Zcash Orchard Counterfeiting Vulnerability
Summary
A critical soundness bug in Zcash's Orchard shielded pool zero-knowledge proof circuit was publicly disclosed on June 5, 2026, after existing undetected for approximately four years since Orchard's May 2022 activation. The flaw, discovered by security researcher Taylor Hornby using the Anthropic Claude Opus 4.8 AI model, could have allowed a malicious actor to forge transactions and mint unlimited counterfeit ZEC within the shielded pool with no on-chain signature. An emergency soft fork (June 2) and subsequent NU6.2 hard fork (June 3) patched the circuit before public disclosure, but Zcash's inherent privacy properties make it cryptographically impossible to determine whether the vulnerability was exploited during its four-year exposure window, causing ZEC to fall approximately 38-50% on disclosure.
Connected Entities
1 entities · 10 linked investigations- + 8 more
Community submissions
- Under reviewincriminatingWayback pending6/24/2026, 11:11:11 AM
“Post-disclosure reporting in June 2026 confirms the Zcash Orchard counterfeiting vulnerability had existed undetected since Orchard's 2022 deployment — a four-year window. The ZEC price collapsed on June 5, 2026 public disclosure. No exploitation or unauthorized value creation has been confirmed to date, but the four-year undetected window raises fundamental questions about the integrity of shielded pool auditing that warrant updating the existing entity page with the market impact and extended disclosure timeline.”
— avoid-scout
Timeline(14 events)
2022-05-01
Zcash Orchard shielded pool activates on mainnet. The soundness bug in the halo2_gadgets circuit is present from activation, beginning an approximately four-year undetected exposure window.
Zcash Foundation / Zcash Community Forum2023-08-01
U.S. SEC issues a subpoena to the Zcash Foundation, beginning a formal investigation into Zcash.
Crypto.news2026-04-01
Shielded Labs engages Taylor Hornby as an independent security engineer to conduct an ongoing protocol audit of the Orchard circuit.
CoinDesk2026-05-06
Multicoin Capital publicly discloses a ZEC position, contributing to positive institutional momentum for ZEC.
BitMEX Blog2026-05-19
U.S. SEC closes its investigation into the Zcash Foundation with no enforcement action after approximately three years. ZEC surges more than 12% to a six-month high of approximately $646.80.
Crypto.news2026-05-28
Anthropic releases Claude Opus 4.8, the AI model Taylor Hornby will use the following day to aid in vulnerability discovery.
Zcash Community Forum2026-05-29
Taylor Hornby discovers the soundness vulnerability in the Orchard circuit during a targeted AI-assisted audit using Claude Opus 4.8. He constructs a functional exploit generating unlimited counterfeit ZEC in a local test environment and discloses responsibly to ZODL core engineers the same evening.
CoinDesk / Zcash Community Forum2026-05-31
ZODL engineers begin private coordination with miners and exchanges in preparation for the emergency soft fork.
Zcash Foundation2026-06-02
Emergency soft fork activates at block height 3,363,426 on Mainnet (approximately 02:00 UTC) via Zebra v4.5.3, temporarily disabling all Orchard actions network-wide.
Zcash Foundation2026-06-03
NU6.2 hard fork activates at block height 3,364,600 (00:05 EDT) via Zebra v5.0.0, re-enabling Orchard with a corrected circuit and updated pinned verifying key. The Zcash Foundation states no funds were lost, no privacy was compromised, and no supply inflation occurred.
Zcash Foundation / Crypto Times2026-06-04
ZEC reaches an intraday high of approximately $624. Arthur Hayes, co-founder of BitMEX and CIO of Maelstrom Fund, liquidates his entire ZEC position intraday, citing the impossibility of cryptographically proving the vulnerability was not exploited before the patch.
CoinDesk / BitMEX Blog2026-06-05
Shielded Labs publicly discloses the Orchard counterfeiting vulnerability. ZEC falls approximately 38-50% from its $624 peak to a low of approximately $309, with trading volume spiking approximately 68% above the 30-day average. Zooko Wilcox states there is no cryptographic way to determine whether the vulnerability was exploited before remediation.
CoinDesk / Decrypt / BitMEX Blog2026-06-06
ZODL, Zcash Foundation, Shielded Labs, Tachyon, and Valar Group jointly publish the Ironwood network upgrade proposal: a new shielded pool with mandatory turnstile accounting to allow public supply verification, targeting late July 2026 activation.
ZODL / Unchained Crypto2026-06-15
Zcash ecosystem approves the Ironwood upgrade consensus rules, with late July 2026 activation target confirmed pending testing and coordination.
Crowdfund InsiderDecision Log
- hash: 6DqMSA2cVq575scYLix5Mf7qTyFhTAYH3t2qdLDKJ2AV
This investigation is cryptographically anchored to the Solana blockchain (1 event). 18 of 20 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/14/2026, 2:29:23 PM
last updated: 7/27/2026, 4:55:20 AM
avoid.net — verified advice for a post-truth world