Zcash tumbles after founder says Orchard bug enabled counterfeit ZEC minting

A flaw in Zcash’s Orchard shielded pool, patched on June 1 after reportedly being active since May 2022, raised concerns that counterfeit ZEC could have been created undetectably within the privacy-focused system.

ZEC

Summary

Zcash’s ZEC fell more than 40% after disclosure of a critical vulnerability in Orchard, Zcash’s newer shielded payment system and shielded pool, that founder said could have allowed unlimited counterfeit minting of ZEC. The flaw was patched on June 1 and, according to the founder’s post, had been active since May 2022, though earlier reports said it had gone undetected for about four years. The issue renewed scrutiny of privacy-focused cryptocurrency designs because shielded systems can protect user privacy while making some forms of auditing and anomaly detection harder when supply-integrity flaws emerge. Reports said Anthropic’s Claude helped demonstrate the exploit, while the founder’s post said Claude Opus 4.8 was used in the fix or remediation.

Terms & Concepts
  • Orchard: Zcash’s newer shielded payment system and shielded pool design.
  • counterfeit minting: Unauthorized creation of new tokens beyond protocol limits.
  • shielded pool: A privacy-preserving pool on Zcash that hides transaction details.