Zcash vulnerability disclosure sends ZEC down 38%
Security & Exploits ·
A four-year-old flaw in Zcash's Orchard shielded pool could have let an attacker mint unlimited counterfeit ZEC without leaving any on-chain trace, and its disclosure wiped more than a third off the token's price overnight.
ZEC fell from a local top of $635 on Wednesday to an intraday low of $309 on Thursday, Decrypt reported, before recovering slightly to around $330, down 37.8% on the day. The bug sat in two lines of code within the Orchard circuit, the cryptographic component that governs Zcash's shielded transactions, and was found on May 29 by security researcher Taylor Hornby using AI-assisted auditing tools. Shielded Labs, the organization behind Zcash development, said the vulnerability existed from Orchard's activation in May 2022 until an emergency fix was deployed on June 1, 2026.
The core problem is not just that the bug existed, but that its exploitation cannot be ruled out after the fact. Shielded Labs wrote that "there is no definitive way to determine, using only cryptography, whether such exploitation occurred," since Orchard's privacy properties hide the very evidence that would confirm an attack took place. That distinction has drawn criticism from commentators who argue privacy coins carry a structural risk absent in transparent chains like Bitcoin or Ethereum, where on-chain exploitation would be immediately visible.
The flaw falls into a category known as under-constrained elliptic curve checks, described as among the most common weaknesses in production zero-knowledge circuits, according to Aztec Labs CEO Joe Andrews, who noted the pattern is not new to Zcash and that AI is speeding up discovery of such bugs across the industry. Andrews said the durable fix is formal circuit verification paired with a second proof system, an approach he said Ethereum is already pursuing, so that both systems must agree before a state transition is considered valid.
Market reaction has been mixed. Arthur Hayes said he liquidated his entire ZEC position following the disclosure, even while calling exploitation "extremely unlikely," because it cannot be formally proven impossible. The immediate risk to holders is framed not as chain-wide inflation but as potential insolvency within the Orchard pool itself, where shielded ZEC holders could be diluted if counterfeit claims competed against legitimate ones for a finite balance. Cypherpunk Technologies, a treasury firm whose shares fell around 40% alongside the news, reaffirmed plans to accumulate 5% of ZEC supply while investing in formal verification work.
What remains unresolved is whether any counterfeiting actually occurred during the four-year exposure window, a question Shielded Labs says cryptography alone cannot answer, leaving the market to weigh a fixed bug against an unresolved trust gap.