Zcash's Orchard shielded pool had a critical counterfeiting vulnerability discovered May 29, 2026 allowing unlimited undetectable ZEC creation; it was patched via emergency response after disclosure to ZODL.
Security & Exploits ·
A critical counterfeiting vulnerability in Zcash's Orchard shielded pool was discovered on May 29, 2026 by security researcher Taylor Hornby during targeted audits using Anthropic's Opus 4.8 AI. The flaw stemmed from an under-constrained elliptic curve multiplication and had been present since the pool's 2022 activation, enabling the creation of unlimited undetectable counterfeit ZEC.
The vulnerability allowed attackers to generate fake ZEC without detection, a critical failure for a privacy-focused asset. Upon discovery, the flaw was rapidly disclosed to ZODL and addressed through emergency response protocols, preventing widespread exploitation.
However, significant uncertainty remains regarding the actual scope of prior misuse. Orchard's privacy architecture prevents cryptographic proof of whether the vulnerability was exploited before the patch, leaving open whether malicious actors had already created undetected counterfeit coins during the four-year window since the pool's launch.