- Researchers discovered a critical flaw in Zcash’s Orchard privacy pool.
- The vulnerability could have allowed attackers to mint unlimited counterfeit ZEC.
- The issue was identified using AI-assisted security analysis.
- Developers patched the flaw within days of discovery.
- Teams believe real-world exploitation was unlikely.
AI-assisted research uncovers serious flaw
A security researcher has uncovered one of the most significant vulnerabilities in Zcash’s history, revealing a flaw that could have allowed attackers to generate unlimited counterfeit ZEC within the network’s Orchard shielded transaction pool.
The vulnerability was discovered by security engineer Taylor Hornby during an independent review commissioned by Shielded Labs, a support organization focused on the Zcash ecosystem. Hornby identified the issue on May 29 while using Anthropic’s Opus 4.8 AI model alongside traditional security auditing techniques.
According to Shielded Labs, the flaw was severe enough that a working exploit successfully generated unlimited counterfeit ZEC during testing in a local development environment.
How the vulnerability worked
The issue originated from an under-constrained component inside the Orchard zero-knowledge proof circuit. This weakness allowed attackers to provide false inputs during cryptographic calculations while still producing transactions that appeared valid to the network.
Because Orchard powers Zcash’s privacy-preserving transactions, any successful exploit could have created counterfeit coins without immediate detection.
The vulnerability had reportedly existed since Orchard launched in May 2022.
Patch deployed quickly
After discovering the flaw, Hornby immediately notified engineers at the Zcash Open Development Lab. Developers released a fix on June 1, just days after the vulnerability was reported.
Although the privacy-focused nature of Orchard makes it difficult to prove whether the bug was ever exploited, researchers believe large-scale abuse is unlikely.
Shielded Labs noted that the vulnerability remained undiscovered for years despite extensive review by experienced cryptographers, suggesting it required highly specialized analysis to uncover.
Network upgrades under consideration
To strengthen confidence in the network, Zcash developers are exploring a future upgrade that would allow anyone to verify the integrity of the coin supply and prove that no counterfeit ZEC exists within Orchard.
The proposal could include a new shielded pool and additional accounting mechanisms designed to improve transparency while maintaining privacy protections.