Security & Audits
Share
A newly disclosed security flaw in Zcash’s Orchard shielded transaction pool has triggered renewed scrutiny over the protocol’s privacy architecture, after researchers warned it could theoretically allow the creation of counterfeit tokens within the system.
The vulnerability, identified by security engineer Taylor Hornby and published by Shielded Labs on X, was followed by a sharp selloff in Zcash, with the token (ZEC) falling 31% in a matter of hours before stabilizing near $409.64, according to market data.
Shielded Labs, an independent organization supporting Zcash development, said it commissioned Hornby in April to conduct a protocol review using both traditional methods and AI-assisted security tooling.
On May 29, Hornby reportedly identified a flaw in the Orchard circuit, Zcash’s zero-knowledge proof system responsible for validating shielded transactions. The issue was escalated to the Zcash Open Development Lab (ZODL), and a patch was deployed on June 1.
According to the disclosure, the vulnerability existed since Orchard’s activation in May 2022.
Shielded Labs said Hornby leveraged Anthropic’s Opus 4.8 model alongside custom AI-driven testing frameworks to construct a working exploit in a controlled environment, demonstrating that it could generate “unlimited, undetectable counterfeit ZEC.”
The flaw stemmed from an under-constrained component in the Orchard circuit, which allowed invalid inputs to pass elliptic curve verification checks.
The Orchard pool is Zcash’s privacy layer, enabling fully shielded transfers that conceal sender, receiver, and transaction value using zero-knowledge proofs.
Within this system, the circuit is responsible for ensuring that only mathematically valid transactions are accepted. Any weakness in constraint logic can, in theory, undermine the integrity of the shielded supply verification model.
While the bug was fixed, its multi-year presence raised questions about whether it could have been exploited undetected.
Shielded Labs said it cannot conclusively determine whether the vulnerability was ever used maliciously due to the privacy-preserving design of the Orchard pool.
However, the organization stated it is not “overly concerned” that counterfeiting occurred before the patch, arguing that the flaw went unnoticed even under extensive cryptographic review.
The researchers added that the discovery was the result of proactive security testing intended to identify vulnerabilities before adversaries could exploit them.
Following the disclosure, Shielded Labs said it is evaluating a potential network upgrade aimed at improving transparency around supply integrity in the shielded pool.
The proposal would allow users to verify the total supply within Orchard and introduce a new shielded pool design with stricter accounting mechanisms applied to all transactions.
Zcash experienced significant volatility following the disclosure, with the sharpest price decline occurring within hours of the announcement.
While Shielded Labs emphasized that the vulnerability has been patched and does not confirm any confirmed exploitation, the incident highlights ongoing risks in advanced zero-knowledge systems where complex cryptographic constraints underpin supply validity.
The organization stated that Zcash remains structurally sound and is positioned to recover, but acknowledged that transparency around shielded asset integrity will remain a key focus going forward.
Market pressure on Zcash intensified further following the initial disclosure, with ZEC extending its decline beyond 50% during subsequent trading sessions before partially recovering. At one point, the token fell from roughly $630 to near $250, accompanied by significant volatility across derivatives markets.
According to CoinGlass data, liquidations linked to the move surpassed $116 million, placing Zcash among the most heavily liquidated assets over the period, behind only Bitcoin and Ether. Long positions accounted for the majority of forced closures, highlighting the extent of leveraged exposure during the selloff.
Developers and researchers also released additional technical clarifications outlining the full exposure window of the vulnerability, confirming it remained active from the Orchard pool’s activation in 2022 until its remediation in 2026. They further detailed the specific circuit-level weakness that enabled the exploit scenario and confirmed that a post-patch network upgrade re-enabled Orchard functionality with corrected constraints.
Importantly, contributors reiterated that due to the shielded nature of the system, there is no cryptographic method to determine whether the vulnerability was exploited prior to remediation. While no evidence of abuse has been identified, the inability to verify historical integrity remains a core unresolved limitation.
In response, Shielded Labs is now evaluating a broader protocol upgrade aimed at introducing enhanced supply integrity verification mechanisms for shielded assets, alongside a parallel effort to formally verify the Orchard circuit as part of longer-term security hardening.
This article has been updated to reflect additional market developments, liquidation data, and responses from industry participants following the disclosure.
Disclaimer of Warranty
The information provided in this article is for general informational purposes only. We make no warranties about the completeness, reliability, and accuracy of this information. Read full disclaimer
Editor's Picks
In the Same Space

The Quantum Clock Is Ticking: Can Crypto Upgrade Before Its Security Model Is Tested?
News Desk
Jul 9, 2026
4 min

From DeFi to AI: Why Crypto Investors Are Expanding Their Thesis
News Desk
Jul 9, 2026
4 min

MiCA Register Expands with 14 New CASPs Amid Slower Crypto Licensing Growth
News Desk
Jul 17, 2026
3 min

FATF Calls for Faster Crypto AML Enforcement as Stablecoin-Related Crime Rises
News Desk
Jul 17, 2026
4 min



