← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] Zcash Orchard Bug Erases $3B, Breaks Supply Trust

Zephyra|June 5, 2026|BPF
EXECUTIVE SUMMARY

A critical soundness bug in Zcash's Orchard zero-knowledge proof circuit — undetected for four years since the pool's May 2022 activation — allowed unlimited counterfeit ZEC creation inside the shielded pool. Security engineer Taylor Hornby discovered the flaw on May 29, 2026 using an AI-assisted...

"The vulnerability could have been exploited to undetectably create an unlimited amount of counterfeit ZEC within Orchard." — Zooko Wilcox-O'Hearn, Zcash Founder

Executive Summary

A critical soundness bug in Zcash's Orchard zero-knowledge proof circuit — undetected for four years since the pool's May 2022 activation — allowed unlimited counterfeit ZEC creation inside the shielded pool. Security engineer Taylor Hornby discovered the flaw on May 29, 2026 using an AI-assisted auditing framework running Anthropic's Opus 4.8 model, one day after the model's release. Zcash developers coordinated an emergency soft fork on June 2 (block 3,363,426) and a hard fork on June 3 (block 3,364,600) to remediate the vulnerability.

ZEC shed over 50% in value post-disclosure, falling from approximately $630 to as low as $250 before partially recovering to ~$310. Liquidations topped $116 million. BitMEX co-founder Arthur Hayes liquidated his entire ZEC position. The incident marks the second counterfeiting-class bug in Zcash's history, following a similar 2018 flaw quietly patched during the Sapling upgrade. Shielded Labs has proposed a new network upgrade deploying a clean shielded pool with turnstile accounting to verify supply integrity.

Table of Contents

  1. The Vulnerability: Under-Constrained Elliptic Curve Multiplication
  2. Discovery: AI-Assisted Circuit Auditing
  3. Emergency Response Timeline
  4. Market Impact: $3B in Market Cap Erased
  5. The Supply Integrity Problem
  6. Historical Precedent: 2018 Counterfeiting Bug
  7. Zcash vs. Monero: Privacy Architecture Under Stress
  8. Implications for ZK Circuit Security
  9. Key Takeaways
  10. Conclusion

The Vulnerability: Under-Constrained Elliptic Curve Multiplication

The flaw resided in two lines of code within the Orchard circuit's variable-base scalar multiplication gadget, part of the halo2_gadgets crate. The constraint, intended to enforce an arithmetic check on transaction inputs, contained a gap that allowed arbitrary false values to pass validation.

Specifically, the vulnerability stemmed from an "under-constrained" element in the circuit that made it possible to input arbitrary false values into an elliptic curve multiplication and still receive valid approval from the proof system. This broke the "soundness" property — the fundamental guarantee that a zero-knowledge proof system will reject invalid state transitions.

The practical consequence: an attacker could spend the same shielded note multiple times by revealing a unique nullifier with each spend. Each forged transaction would produce a valid proof, minting unlimited, undetectable counterfeit ZEC within the Orchard pool.

Under-constrained elliptic curve checks rank among the most common weaknesses in production ZK circuits, according to security researchers. The Orchard circuit had passed multiple audits by expert cryptographers over four years without the flaw being identified.

Discovery: AI-Assisted Circuit Auditing

Taylor Hornby, an independent security engineer hired by Shielded Labs in April 2026 for an ongoing protocol review, discovered the vulnerability on May 29 using a custom AI auditing agent framework. The framework was paired with Anthropic's Opus 4.8 model, released just one day prior on May 28.

According to reporting from BeInCrypto and Blockhead, the AI-assisted approach enabled examination of specific circuit constraints at a depth and speed that previous manual reviews had not achieved. Hornby subsequently wrote a complete exploit program that successfully generated unlimited counterfeit ZEC in a local testing environment.

The disclosure was made privately to the Zcash Open Development Lab (ZODL), which coordinated the emergency response across ecosystem participants including miners and exchanges. The public disclosure came on June 5, after the network had already been patched.

The role of AI in discovering a vulnerability that eluded multiple expert audits for four years raises questions about the adequacy of conventional security review processes for complex ZK circuits.

Emergency Response Timeline

The response unfolded over six days:

| Date | Event | |------|-------| | May 29 (evening) | Hornby identifies vulnerability, discloses to ZODL engineers | | May 30–June 1 | Private coordination with miners, exchanges, and ecosystem stakeholders | | June 2, 02:00 UTC | Soft fork at block 3,363,426 — Zebra 4.5.3 temporarily disables all Orchard transactions | | June 3, 00:05 EDT | NU6.2 hard fork at block 3,364,600 — Orchard re-enabled with corrected circuit | | June 3 | Zcash blockchain experiences over 4 hours of downtime during the transition | | June 5 | Public disclosure by Zooko Wilcox-O'Hearn and Shielded Labs |

The decision to disable and then hard-fork the protocol within five days of discovery, before public disclosure, drew criticism. Seth for Privacy characterized ZODL's coordination process as an "abuse of insider access," highlighting governance centralization concerns in what is ostensibly a decentralized protocol.

This was only Zcash's second security-driven protocol upgrade since the network launched in 2016.

Market Impact: $3B in Market Cap Erased

ZEC lost over $3 billion in market capitalization within approximately 24 hours of the June 5 disclosure.

Price action:

  • Pre-disclosure: ~$630 (June 4)
  • Initial drop: -38% within 24 hours
  • Extended selloff: -50%+ to approximately $250 at the trough
  • Partial recovery: ~$310 by end of June 5

Liquidation data (CoinGlass):

  • Total ZEC liquidations: $116 million over 24 hours
  • Long liquidations: ~$72 million
  • Short liquidations: ~$45 million
  • ZEC ranked as the third-largest liquidation event behind Bitcoin and Ethereum
  • Peak liquidation volume occurred between 8:00–9:00 UTC on June 5

Notable market participant exits: Arthur Hayes, BitMEX co-founder and Maelstrom CIO, disclosed he had sold his entire ZEC position and Maelstrom's holdings. According to crypto.news, Hayes framed the exit as reflecting a fundamental thesis failure, stating that "privacy trades need certainty rather than mere probability of soundness."

The selloff occurred against a backdrop of ZEC's prior 900%+ gain over twelve months, gains that some analysts attributed to trader rotation into privacy assets rather than measurable adoption growth.

The Supply Integrity Problem

The core unresolved issue: due to the privacy properties of the Orchard pool, there is no cryptographic way to determine whether the flaw was exploited before the June 2 patch.

The Zcash Foundation stated that "no evidence of unauthorized value creation" was found. However, the privacy architecture that makes Zcash's shielded transactions unlinkable also makes proving negative exploitation mathematically impossible through on-chain analysis alone.

Approximately 30% of ZEC's circulating supply — roughly 5 million of 16.7 million ZEC — sits in the shielded pool. The Orchard pool specifically holds approximately 4.2 million ZEC.

Shielded Labs' proposed remedy: Shielded Labs has proposed a network enhancement that would:

  1. Deploy an entirely new shielded pool
  2. Enforce turnstile accounting on all coins migrating from the Orchard pool
  3. Require every ZEC exiting Orchard to pass through a publicly auditable accounting mechanism
  4. Enable independent verification of ZEC's total supply authenticity

The proposal aims to prove that counterfeit ZEC does not remain inside the affected pool. Shielded Labs stated it plans to publish full technical details the following week. The upgrade would require community support and must pass Zcash's governance process before activation.

Historical Precedent: 2018 Counterfeiting Bug

This is the second counterfeiting-class vulnerability in Zcash's history. In March 2018, a cryptographer employed by the Zerocoin Electric Coin Company discovered a bug that theoretically allowed unlimited counterfeiting. That flaw was quietly fixed during the Sapling network upgrade, which activated on October 28, 2018 — a seven-month disclosure-to-fix cycle, compared to five days for the current Orchard bug.

The recurrence of the same vulnerability class — counterfeiting enabled by ZK circuit flaws — raises structural questions about the long-term auditability of zero-knowledge proof systems in production cryptocurrency deployments.

Zcash vs. Monero: Privacy Architecture Under Stress

The Orchard vulnerability has reignited the comparison between Zcash's optional-privacy, ZK-proof-based architecture and Monero's mandatory-privacy, ring-signature-based model.

| Metric | Zcash (ZEC) | Monero (XMR) | |--------|-------------|--------------| | Privacy model | Optional (shielded pool) | Mandatory (all transactions) | | Current tech | Halo 2 zk-SNARKs | FCMP++ (deployed late 2025) | | Shielded/private usage | 59.3% of transactions (Feb 2026 ATH) | 100% | | Daily public tx count | ~8,500 | ~3x Zcash volume | | Supply auditability | Impaired (post-bug) | Not cryptographically auditable | | Exchange delistings | Partial (viewing keys provide opt-in compliance) | Extensive (70+ exchanges by late 2025) |

According to CryptoTimes reporting, Monero remained price-stable during Zcash's selloff, with some capital rotation toward XMR. However, Monero's own architecture does not offer supply auditability either — a fundamental limitation shared by both privacy-coin approaches.

Zcash retains one structural advantage: its optional privacy model and viewing keys allow selective disclosure, enabling centralized platforms to maintain listings. By contrast, Monero's mandatory privacy has led to delistings from over 70 exchanges.

Implications for ZK Circuit Security

The incident surfaces systemic concerns for the broader zero-knowledge proof ecosystem, which underpins not only privacy coins but also Ethereum Layer 2 rollups, cross-chain bridges, and identity systems.

Under-constrained circuits — where proof systems fail to enforce all necessary arithmetic checks — represent a known vulnerability class. The Orchard bug persisted through multiple expert audits over four years, suggesting conventional code review processes may be insufficient for the mathematical complexity of ZK circuits.

The AI-assisted discovery method — using a custom agent framework paired with a large language model — represents a new vector for protocol security. If an AI model can identify a flaw that human auditors missed for 48 months, the economics of ZK circuit auditing may shift. The question is whether this extends to other production ZK systems, including those securing billions in Layer 2 TVL.

For protocols deploying ZK proofs in production, the Zcash incident provides a concrete data point: four years of expert review were insufficient. The surface area for soundness bugs in complex circuits remains large, and the consequences of a missed constraint — particularly in privacy-preserving systems where exploitation is undetectable — are severe.

Key Takeaways

  • A four-year-old soundness bug in Zcash's Orchard circuit allowed unlimited undetectable counterfeiting. The flaw was in two lines of code governing elliptic curve multiplication constraints.
  • AI-assisted auditing found what humans missed. Taylor Hornby's custom framework, paired with Opus 4.8, identified the vulnerability one day after the model's release. Multiple expert audits over four years had not caught it.
  • ZEC lost 50%+ in value. Over $3 billion in market cap was erased, with $116 million in liquidations. Arthur Hayes exited his entire position.
  • Supply integrity cannot be cryptographically verified. Privacy properties of the Orchard pool make it impossible to prove the bug was never exploited. Shielded Labs has proposed a turnstile-based migration to a new pool.
  • This is Zcash's second counterfeiting-class bug. The first occurred in 2018 and was quietly patched during the Sapling upgrade.
  • The incident has implications beyond privacy coins. Any protocol deploying ZK proofs in production — including Ethereum L2s — faces analogous under-constrained circuit risks.

Conclusion

The Orchard vulnerability represents the most severe security event in Zcash's ten-year history. The flaw's four-year dormancy, its discovery by AI rather than conventional audit, and the fundamental inability to verify whether it was exploited each compound the damage to market confidence.

The proposed turnstile migration offers a path to supply verification, but requires community governance approval and user action to migrate funds. Until that process completes, a persistent uncertainty hangs over Zcash's monetary integrity — the very property a cryptocurrency cannot afford to have questioned.

For the broader ZK ecosystem, the lesson is concrete: under-constrained circuits in production represent an existential risk class. The mathematical complexity of zero-knowledge proof systems may exceed what manual auditing can reliably catch. Whether AI-assisted security review becomes standard practice — and whether it arrives before the next four-year bug is exploited rather than discovered — will shape the reliability of ZK infrastructure across the industry.

Sources & References

  1. Zcash plummets 38% as Shielded Labs reveals a major bug that went undetected for four years — CoinDesk, June 5, 2026
  2. Security researcher finds Zcash vulnerability allowing 'unlimited' counterfeit minting; ZEC drops 31% — The Block, June 5, 2026
  3. Zcash selloff extends past 50% amid bug disclosure as liquidations top $100 million — The Block, June 5, 2026
  4. Zcash Bug Could Have Let Attackers Print Cryptocurrency Out of Thin Air — Gizmodo, June 5, 2026
  5. ZEC Crashes 38% as Zcash Discloses 'Critical Counterfeiting Vulnerability' — Decrypt, June 5, 2026
  6. An Opus 4.8 Audit Uncovered Zcash's Bug — ZEC Plunged 30% — BeInCrypto, June 5, 2026
  7. Zcash Founder Discloses Critical Orchard Forgery Flaw Fixed by Emergency Hard Fork — Blockhead, June 5, 2026
  8. Shielded Labs Proposes New Zcash Upgrade to Prove ZEC Supply After Orchard Bug — The Defiant, June 5, 2026
  9. Zcash bug raises supply doubts as Hayes exits full ZEC bag — Crypto.news, June 5, 2026
  10. Zcash vs. Monero: The 2026 Privacy Coin War Just Got Decided in One Week — CryptoTimes, June 5, 2026
  11. The Orchard Counterfeiting Vulnerability—And Next Steps — Zcash Community Forum, June 2026
  12. Zcash Counterfeiting Vulnerability Successfully Remediated — Electric Coin Company (2018 vulnerability reference)