< Back to all clusters
[TECHNOLOGY] · 2 sources

Zcash patches critical Orchard pool flaw as token rebounds 70%

A critical security flaw was discovered in Zcash's Orchard privacy pool on May 29, 2026. The vulnerability, identified by researcher Taylor Hornby, could have allowed the creation of unlimited ZEC tokens by bypassing input‑validation checks.

The Zcash development team, through the Zcash Open Development Lab (ZODL), responded with an emergency soft fork to temporarily disable Orchard transactions, followed by a hard fork (NU6.2) on June 3 that repaired the code and re‑enabled the pool. No evidence of exploitation has been reported, and the fix has been deployed to the network.

The vulnerability triggered a sharp price drop of more than 60%, taking ZEC from around $630 to a low of $250. After the patches were applied, the token recovered, gaining about 70% to trade near $428. Investors are monitoring the situation as the community assesses the long‑term impact on Zcash's privacy guarantees.