Skip to main content
AVOID.NET

Zcash Orchard Pool Counterfeiting Vulnerability 2026

avoid.net/zcash-orchard-pool-counterfeiting-vulnerability-2026→28/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3Sxz8n…A5L2

Summary

On June 5, 2026, Shielded Labs publicly disclosed a critical soundness flaw in the zero-knowledge proof circuit of Zcash's Orchard shielded pool that had existed undetected since the pool's activation in May 2022. The vulnerability, found by security engineer Taylor Hornby using Anthropic's Claude Opus 4.8 AI model, could have allowed unlimited undetectable counterfeit ZEC minting with no on-chain signature; an emergency hard fork patched the circuit by June 3, 2026. Because Orchard's privacy design conceals transaction history, no cryptographic method exists to determine whether the flaw was exploited during the four years it was present, leaving the supply integrity of shielded ZEC permanently unverifiable for that period.

Connected Entities

2 entities · 26 linked investigations
Organizations
□BitMEX56□Zcash Orchard Pool Counterfeiting Vulnerability 2026
Relationships
  • Zcash Orchard Pool Counterfeiting Vulnerability 2026→mentioned with→BitMEX(65%)
Have evidence about Zcash Orchard Pool Counterfeiting Vulnerability 2026?

Timeline(10 events)

May 2022

Zcash Orchard shielded pool activated on mainnet, beginning the period during which the counterfeiting vulnerability was present and undetected.

CoinDesk

April 2026

Shielded Labs engages Taylor Hornby as an independent security engineer to conduct a targeted protocol security audit of Zcash.

Unchained Crypto

28 May 2026

Anthropic releases Claude Opus 4.8 model.

Unchained Crypto

29 May 2026

Taylor Hornby discovers the soundness flaw in the Orchard zero-knowledge proof circuit using Claude Opus 4.8 in an AI-assisted audit. He discloses the vulnerability to Zcash Open Development Lab (ZODL) and creates a working exploit in a local test environment.

CoinDesk

June 2026

Emergency soft fork coordination begins; Zebra 4.5.3 release prepared to disable Orchard transactions at a specific block height.

CryptoTimes

2 June 2026

Emergency soft fork activates at mainnet block height 3,363,426 at approximately 02:00 UTC, temporarily disabling all Orchard transactions. A 25-block fork and 37 orphaned blocks result from nodes running outdated software.

CryptoTimes

3 June 2026

NU6.2 hard fork activates at block height 3,364,600 via Zebra 5.0.0, re-enabling the Orchard pool with a corrected circuit that introduces a copy_advice() equality constraint. ZEC briefly rallies from approximately $544 to $624.

CoinTelegraph

4 June 2026

ZEC reaches a local high of approximately $624 in the aftermath of the confirmed patch. Arthur Hayes holds ZEC as his second-largest fund position at this point.

BitMEX Blog

5 June 2026

Shielded Labs publishes the public disclosure of the Orchard counterfeiting vulnerability, authored by Jason McGee. ZEC crashes approximately 38-50% within 24-48 hours, falling to a low of $309. Arthur Hayes publicly announces he has liquidated his entire Zcash position, citing that the exploit's occurrence cannot be cryptographically ruled out.

CoinDesk

15 June 2026

Shielded Labs updates the original disclosure post, per page metadata on the official article.

Shielded Labs
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 6/29/2026, 12:18:51 PM

last updated: 7/27/2026, 6:38:44 AM

3 views

avoid.net — verified advice for a post-truth world