Dragonfly’s Haseeb says fixed Zcash flaw was limited to privacy pool

Dragonfly’s Haseeb says fixed Zcash flaw was limited to privacy pool

He said forged ZEC could not reach mainstream exchanges without becoming publicly visible on transparent addresses, and said a future upgrade will add a new Turnstile mechanism and privacy pool.

ZEC

Fact Check
Haseeb's primary X posts (https://x.com/hosseeb/status/2062889228090871994 and /2062918102929518743) directly state that the bug was confined to the shielded (privacy) pool, that counterfeit ZEC would need to be unshielded onto transparent addresses where total supply is publicly verifiable to reach exchanges, and that Zcash will deploy a new turnstile and shielded pool. The odaily and WuBlockchain summaries corroborate these points.
Summary

Market fears around a recently fixed Zcash vulnerability overstate the practical risk, Dragonfly managing partner Haseeb said, arguing the flaw would only have let an attacker forge ZEC inside the shielded pool and that exploiting it before the patch was very unlikely. Any attempt to move those coins to mainstream exchanges would require unshielding them into transparent addresses, where any supply above Zcash's cap would be publicly visible and could be blocked, he said. Haseeb added that about 30% of ZEC remains in the shielded pool and only about 1% was unshielded after disclosure. He also said exchanges such as Binance and Coinbase mostly trade transparent ZEC, that Zcash plans a future upgrade with a new Turnstile mechanism and privacy pool, and disclosed that Dragonfly still holds ZEC while he is personally a ZODL investor.

Terms & Concepts
  • privacy pool: shielded pool for private transactions
  • transparent addresses: publicly visible Zcash wallet addresses
  • Turnstile mechanism: supply-checking conversion process