Zcash Foundation releases Zebra 4.5.3 and 5.0.0 to fix Orchard flaw

The update addresses a critical vulnerability in the Orchard Action circuit, with Zebra 4.5.3 temporarily disabling Orchard through a time-sensitive network upgrade at a specified block.

Summary

Zcash Foundation has released Zebra 4.5.3 and 5.0.0 to remediate a critical vulnerability affecting the Orchard Action circuit. As a containment measure, Zebra 4.5.3 temporarily suspended Orchard functionality through a time-sensitive network upgrade activated at a specified block. The move suggests the foundation prioritized an immediate protocol-level response to limit exposure while rolling out patched software.

Terms & Concepts
  • Orchard Action circuit: A Zcash circuit tied to Orchard shielded actions.
  • network upgrade: A protocol change activated at a set block height.
  • Zebra: Zcash Foundation's node software implementation.