THORChain delays ZEC launch over Zcash vulnerability as network remains offline after $10.7 million exploit

The protocol has been down for three weeks after a vault attack tied to the GG20 threshold signature scheme, while Zcash integration slipped further after a bug in Orchard triggered an emergency fix.

RUNE
ZEC

Summary

THORChain remains offline three weeks after a $10.7 million exploit drained one of its vaults through a flaw in the GG20 threshold signature scheme, delaying broader recovery efforts and pushing back its planned Zcash integration. Developers have released version 3.19 and added a new “key verify” safety step before restarting, with node operators expected to upgrade software, migrate funds and then reopen trading over several days once the process begins. The recovery plan, ADR028, is designed to absorb the loss without minting new RUNE, using protocol funds first and passing any remainder to synthetic asset holders, while also offering the attacker a bounty to return the funds. ZEC had already stayed in THORChain’s launch queue, but the timeline slipped further after security researcher Taylor Hornby, working under contract with Shielded Labs, found a soundness bug in Zcash’s Orchard shielded pool. Zcash temporarily disabled Orchard transactions in a June 2 soft fork and restored the pool with a corrected circuit in the NU6.2 hard fork on June 3. After the flaw was disclosed, ZEC fell roughly 40% within 24 hours, with CoinMarketCap data showing it near $333, down from a 52-week high above $700.

Terms & Concepts
  • GG20 threshold signature scheme: A security system used to coordinate signing across multiple participants; a flaw in it was exploited in THORChain’s vault attack.
  • synthetic asset holders: Users holding protocol-created assets that track the value of other assets rather than the original tokens themselves.
  • Orchard shielded pool: Zcash’s privacy-focused transaction pool, where a bug led to an emergency software fix.