strike and disappear quickly," not deliberately hiding for months or even years.


Can Legitimate Assets in Orchard Be Withdrawn?


We believe they can be withdrawn normally, provided the vulnerability has never been exploited. If this assessment holds true, all legitimate assets users have deposited into Orchard can be successfully transferred out.



Conversely, if hackers have already used the vulnerability to create counterfeit tokens and transferred them into the pool, the existing withdrawal channels would cap the total withdrawal amount. The withdrawal limit would equal the total amount of legitimate tokens initially deposited. In this scenario, if counterfeit tokens are withdrawn first, some users' legitimate assets might not be fully recovered.



We consider the likelihood of this extreme scenario to be low. If users still have concerns, they can move their assets out of the Orchard pool. However, before doing so, it's important to understand the potential risks of different withdrawal methods:


  • Transferring to a transparent address (t-address): The transfer amount and time will be fully public, and the assets will become publicly associated with that address, completely losing privacy.
  • Transferring to the Sapling shielded pool: The transfer amount and time will still be recorded, but it won't link the assets to a specific address or transaction history, offering better privacy than transparent addresses. Note that Sapling relies on a trusted setup ceremony completed in 2018, which itself carries additional security considerations.
  • Wallets: Among mainstream self-custody wallets, currently only YWallet and Zkool support the Sapling pool.
  • Other wallets or custodial platforms: There may also be risks of operational errors, software faults, platform risk controls, and other unexpected issues.


Overall, these risks are manageable. Combined with the assessment that "the vulnerability was most likely not exploited," keeping assets in the original shielded wallet is a prudent choice. If users can ensure operational safety, withdrawing assets is also a viable option. Users should decide based on their individual circumstances.


Can Users Independently Verify That Zcash's Total Supply Has Not Been Inflated?


Currently, this is not possible. Due to the existence of this vulnerability, ordinary users cannot independently verify whether the total token supply within the shielded pools has been inflated.



However, the planned Ironwood network upgrade will address this issue. The logic is as follows:



This upgrade will permanently close the Orchard pool, disallowing new asset deposits. Tokens within the pool will no longer be able to move internally; all assets can only be withdrawn through the original channels. The total withdrawal amount from these channels strictly equals the amount of legitimate tokens originally deposited, fundamentally preventing any excess outflow of tokens.


After the upgrade is complete, anyone running a node will be able to verify that the total token supply is compliant. Even if counterfeit tokens were created in the past, they will no longer be able to circulate within the Orchard pool, artificially inflating the total supply. Users won't need to speculate about the actions of hackers or other users; the protocol itself will guarantee that token over-issuance cannot occur.


This point is crucial. Zcash's long-term credibility is built on users' ability to independently verify the total token supply. The Ironwood upgrade will restore this capability to users.


How to Confirm the Project Has No Other Token Forgery Vulnerabilities?


At this stage, we cannot give an absolute answer, but we have reason to believe no similar vulnerabilities currently exist.


Shielded Labs, in collaboration with several teams, conducted a comprehensive review of the Zcash protocol, specifically searching for token forgery vulnerabilities. During this process, the team also utilized Anthropic's not-yet-publicly-released Mythos AI model for auxiliary detection. We will publish a follow-up article detailing the process and results of this review.


To date, the team has not discovered any new forgery vulnerabilities. This review assembled experienced technical personnel, professional security teams, and advanced AI analysis tools, which further strengthens our confidence that there are currently no undisclosed high-risk vulnerabilities of the same type.


Simultaneously, we are collaborating with partners like the Tachyon project to conduct additional inspections, further strengthening our security defenses. Related progress will also be announced later.


Summary


This Orchard vulnerability raises four core questions: whether the vulnerability was exploited, whether legitimate assets can be withdrawn, whether the total token supply can be verified, and whether other forgery vulnerabilities exist.


Based on the current investigation results, we assess that the likelihood of the vulnerability being exploited previously is low. Therefore, user assets are safe, and the total token supply currently remains normal. After repeated inspections by multiple independent teams, we are increasingly confident that the project currently has no other undiscovered forgery vulnerabilities.


However, one point is unavoidable: currently, users cannot independently verify the total token supply. The upcoming network upgrade will completely solve this problem. After the upgrade, the Orchard pool will be permanently closed, allowing users to independently verify the total token supply without needing to judge whether token forgery has ever occurred.

Пов'язані питання

QWhat are the four key questions raised by the Orchard security vulnerability?

AThe four key questions are: 1) Has the vulnerability been exploited? 2) Can legitimate user assets stored in Orchard be withdrawn normally? 3) Can users independently verify that the total Zcash supply has not been artificially increased? 4) How can we confirm there are no other similar token counterfeiting vulnerabilities in the project?

QWhat is the primary reason why the authors believe the Orchard vulnerability likely hasn't been exploited?

AThe authors believe exploitation is unlikely primarily because the vulnerability was discovered through proactive investigation by Shielded Labs using specialized AI detection tools, not due to a public exposure. They argue that exploiting it requires deep expertise and that typical cryptocurrency attackers would likely have cashed out already, leaving detectable traces, which haven't been observed.

QHow does the planned Ironwood network upgrade aim to restore users' ability to verify the Zcash supply?

AThe Ironwood upgrade will permanently close the Orchard pool, preventing new deposits and internal transfers. All assets can only be withdrawn via the original channels, whose total withdrawal amount is strictly capped at the amount of legitimate tokens originally deposited. This prevents any excess tokens from leaving the pool, allowing anyone running a node to verify the total supply compliance.

QWhat risks do users face if they choose to transfer their assets out of the Orchard pool?

ATransferring to a transparent address (t-address) reveals the amount, timing, and links the assets to that address, losing all privacy. Transferring to the Sapling pool offers better privacy but relies on a 2018 trusted setup ceremony, which introduces its own security considerations. Additionally, users may face risks from operational errors, software bugs, or platform restrictions when using wallets or custodial services.

QWhat measures have been taken to search for other potential token counterfeiting vulnerabilities in Zcash?

AShielded Labs, in collaboration with other teams, conducted a comprehensive audit of the Zcash protocol specifically for token counterfeiting vulnerabilities. They utilized advanced tools including an unreleased AI model from Anthropic called Mythos. So far, no new such vulnerabilities have been found, increasing confidence that no other high-risk, undisclosed vulnerabilities of this type exist.

Пов'язані матеріали

If the AI Bubble Is Already Bursting, Who Will Truly Survive?

If the AI Bubble is Bursting, Who Will Remain? The debate over an AI bubble is intensifying, with figures like Ray Dalio warning of high levels and Jensen Huang seeing immense, early-stage opportunity. Both views hold truth: a speculative bubble in capital markets likely exists, mirroring the dot-com era, but the underlying technological shift is real and transformative. History shows that while bubbles burst—wiping out overvalued companies and speculative capital—they often leave behind critical physical and digital infrastructure. The dot-com bust, for instance, eliminated many firms but left the global fiber optic networks and data centers that enabled the rise of Amazon, Netflix, and cloud computing. Today's massive AI infrastructure investments (projected at trillions by 2030) in data centers, power, cooling, and GPUs may follow a similar path, creating the foundation for future applications. A key divergence from past bubbles is the "Jevons Paradox" effect in AI. As the cost of AI inference has plummeted by over 99.7% since 2023, enterprise spending on AI has skyrocketed. Cheap "tokens" have unlocked vast, previously uneconomical use cases, moving AI from simple chatbots into core business workflows—code generation, legal document review, scientific simulation, and financial analysis. The market is now in a phase of self-correction, weeding out superficial "API-wrapper" startups, but this cleansing process strengthens the ecosystem. The long-term trajectory is clear. The value is gradually shifting from capital expenditure (CapEx) on hardware to operational expenditure (OpEx) on transformative applications. As AI becomes a utility, the winners will be firms that deeply integrate it to solve vertical industry problems in law, healthcare, finance, and manufacturing. The泡沫 will recede, but the foundational shift towards an AI-powered era across all sectors is irreversible. The underlying productive force of AI contains no bubble.

marsbit18 хв тому

If the AI Bubble Is Already Bursting, Who Will Truly Survive?

marsbit18 хв тому

If the AI Bubble Is Already Bursting, Who Will Truly Remain?

**Summary: If the AI Bubble is Bursting, What Will Remain?** The debate around an AI bubble is intensifying, with figures like Ray Dalio warning of high valuations while Jensen Huang sees immense opportunity. This echoes the dot-com bubble, which saw massive wealth destruction but ultimately left behind critical infrastructure like undersea cables and broadband, enabling future giants like Amazon and Netflix. Similarly, today's AI boom involves trillions invested in data centers, power, cooling, and GPUs, while application-layer revenue remains comparatively modest. This investment-disparity signals a bubble. However, the core technological progress is real and accelerating. AI inference costs have plummeted by over 99.7% since 2023, making intelligence increasingly cheap and accessible. This cost collapse is unlocking vast new demand. Instead of reducing spending, enterprises are tripling their AI cloud expenditure. Cheap "tokens" enable AI to move beyond simple chatbots into complex workflows—automating code writing, legal document review, financial analysis, and scientific research. This follows "Jevons's paradox": improved efficiency leads to greater total consumption. The market is now undergoing a necessary purification, weeding out "API-wrapper" startups with no real moat. The deeper evolution involves a shift from capital expenditure (CapEx) on infrastructure to operational expenditure (OpEx) on value-creation in applications. While hardware vendors currently profit most, long-term value will migrate to AI-native firms solving vertical industry problems. Ultimately, a market correction will cleanse speculative excess but will not reverse the AI+ trend. The massive physical and algorithmic infrastructure being built will endure, becoming a cheap, utility-like foundation. Just as the internet became indispensable to all industries post-2000, AI is poised to empower and redefine every sector, moving society irreversibly toward an intelligence-augmented era. The bubble may burst, but the underlying productive momentum is solid.

链捕手25 хв тому

If the AI Bubble Is Already Bursting, Who Will Truly Remain?

链捕手25 хв тому

Microsoft CEO: In the AI Era, How Do You Define a Company's Moat?

Microsoft CEO Satya Nadella argues that in the AI era, a company's true competitive edge, or "moat," is not determined by choosing the single most powerful model, but by its ability to build a continuous "learning loop." This system integrates and evolves by connecting human workflows, domain expertise, organizational judgment, and employee experience. He posits that future companies will accumulate two types of capital: Human Capital (employee knowledge, judgment, creativity) and "Token Capital" (a firm's own built and owned AI capabilities). Importantly, AI amplifies rather than devalues human capital. Human direction is essential to guide progress, as computational power alone is aimless. The core opportunity lies in creating a closed-loop system where human and token capital reinforce each other in a compound, self-improving cycle. A company must be able to preserve its unique institutional knowledge—its "company veteran" expertise—even if it switches underlying general-purpose AI models. This requires private evaluation benchmarks, reinforcement learning environments based on internal data, and queryable knowledge bases. Nadella warns against a future where economic value is concentrated by a few dominant models that commoditize entire industries' knowledge. Instead, the priority should be building a broad "frontier ecosystem" where every company, industry, and nation can own its learning loop. This allows organizations to retain control of their intellectual property, amplify employee capabilities, and ensure the economic value created by AI is captured within their own businesses and communities. True corporate sovereignty in the AI age comes from turning organizational knowledge into a compounding system that creates enduring, defensible value.

marsbit1 год тому

Microsoft CEO: In the AI Era, How Do You Define a Company's Moat?

marsbit1 год тому

ETFs Are Just the Ticket: The True Institutionalization of Bitcoin Is Happening Where You Can't See It

Beyond the Bitcoin ETF spotlight, a deeper institutionalization is underway, leveraging Bitcoin as a foundational financial primitive. Institutions are using Bitcoin for purposes long reserved for assets like U.S. Treasuries and gold: as collateral for loans, insurance reserves, and the backbone of rated bonds. Examples include a Barbados-based insurer capitalizing with $40M in Bitcoin reserves and Ledn's $188M securitization of Bitcoin-backed loans, which received the first-ever investment-grade rating (BBB-) from S&P for a digital asset-backed security. This structure was stress-tested during a 27% price drop in early 2026, triggering automatic liquidations that functioned as designed but revealed the systemic risk of synchronized selling across leveraged positions. Infrastructure is evolving to support this, with platforms like Anchorage Digital's Atlas network enabling secure, institutional-grade settlement and collateral management. Strategies like basis trades and corporate treasuries (exemplified by companies like MicroStrategy issuing billions in equity and debt to fund Bitcoin acquisitions) further integrate Bitcoin into financial mechanics. While ETFs solved "how to own" Bitcoin, these developments answer "what to do with it," embedding the asset into the working machinery of finance—as collateral upon which loans, derivatives, and structured products are built. The real, enduring institutional shift is happening in these largely invisible plumbing and financing systems.

marsbit1 год тому

ETFs Are Just the Ticket: The True Institutionalization of Bitcoin Is Happening Where You Can't See It

marsbit1 год тому

Торгівля

Спот
Ф'ючерси

Популярні статті

Як купити ZEC

Ласкаво просимо до HTX.com! Ми зробили покупку Zcash (ZEC) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити Zcash (ZEC).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої Zcash (ZEC)Після придбання Zcash (ZEC) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля Zcash (ZEC)Легко торгуйте Zcash (ZEC) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

557 переглядів усьогоОпубліковано 2024.12.12Оновлено 2026.06.02

Як купити ZEC

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни ZEC (ZEC).

活动图片