Zcash Price Plunges After Undetectable Counterfeiting Vulnerability Spurs Crypto Security Debate

Zcash shares in the “Orchard” shielded pool fell sharply after developers disclosed a dormant vulnerability that could have enabled counterfeiting of ZEC without an on-chain trace, and which they say has no cryptographic way to prove was not exploited before it was patched. Multiple reports pegged the selloff at roughly the high-30% range, with some estimates reaching past 50% before partial rebounds as an emergency fix went out in early June and broader remediation followed shortly after. The flaw, stemming from an under-constrained element in the Orchard circuit, was identified by security researcher Taylor Hornby using AI-assisted auditing, and developers said it had been present since Orchard’s activation in May 2022. Beyond the specific bug, the episode reignited concerns that privacy-centric transaction systems can make certain attacks difficult or impossible to verify after the fact, unlike more transparent networks. Looking ahead, the incident is prompting discussion of longer-term technical changes, including potential upgrades to improve supply accountability and public verifiability of ZEC issuance.
CoinGecko data showed Zcash’s sharpest move: it fell from about $635 (Wednesday’s local top) to an intraday low of $309 on Thursday, then only partially recovered to around $330—down 37.8% on the day.
Zcash founder Zooko Wilcox said on X that security researcher Taylor Hornby discovered the vulnerability on May 29, using a custom auditing-agent framework paired with the newly released Opus 4.8 AI model.
Shielded Labs’ disclosure gave a specific timeline and emphasized the limits of cryptography: “The vulnerability was present from Orchard’s activation in May 2022 until the emergency fix was deployed on June 1, 2026,” and “there is no definitive way to determine, using only cryptography, whether such exploitation occurred.”
Independent privacy-crypto experts said this bug class is familiar: Joe Andrews, CEO of privacy-first studio Aztec Labs, said “under-constrained elliptic curve checks” are “among the most common weaknesses in production ZK circuits.”
In addition to broader “public verifiability” discussion, developers said they are researching an upgrade to implement a new shielded pool and “enforce turnstile accounting” so the ZEC supply can be publicly verified.
Publishers
25
Articles
16
Reach
41