GoPlus Security details ZEC Orchard infinite mint flaw active since May 2022

A missing constraint in the halo2 library allowed counterfeit ZEC creation and double-spending in Orchard until a June 1 patch, according to the firm's analysis.

Summary

GoPlus Security published a detailed analysis of an Orchard infinite mint vulnerability affecting ZEC. The issue stemmed from a missing constraint in the halo2 library, which the firm said allowed unlimited counterfeit ZEC minting and double-spending from May 2022 until it was patched on June 1. The report points to a serious failure in a zero-knowledge proof component, where an omitted verification condition can let invalid transactions appear legitimate and undermine a network’s supply integrity.

Terms & Concepts
  • Orchard: Zcash shielded payment protocol
  • halo2 library: Zero-knowledge proof software library
  • double-spending: Spending the same funds twice