Close Menu
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Facebook X (Twitter) Instagram
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Cryphedge.com
Home » Zcash Plunges After Four-Year Bug Could Have Allowed Unlimited Token Minting
Zcash Plunges After Four-Year Bug Could Have Allowed Unlimited Token Minting

Zcash Plunges After Four-Year Bug Could Have Allowed Unlimited Token Minting

June 6, 20265 Mins ReadNo Comments NFT News
Share
Facebook Twitter LinkedIn Pinterest Email

Zcash (the token is known as ZEC) is facing a massive wave of skepticism after the development community published details about a critical vulnerability in Orchard, the network’s latest shielded pool. ZEC plunged over 50% at one point following this information, before recovering to $367.35 on June 6.

The vulnerability was discovered on May 29 by security researcher Taylor Hornby and was fixed through an emergency upgrade a few days later. Zcash Open Development Lab (ZODL) stated that there is no evidence that the bug was ever exploited or that unauthorized ZEC was created. However, this bug could allow counterfeit ZEC to be created within Orchard, while the private design of this pool makes it difficult to definitively prove that it was never exploited.

What Happened 

The vulnerability was discovered on May 29 in Orchard, where transactions are verified using zero-knowledge proofs to maintain user privacy. According to the Zcash Open Development Lab, security researcher Taylor Hornby discovered the bug during an audit commissioned by Shielded Labs and reported it to the ZODL engineering team shortly thereafter. 

The issue lies within Orchard’s transaction verification mechanism. If exploited, this vulnerability could cause the system to accept invalid transactions within Orchard. ZODL confirmed the report within hours and began preparing a mitigation plan with network operators. 

Due to the bug involving consensus rules, Zcash had to handle it via a network upgrade rather than a standard wallet or node update. ZODL first paused Orchard-related activities through a soft fork to limit risks, then deployed a hard fork to update the fixed circuit and restore Orchard.

Main Timeline: 

  • May 29: Taylor Hornby discovers and reports the Orchard vulnerability to ZODL. 
  • May 30-31: ZODL confirms the bug, prepares the patch, and begins private coordination with miners, exchanges, and infrastructure operators. 
  • June 1-2: Zcash activates the soft fork, pausing the creation of new outputs and the spending of existing balances within Orchard. 
  • June 3: The hard fork is completed, and Orchard is reactivated with the fixed circuit.

Why the Bug Mattered 

The critical point of the Orchard bug lies in soundness—the ability to guarantee that the system only accepts valid proofs and states. When this guarantee is broken, a proof can be accepted even if the state behind it does not comply with the protocol’s rules. 

According to an article by Zooko Wilcox, Jason McGee, and Taylor Hornby, Hornby successfully created a full exploit in a local test environment. In that environment, the exploit could create counterfeit ZEC within Orchard without being detected. 

https://t.co/v7BiOdzU9E

— zooko🛡🦓🦓🦓 ⓩ (@zooko) June 4, 2026

If a similar bug were exploited on the mainnet, the consequence would not just be a single incorrect transaction being accepted. It could distort the accounting of the shielded pool and directly raise questions about the integrity of the ZEC supply.

What Remains Unclear 

ZODL stated that there is no evidence that the vulnerability was ever exploited, no unauthorized creation of ZEC has been detected, and no impact on the privacy of assets in Zcash’s pools has been recorded. The group also said the total supply of ZEC remained safe following checks during the incident response.

What remains unclear is whether the vulnerability had been exploited before being patched. Shielded Labs stated that due to the private nature of this pool, it is impossible to rely solely on existing cryptographic evidence to absolutely confirm that the vulnerability was never exploited before being patched. Even so, the group assesses the likelihood of prior exploitation as low, given that the bug is difficult to detect and the ecosystem’s response was rapid after receiving the report.

Market Reaction 

ZEC at one point fell over 50% from the $600 range to below $260 after information about the Orchard vulnerability spread. According to CoinGecko data, the token is currently trading around $367.35, down 10.8% in 24 hours, with trading volume over the same period reaching $3.35 billion.

Zcash Plunges After Four-Year Bug Could Have Allowed Unlimited Token Minting

ZEC price chart (1D). Source: TradingView

In the context of Zcash having a maximum supply of 21 million ZEC, information about a bug that could create counterfeit ZEC in a shielded pool quickly shifted the narrative from a technical issue to a question of trust in the supply.

How Zcash Responded 

ZODL stated that the remediation process required network-level coordination because the bug was consensus-related. Miners, exchanges, node operators, wallets, infrastructure, and other independent parties had to collectively deploy updated software for the upgrade to activate successfully. 

The response was deployed with a risk-mitigation-first approach, followed by a complete resolution: Orchard was temporarily paused while the network prepared for the upgrade, then restored when the fixed circuit was activated. ZODL stated that relevant node software and wallet SDKs were also updated following the upgrade. 

According to ZODL, this is the second security-driven protocol upgrade in Zcash’s history since the network launched in 2016. ZODL stated that relevant node software and wallet SDKs were updated following the upgrade.

What Comes Next 

Shielded Labs stated they are working on a new network upgrade proposal so that users can verify the integrity of the Zcash supply more directly. The idea being discussed is to deploy a new shielded pool and apply turnstile accounting to assets leaving Orchard, thereby checking whether the old pool contains invalid values. 

This proposal still needs to go through Zcash’s standard governance process before it can be activated. Shielded Labs also stated they are preparing to publish more details about this option and begin a formal verification project for the Orchard circuit. For now, the vulnerability has been patched, and Orchard is back online. The next focus is whether Zcash can present a convincing enough mechanism to address the uncertainty regarding the supply in the period before the patch was deployed.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
cryphedge

Related Posts

Cardano Foundation CEO Urges Calm as ADA Slides to Late-2020 Lows

June 6, 2026

Mastercard Enables Stablecoin Settlement Across Eight Blockchains

June 5, 2026

Coinbase and Better Fund First Fannie Mae-Backed Bitcoin Mortgage

June 5, 2026

Bitcoin Treasury Firms Shed $62 Billion in Deepening Crypto Rout

June 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Hyperliquid’s UK warning reveals the regulatory test behind its Wall Street push

June 6, 2026

Has Ethereum (ETH) Price Finally Bottomed? Here’s Where It Could Head in June 2026

June 6, 2026

Is CC Price Poised For $0.20 With Rising Institutional Interest?

June 6, 2026

Zcash Plunges After Four-Year Bug Could Have Allowed Unlimited Token Minting

June 6, 2026
About

cryphedge is an online news portal that aims to share the latest crypto news, bitcoin, altcoin, blockchain, nft news, regulation, trading, crypto scams and much more stuff.

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

How Likely Is a Shiba Inu (SHIB) ETF? See If the SEC Will Approve

September 28, 2025

Echelon Strengthens Esports with $3M Commitment to Parallel

January 21, 2025

Mantra CEO vows token burn to regain investor trust after OM collapse

April 15, 2025
Subscribe
Please enable JavaScript in your browser to complete this form.
Loading
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$60,558.00-1.60%
  • ethereumEthereum(ETH)$1,558.17-2.44%
  • tetherTether(USDT)$1.00-0.02%
  • binancecoinBNB(BNB)$572.43-0.80%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.09-1.90%
  • solanaSolana(SOL)$61.76-4.16%
  • tronTRON(TRX)$0.3234140.66%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.46%
  • dogecoinDogecoin(DOGE)$0.081414-1.71%
  • HyperliquidHyperliquid(HYPE)$56.56-5.36%
  • USDSUSDS(USDS)$1.00-0.03%
  • leo-tokenLEO Token(LEO)$9.45-1.31%
  • RainRain(RAIN)$0.012832-2.61%
  • stellarStellar(XLM)$0.2116313.14%
  • CantonCanton(CC)$0.1603847.69%
  • zcashZcash(ZEC)$354.56-5.63%
  • cardanoCardano(ADA)$0.156265-2.08%
  • moneroMonero(XMR)$293.41-7.67%
  • chainlinkChainlink(LINK)$7.36-1.48%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$43.17-2.37%
  • USD1USD1(USD1)$1.000.04%
  • Ethena USDeEthena USDe(USDE)$1.00-0.02%
  • ToncoinToncoin(TON)$1.647.75%
  • bitcoin-cashBitcoin Cash(BCH)$216.350.10%
  • daiDai(DAI)$1.00-0.01%
  • LABLAB(LAB)$13.4535.01%
  • MemeCoreMemeCore(M)$2.982.84%
  • hedera-hashgraphHedera(HBAR)$0.079581-1.82%
  • litecoinLitecoin(LTC)$41.05-5.89%
  • suiSui(SUI)$0.71-0.02%
  • avalanche-2Avalanche(AVAX)$6.64-2.68%
  • PayPal USDPayPal USD(PYUSD)$1.00-0.02%
  • Circle USYCCircle USYC(USYC)$1.130.00%
  • shiba-inuShiba Inu(SHIB)$0.000005-1.56%
  • tether-goldTether Gold(XAUT)$4,284.87-0.50%
  • crypto-com-chainCronos(CRO)$0.0580790.15%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • nearNEAR Protocol(NEAR)$1.85-6.73%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.12-1.39%
  • pax-goldPAX Gold(PAXG)$4,290.28-0.84%
  • BittensorBittensor(TAO)$192.75-2.49%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.055406-3.77%
  • mantleMantle(MNT)$0.51-1.10%
  • Ripple USDRipple USD(RLUSD)$1.000.01%
  • AsterAster(ASTER)$0.620.06%
  • polkadotPolkadot(DOT)$0.94-2.43%
  • HTX DAOHTX DAO(HTX)$0.000002-0.05%
  • OndoOndo(ONDO)$0.323325-7.73%
  • uniswapUniswap(UNI)$2.44-1.63%
  • Falcon USDFalcon USD(USDF)$1.00-0.07%
  • okbOKB(OKB)$68.79-3.13%
  • WorldcoinWorldcoin(WLD)$0.416883-23.38%
  • usddUSDD(USDD)$1.000.03%
  • Pi NetworkPi Network(PI)$0.1245250.05%
  • BFUSDBFUSD(BFUSD)$1.000.04%
  • SkySky(SKY)$0.055181-6.11%
  • bitget-tokenBitget Token(BGB)$1.830.49%
  • internet-computerInternet Computer(ICP)$2.30-1.80%
  • HumanityHumanity(H)$0.624.89%
  • PepePepe(PEPE)$0.000003-2.25%
  • ethereum-classicEthereum Classic(ETC)$6.77-1.54%
  • MorphoMorpho(MORPHO)$1.64-2.26%
  • USDtbUSDtb(USDTB)$1.000.02%
  • United StablesUnited Stables(U)$1.00-0.02%
  • Spiko EU T-Bills Money Market FundSpiko EU T-Bills Money Market Fund(EUTBL)$1.210.01%
  • Blockchain CapitalBlockchain Capital(BCAP)$107.060.00%
  • quant-networkQuant(QNT)$66.62-0.48%
  • Superstate Short Duration U.S. Government Securities Fund (USTB)Superstate Short Duration U.S. Government Securities Fund (USTB)(USTB)$11.100.00%
  • DeXeDeXe(DEXE)$20.042.05%
  • aaveAave(AAVE)$60.38-4.63%
  • Janus Henderson Anemoy Treasury FundJanus Henderson Anemoy Treasury Fund(JTRSY)$1.110.00%
  • EthenaEthena(ENA)$0.089806-5.17%
  • cosmosCosmos Hub(ATOM)$1.62-2.81%
  • render-tokenRender(RENDER)$1.59-6.68%
  • algorandAlgorand(ALGO)$0.092228-1.92%
  • POL (ex-MATIC)POL (ex-MATIC)(POL)$0.077130-0.98%
  • kaspaKaspa(KAS)$0.029959-4.24%
  • kucoin-sharesKuCoin(KCS)$6.08-3.02%
  • 币安人生 (BinanceLife)币安人生 (BinanceLife)(币安人生)$0.8015.05%
  • ​​Stable​​Stable(STABLE)$0.0332295.01%
  • nexoNEXO(NEXO)$0.74-0.44%
  • Venice TokenVenice Token(VVV)$15.47-13.55%
  • justJUST(JST)$0.0830093.08%
  • gatechain-tokenGate(GT)$6.11-1.99%
  • AudieraAudiera(BEAT)$2.2224.75%
  • SirenSiren(SIREN)$0.8514.15%
  • BeldexBeldex(BDX)$0.078472-0.64%
  • xdce-crowd-saleXDC Network(XDC)$0.0294300.14%
  • GHOGHO(GHO)$1.000.02%
  • FlareFlare(FLR)$0.006716-0.17%
  • filecoinFilecoin(FIL)$0.73-2.74%
  • Usual USDUsual USD(USD0)$1.00-0.01%
  • aptosAptos(APT)$0.65-3.47%
  • YLDSYLDS(YLDS)$1.00-0.01%
  • MidnightMidnight(NIGHT)$0.030866-1.82%
  • A7A5A7A5(A7A5)$0.013063-0.44%
  • injective-protocolInjective(INJ)$5.11-1.68%
  • Provenance BlockchainProvenance Blockchain(HASH)$0.0094631.07%