Zcash fixes critical Orchard bug as ZEC price tumbles over 30%
Zcash developers patched a critical flaw in the Orchard shielded pool that could have allowed unlimited minting of counterfeit ZEC. The vulnerability, present since May 2022, was disclosed privately by security researcher Taylor Hornby on May 29 after he used an AI tool (Claude Opus 4.8) to test the circuit. An emergency hard‑fork was activated on June 3 to close the bug.
Following the disclosure, ZEC fell more than 30% in a single day, wiping out roughly $3 billion in market capitalisation. While no direct evidence of exploitation exists, the privacy nature of Orchard makes it impossible to prove whether counterfeit coins were ever minted. Developers are proposing a supply‑verification upgrade to let the community audit the token supply and restore confidence.
The incident highlights a recurring theoretical risk in zero‑knowledge privacy protocols, though Zcash’s team noted the bug survived years of expert review and was only identified through a targeted AI‑assisted audit.