A soundness flaw in Zcash's Orchard zero-knowledge proof circuit, present since May 2022 and undetected for four years, could have allowed an attacker to mint unlimited counterfeit ZEC with no on-chain trace. Security researcher Taylor Hornby discovered the bug on May 29, 2026, one day after Anth...
"Because of the privacy properties of Orchard, there is no way to cryptographically prove whether the vulnerability was exploited before it was remediated." — Zooko Wilcox-O'Hearn, Zcash Founder
A soundness flaw in Zcash's Orchard zero-knowledge proof circuit, present since May 2022 and undetected for four years, could have allowed an attacker to mint unlimited counterfeit ZEC with no on-chain trace. Security researcher Taylor Hornby discovered the bug on May 29, 2026, one day after Anthropic released its Opus 4.8 model, which Hornby used in a targeted AI-assisted audit of the Orchard circuit. He produced a working exploit in a test environment. An emergency soft fork on June 2 disabled Orchard transactions; a hard fork (NU6.2) on June 3 at block 3,364,600 restored shielded functionality with a corrected circuit.
ZEC fell 38% from a pre-disclosure price near $635 to an intraday low of $309 on June 5, erasing over $3 billion in market capitalization. Twenty-four-hour trading volume spiked to $2.3–2.8 billion. The incident exposes a structural tension at the core of privacy-preserving cryptography: the same properties that make shielded transactions private also make supply integrity unverifiable when a soundness bug exists. Shielded Labs has proposed a new shielded pool with turnstile accounting to address this, but the episode raises questions that extend well beyond Zcash to every protocol relying on zero-knowledge proof circuits.
The bug resided in the halo2_gadgets crate, specifically in an under-constrained element of the Orchard zero-knowledge proof circuit. The flaw allowed arbitrary false inputs to pass through an elliptic curve multiplication check and still validate as legitimate. In concrete terms, an attacker could forge shielded transactions that created ZEC from nothing — counterfeit tokens indistinguishable from legitimate ones within the Orchard pool.
The vulnerability class is well-documented in ZK security literature. A 2024 analysis found that 96% of documented bugs in SNARK-based ZK systems stemmed from under-constrained circuits — circuits that lack sufficient algebraic constraints to prevent invalid proofs from passing verification. The Zcash Orchard flaw fits this pattern precisely.
The bug had survived four years of audits, academic review, and multiple network upgrades since Orchard's activation in May 2022. Engineers Daira-Emma Hopwood, Kris Nuttycombe, and Jack Grigg confirmed the vulnerability upon disclosure and coordinated the emergency response.
Critically, the vulnerability's impact was bounded by Zcash's architecture. Counterfeiting could occur only within the Orchard shielded pool, which held approximately 30% of circulating ZEC (roughly 5 million of 16.7 million ZEC) as of May 2026. However, due to the privacy properties of the pool, there is no cryptographic method to determine whether the bug was exploited before the fix. Shielded Labs has stated exploitation was unlikely given the bug's complexity, but "unlikely" is not "impossible," and the distinction matters when supply integrity is at stake.
Shielded Labs hired Taylor Hornby in April 2026 specifically to conduct a security review of the Orchard protocol. On May 28, Anthropic released its Opus 4.8 model. On May 29, Hornby used the model within a custom AI auditing framework for a targeted review of the Orchard circuit — and identified the flaw within a day of the model's availability.
Hornby did not merely flag the issue theoretically. He developed a complete proof-of-concept exploit program that successfully created unlimited counterfeit ZEC in an isolated test environment. The speed of discovery — within hours of applying AI-assisted analysis to a codebase that had undergone years of human review — is notable.
The incident represents one of the highest-profile real-world applications of AI-assisted security auditing in the blockchain sector. The broader industry has been moving toward hybrid AI-human audit models through 2025 and 2026, with AI tools currently detecting approximately 65% of known vulnerabilities in curated datasets, according to industry benchmarks. The Zcash case suggests that for specific classes of mathematical constraint bugs, AI models may identify patterns that human reviewers consistently miss.
This does not mean AI auditing is a solved problem. AI tools still struggle with novel attack vectors and complex multi-step exploits. But for the specific category of under-constrained ZK circuits — where the bug is essentially a missing mathematical constraint — large language models appear to offer a meaningful advantage in coverage.
| Date | Event | |------|-------| | May 29, 2026 | Hornby discovers vulnerability, discloses to ZODL core engineers | | May 29–Jun 1 | Private coordination; emergency patch development | | Jun 2, 02:00 UTC | Soft fork at block 3,363,426 disables Orchard transactions (Zebra 4.5.3) | | Jun 3, 00:05 EDT | NU6.2 hard fork activates at block 3,364,600, restoring shielded functionality | | Jun 5 | Public disclosure via Shielded Labs forum post |
The five-day window from discovery to public disclosure follows responsible disclosure norms. The two-phase approach — first disabling the vulnerable component, then deploying a corrected circuit — minimized user disruption while eliminating the attack surface.
ZEC traded near $635 prior to the disclosure. Within 24 hours of the public announcement on June 5, the token fell to an intraday low of $309 — a 38% decline. It partially recovered to approximately $340 by end of day, still representing a roughly $3 billion reduction in market capitalization.
Twenty-four-hour trading volume surged to between $2.3 billion and $2.8 billion, multiple times normal daily volume, indicating forced liquidations and panic selling.
Notable market participants reacted immediately. Arthur Hayes, BitMEX co-founder and Maelstrom CIO, stated he had liquidated his entire ZEC position: "Privacy trades need certainty rather than mere probability of soundness." Grayscale CLO Craig Salm took the opposing view, arguing exploitation was unlikely given the difficulty of the exploit and the absence of observable market anomalies during bull market conditions.
The selloff occurred against an already-weak crypto backdrop. Bitcoin was trading near $63,800, down roughly 45% from cycle highs, with $4.4 billion in cumulative ETF outflows over 13 consecutive sessions. The total crypto market cap sat near $2.4 trillion. ZEC's idiosyncratic selloff compounded broader risk-off sentiment.
The Zcash incident crystallizes a fundamental design tension that applies to all privacy-preserving blockchain protocols. In a transparent ledger like Bitcoin, anyone can audit the total supply at any time by summing unspent outputs. A counterfeiting bug would be immediately detectable. In a shielded protocol, this verification is impossible by design — the same cryptographic properties that hide transaction amounts also hide supply inflation from a soundness bug.
This is not a Zcash-specific problem. As Helius co-founder Mert Mumtaz stated following the disclosure: "Almost all privacy protocols have a variant of this same vulnerability."
The historical record supports this. In 2017, a flaw in Monero's RingCT implementation could have enabled similar infinite minting; it was quietly patched before public disclosure. Solana's ZK ElGamal implementation contained a soundness bug that was fixed via responsible disclosure. The FOOMCASH protocol lost $2.26 million in early 2026 to a Groth16 verifier misconfiguration — two elliptic curve constants set to identical values, removing a constraint that enforced soundness.
The risk is structural. ZK circuits are complex mathematical constructions where a single missing constraint can invalidate the entire security model. The zkFuzz research project identified 66 bugs in real ZK circuits, including 38 zero-day vulnerabilities. Under-constrained circuits account for 96% of documented SNARK-based bugs.
For the privacy coin sector specifically, the Zcash event reshuffled the competitive landscape. Zcash's shielded transaction rate had reached an all-time high of 59.3% in February 2026, and shielded supply had grown from 8% in early 2024 to 30% by May 2026. That adoption trajectory is now in question. Monero, which uses ring signatures rather than ZK proofs and maintains mandatory privacy as a default, processes approximately three times Zcash's daily transaction volume (~8,500 transactions per day for Zcash). However, both architectures face their own trade-offs: Monero's larger anonymity sets have historically been shown to be partially deanonymizable, while Zcash's ZK approach offers stronger theoretical privacy but carries the soundness risk now made concrete.
The Zcash vulnerability is not an isolated incident but a data point in an expanding pattern. ZK proof systems are proliferating across the blockchain industry — in Layer 2 rollups (zkSync, Scroll, Polygon zkEVM), in privacy protocols, in cross-chain bridges, and in identity systems. Each deployment introduces ZK circuits that must be correctly constrained.
The financial damage from ZK logic bugs remains in the double-digit millions in aggregate, according to a KuCoin research report, smaller than headline DeFi exploits but growing as ZK adoption scales. The systemic risk is that ZK circuits are among the most complex pieces of code in the blockchain stack, and the talent pool capable of auditing them is small and expensive.
The industry's response has been to layer defenses: formal verification, AI-assisted auditing, bug bounty programs, and multiple independent audits. Shielded Labs has announced it is hiring a Head of Security and a dedicated Cryptographer. But the Zcash case demonstrates that a critical bug can survive four years of scrutiny before an AI model, available for less than 24 hours, surfaces it.
Shielded Labs has outlined a network upgrade proposal to deploy a new shielded pool with turnstile accounting on coins exiting the Orchard pool. Under this design, all ZEC moving from Orchard to the new pool would pass through a transparent intermediate step, allowing anyone to verify total supply integrity. The mechanism requires coins to be briefly unshielded before entering the new pool.
This introduces a trade-off: improved auditability at the cost of a privacy gap during the transition. The proposal is expected to be detailed in full within one week of the June 5 disclosure. Whether the community accepts this trade-off will test the boundary between privacy maximalism and supply verification — a decision with implications for every privacy protocol in the sector.
The Zcash Orchard vulnerability is a case study in the cost of complexity. A two-line error in a ZK circuit went undetected for four years, creating a theoretical attack surface that could have undermined the entire monetary integrity of the network — and no one can prove it was not exploited. The 38% price collapse reflects the market pricing in that uncertainty.
The broader implication is systemic. ZK proof circuits are becoming foundational infrastructure across DeFi, Layer 2 scaling, and cross-chain bridges. Each deployment carries the same class of risk: a single under-constrained element can break soundness guarantees that billions of dollars depend on. The talent and tooling to audit these systems remain scarce, though AI-assisted auditing showed concrete value in this case.
For an industry that has allocated roughly $86–113 billion annually in subsidies and external capital to sustain network operations, the question of whether core cryptographic infrastructure can be trusted adds another layer of fragility. The economic value of blockchain networks ultimately depends on the integrity of their cryptographic foundations. When that foundation contains a four-year-old crack, the market reprices accordingly.