A missing constraint in the halo2 library allowed counterfeit ZEC creation and double-spending in Orchard until a June 1 patch, according to the firm's analysis.
GoPlus Security published a detailed analysis of an Orchard infinite mint vulnerability affecting ZEC. The issue stemmed from a missing constraint in the halo2 library, which the firm said allowed unlimited counterfeit ZEC minting and double-spending from May 2022 until it was patched on June 1. The report points to a serious failure in a zero-knowledge proof component, where an omitted verification condition can let invalid transactions appear legitimate and undermine a network’s supply integrity.