A four-year-old soundness bug in Zcash's Orchard shielded pool — discovered on May 29, 2026 by security researcher Taylor Hornby using Anthropic's Claude Opus 4.8 AI model — could have allowed unlimited, undetectable counterfeiting of ZEC tokens. The Zcash development teams deployed an emergency ...
"The probability of unauthorized minting is extremely low, but it cannot be proven cryptographically impossible." — Arthur Hayes, CIO, Maelstrom Capital / Co-founder, BitMEX
A four-year-old soundness bug in Zcash's Orchard shielded pool — discovered on May 29, 2026 by security researcher Taylor Hornby using Anthropic's Claude Opus 4.8 AI model — could have allowed unlimited, undetectable counterfeiting of ZEC tokens. The Zcash development teams deployed an emergency soft fork on June 2 and a hard fork (NU6.2) on June 3 to patch the flaw, then publicly disclosed it on June 5.
ZEC fell from $624 to $309 within 48 hours of disclosure — a 50% decline that erased over $3 billion in market capitalization. Arthur Hayes liquidated his entire ZEC position, the second-largest holding in his "Holy Trinity" family fund, citing the cryptographic impossibility of verifying whether counterfeit tokens were minted during the four-year exposure window. Liquidations exceeded $41 million in 24 hours. Monero dropped 3-4% on contagion fears after Hornby announced plans to audit XMR next.
The incident represents the second emergency protocol upgrade in Zcash's ten-year history and the highest-profile case of an AI model surfacing a critical vulnerability in production blockchain infrastructure.
The flaw resided in the elliptic-curve multiplication gadget within the ecc::chip::mul function of the halo2_gadgets crate — a core component of the zero-knowledge proof circuit underpinning Zcash's Orchard shielded pool. Orchard launched in May 2022 as part of the NU5 network upgrade.
The specific defect was an under-constrained element in the circuit's arithmetic check on transaction inputs. A constraint that was supposed to enforce validity on elliptic-curve scalar multiplication contained a gap. This gap allowed crafted inputs to bypass proof verification, enabling the generation of valid-appearing proofs for transactions that created ZEC from nothing.
In plain terms: an attacker with sufficient cryptographic knowledge could have forged transaction proofs to mint unlimited counterfeit ZEC within the Orchard pool. Because Orchard transactions are shielded — amounts and sender/receiver identities are hidden by design — any counterfeit tokens created through the exploit would have been indistinguishable from legitimate ones.
The vulnerability was classified as a soundness bug, the most severe category for zero-knowledge proof systems. Soundness is the property guaranteeing that a proof can only be generated for true statements. When soundness breaks, the entire trust model collapses.
Shielded Labs, the Swiss-based nonprofit that funds Zcash protocol development, engaged Taylor Hornby as a part-time security consultant in April 2026. Hornby is a former security engineer at the Electric Coin Company and a long-time Zcash ecosystem contributor.
Hornby used Anthropic's Claude Opus 4.8 — released May 28, 2026 — paired with a custom AI auditing framework to conduct a targeted review of the Orchard circuit. According to multiple reports, within a single day of focused examination, Hornby located the flaw, wrote a complete exploit, and verified in a local testnet that it produced unlimited, undetectable counterfeit ZEC.
The speed of the discovery is notable. The Orchard circuit had been reviewed by multiple human auditors over four years without the flaw being caught. Hornby's AI-assisted approach compressed what would typically require weeks of manual circuit analysis into hours.
Hornby privately disclosed the vulnerability to the Zcash Open Development Lab at 11:53 PM on May 29, 2026. The development teams — including core engineers Daira-Emma Hopwood, Kris Nuttycombe, and Jack Grigg — began emergency remediation immediately.
The fix was deployed in two stages:
Phase 1 — Soft Fork (June 2, 2026). Zebra node software version 4.5.3 activated at block height 3,363,426 at approximately 02:00 UTC. This temporarily disabled all Orchard transactions, preventing any potential exploitation while the permanent fix was finalized. Miners and node operators were contacted directly to ensure rapid upgrade adoption.
Phase 2 — NU6.2 Hard Fork (June 3, 2026). Zebra 5.0.0 activated at block height 3,364,600 at approximately 00:05 EDT. The hard fork introduced a corrected Orchard circuit, permanently closing the vulnerability and re-enabling Orchard transactions.
The entire remediation — from private disclosure to production hard fork — took five days. The public disclosure followed on June 5, two days after the fix was live, giving node operators additional time to upgrade.
This was the second security-driven emergency protocol upgrade in Zcash's history since its 2016 launch.
The June 5 disclosure triggered one of the sharpest single-asset selloffs in 2026:
| Metric | Value | |---|---| | ZEC peak (June 4) | $624 | | ZEC trough (June 5-6) | $265 - $309 | | Decline | ~50% in 48 hours | | Market cap loss | >$3 billion | | 24-hour trading volume | ~$1.4 billion | | Long liquidations (24h) | $41 million | | 52-week high | $736 |
Arthur Hayes' exit accelerated the selloff. Hayes had publicly identified ZEC as one of three core positions in his "Holy Trinity" portfolio — alongside HYPE and NEAR — on May 22, 2026. ZEC had rallied 91% following that endorsement. Hayes liquidated his entire ZEC position on or around June 4, before the public disclosure, characterizing the decision as a response to the fundamental unknowability of whether counterfeit tokens existed.
According to CoinDesk, bearish ZEC bets hit record highs as the price crashed. A $13.1 million whale purchase provided brief support, but selling pressure dominated.
Contagion spread to other privacy coins: Monero (XMR) fell 3-4% on the same day. The decline in XMR extended to approximately 10% after Hornby announced on June 6 that he would apply the same AI-assisted auditing methodology to Monero's codebase.
The core market concern is not the vulnerability itself — it has been patched — but what it implies about the period between May 2022 and June 2026.
Zcash's Orchard pool is designed to conceal transaction amounts and participant identities. This privacy architecture means there is no on-chain record that can definitively prove counterfeit tokens were or were not created during the four-year exposure window.
Zcash founder Zooko Wilcox-O'Hearn stated the vulnerability "could have allowed someone to create unlimited counterfeit ZEC without detection."
The development team emphasized that no evidence of exploitation exists. They also acknowledged, as a matter of cryptographic fact, that the privacy properties "make it impossible to know with certainty whether anyone exploited the bug."
Zcash's turnstile mechanism — which tracks ZEC balances as tokens move between transparent and shielded pools — provides some assurance. The turnstile confirmed that the total ZEC supply across all pools remained consistent with expected issuance. However, this verification applies to cross-pool transfers, not to activity contained entirely within the Orchard pool itself.
Hayes articulated the market's position concisely: the privacy coin thesis "demands perfection, a standard the bug undermined." If supply integrity cannot be verified, the store-of-value proposition weakens regardless of whether exploitation actually occurred.
On June 6, Shielded Labs, the Zcash Foundation, Tachyon Group, Valar Group, and the Zcash Open Development Lab (ZODL) jointly proposed "Ironwood" — a new shielded pool designed to restore verifiable supply integrity.
The proposal has three components:
New shielded pool. Ironwood creates a replacement pool using the corrected Orchard circuit, backed by formal mathematical verification, independent audits, and AI-assisted security review.
Orchard deprecation. New outputs to the existing Orchard pool are blocked. Existing Orchard addresses remain valid, but new funds automatically route to the Ironwood pool.
Turnstile accounting enforcement. Strict transfer limits between pools ensure that no more ZEC can exit Orchard than was legitimately deposited. Once Ironwood activates, any node operator can independently verify circulating supply by summing balances across active pools, without relying on external attestations.
The proposal states that users "would no longer need to rely on external assessments" regarding whether the vulnerability was exploited.
Target activation is late July 2026, following zcashd client deprecation at block height 3,417,100. Migration involves privacy trade-offs — transfer amounts and timing between pools are visible — but restores the supply-verifiability property that the market demands.
The Zcash incident is the highest-profile demonstration of AI-assisted vulnerability discovery in production financial infrastructure. Several implications follow:
Speed asymmetry. Four years of human auditing missed what AI-assisted review found in one day. This does not mean human auditors are obsolete — Hornby's expertise in guiding the AI model was essential. It does suggest that AI dramatically compresses the time-to-discovery for certain classes of bugs, particularly in complex mathematical circuits.
Dual-use concern. The same capability that enables defensive auditing enables offensive exploitation. According to CoinDesk, security experts warn that AI models capable of finding zero-knowledge proof flaws could be used by attackers to target similar vulnerabilities across DeFi protocols and, potentially, traditional financial systems that increasingly rely on cryptographic proofs.
According to Ledger CTO Charles Guillemet, AI "is making crypto's security problem even worse" by reducing the cost and difficulty of finding exploitable flaws. CertiK's 2026 outlook identified AI misuse and infrastructure gaps as primary drivers of crypto hacks.
Privacy coin existential risk. Hornby's announcement that he will next audit Monero sent XMR down 10%. The market is now pricing in the possibility that similar undiscovered vulnerabilities exist in other privacy-focused protocols. If AI auditing becomes standard practice, every unaudited privacy coin carries an implicit discount.
Formal verification demand. The incident strengthens the case for formal mathematical verification of all cryptographic circuits in production systems. Several leading investors and researchers now argue that AI-assisted formal verification is the only viable long-term defense for mission-critical financial software.
A soundness bug in Zcash's Orchard pool, present since May 2022, could have allowed unlimited undetectable counterfeiting. It was discovered on May 29, 2026 by Taylor Hornby using Anthropic's Claude Opus 4.8 and patched via emergency hard fork by June 3.
ZEC lost 50% of its value ($3B+ in market cap) in 48 hours following public disclosure on June 5. Liquidations topped $41 million.
The flaw's exploitation status is cryptographically unverifiable due to Orchard's privacy design. This unknowability — not the bug itself — is what drove Arthur Hayes and other large holders to exit.
The "Ironwood" proposal targets late July 2026 activation to restore supply verifiability through a new shielded pool with turnstile accounting.
AI-assisted auditing found in one day what four years of human review missed, establishing a precedent that reshapes how the industry approaches protocol security — and raises dual-use concerns about AI-enabled exploitation.
Monero dropped 10% after Hornby announced plans to conduct a similar AI-assisted audit of XMR, indicating the market views all unaudited privacy coins as carrying elevated risk.
The Zcash Orchard vulnerability is a case study in how privacy and verifiability exist in tension. The same design that protects user privacy made it impossible to confirm supply integrity after a critical bug was found. The market's response — halving ZEC's value — reflects a rational repricing of that uncertainty.
The Ironwood proposal represents an attempt to resolve this tension through architectural redesign. Whether the community migrates fast enough to restore confidence remains an open question. The late-July target leaves nearly two months of uncertainty.
The broader signal is structural. AI-assisted auditing has arrived as a serious tool for protocol security. It found a four-year-old bug that multiple human reviews missed. The same capability, in adversarial hands, represents an escalation of the threat environment for every protocol relying on complex cryptographic proofs. The industry's response — more formal verification, more AI-assisted review, more rigorous security frameworks — will determine whether this episode is remembered as a close call or a preview.