Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Crypto

Zcash: critical vulnerability allows unlimited minting of fake ZEC

Newsroom by Newsroom
June 5, 2026
in Crypto
Zcash: vulnerabilità critica permette emissione illimitata di ZEC falsi
Share on FacebookShare on TwitterShare on Linkedin

A security researcher discovered a bug in Zcash’s Orchard pool that would have allowed the creation of unlimited quantities of counterfeit tokens.

A security researcher identified a critical vulnerability in the Zcash protocol that could have allowed an attacker to mint “unlimited” counterfeit ZEC within the Orchard pool. The news, made public on Thursday by Shielded Labs – an independent organization supporting Zcash – triggered an immediate collapse in the token’s price.

The price of ZEC plummeted 31% in the 24 hours following the publication of the post, falling to $409.64 at 11:00 PM ET on Thursday. The bulk of the decline was concentrated in the five hours immediately following the announcement. Shielded Labs stated that it had commissioned security engineer Taylor Hornby to conduct a protocol review in April.

Hornby discovered the vulnerability on May 29 using Anthropic’s newly released Opus 4.8 model, combining traditional security research techniques with AI-assisted tools. The findings were immediately shared with engineers at the Zcash Open Development Lab (ZODL). The bug affected the Orchard circuit, the zero-knowledge proof system that guarantees the validity of transactions in Zcash’s shielded pool – the one that allows users to send and receive ZEC with full privacy.

According to the Shielded Labs post, the vulnerability stemmed from an “under-constrained” element of the Orchard circuit, which made it possible to insert arbitrary false inputs into an elliptic curve multiplication while still obtaining transaction approval. “The vulnerability was real and exploitable,” wrote Shielded Labs. “Taylor, with the help of Opus 4.8, wrote a complete exploit that, when tested in a local regtest environment, generated unlimited and undetectable counterfeit ZEC.” The bug had been present since the activation of Orchard in May 2022 and was patched on June 1.

Despite the severity of the discovery, Shielded Labs stated it was not “overly concerned” that actual exploitation had taken place before the fix. The team emphasized that the vulnerability had gone unnoticed for years, even under the scrutiny of the world’s top cryptographers. However, the privacy properties of the Orchard pool make it impossible to definitively rule out a prior exploit. “The discovery was not accidental – it was the result of a deliberate effort to identify vulnerabilities of this type before malicious actors could,” the post reads.

Shielded Labs is currently exploring a network upgrade that would allow anyone to verify the integrity of Zcash’s supply and demonstrate the absence of counterfeit tokens in the Orchard pool. The proposal would also include the deployment of a new shielded pool and the enforcement of turnstile accounting on all coins held in the Orchard pool. “This was a serious bug, and we believe it is important to be transparent about what it means for Zcash users,” the team concluded.

Previous Post

Bitcoin: over $600 million in longs liquidated as BTC heads toward $60,000

Next Post

Meta is paying creators in USDC

Latest News

BancaStato lancia il trading Bitcoin tramite Sygnum e Avaloq
Bitcoin

BancaStato launches Bitcoin trading via Sygnum and Avaloq

by Newsroom
July 24, 2026
0

The Ticino cantonal bank integrates Bitcoin into its digital channels, relying on Sygnum's infrastructure and the Avaloq core banking platform

Read moreDetails
Report BIS: la Banca dei Regolamenti Internazionali boccia le stablecoin
Feature

When the BIS discovers its own irrelevance

by Federico Rivi
July 24, 2026
0

The central bank of central banks warns that dollar stablecoins bypass capital controls, fearing the erosion of its own relevance...

Read moreDetails
ledger bug
Industry

Flaw in Zilliqa’s Ledger app exposes users’ private keys

by Newsroom
July 23, 2026
0

Zilliqa reports that the vulnerability generates predictable ephemeral nonces, allowing an attacker to reconstruct a user's private key from publicly...

Read moreDetails
Industry

Jack Dorsey launches Buzz, an open-source AI agent workspace built on Nostr

by Newsroom
July 23, 2026
0

The platform assigns cryptographic identities to AI agents on a permissionless protocol, moving control outside centralised servers

Read moreDetails
Bitcoin

Wavelength: Lightning Labs brings bitcoin to any app with a single API call

by Newsroom
July 22, 2026
0

Lightning Labs' new toolkit adds a self-custodial bitcoin wallet to any application with a few API calls: no node to...

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team

Follow Us

Italiano
No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.