A critical counterfeiting vulnerability in Zcash's Orchard pool was discovered, causing ZEC price to drop 30%. A security engineer found the bug using Anthropic's Claude Opus 4.8; the patch is deployed but exploitation cannot be ruled out.
A critical counterfeiting vulnerability was discovered in Zcash's Orchard privacy pool, allowing unlimited counterfeit ZEC creation. Security engineer Taylor Hornby, hired by Shielded Labs, found the bug on May 29 and reported it; a hard fork patch was activated on June 3. The vulnerability existed since May 2022 and bypasses elliptic curve multiplication checks. Anthropic's Claude Opus 4.8 was used in the discovery.
Zcash is a privacy coin based on zero-knowledge proofs; Orchard is its latest privacy pool. The bug resided in the Orchard circuit's cryptographic verification logic, enabling undetectable counterfeit ZEC generation. A similar counterfeiting vulnerability was found in Zcash in 2018.
While patched, Orchard's privacy properties make it impossible to cryptographically prove past exploitation. Shielded Labs considers actual exploitation unlikely due to the bug's subtlety and the sophisticated tools required. This incident highlights that circuit verification vulnerabilities in privacy protocols can pose real-world threats.
Zcash's 30% drop was triggered by Anthropic AI (Opus 4.8) discovering a 4-year-old counterfeiting vulnerability that passed multiple security audits. Comments note that due to zero-knowledge design, there is no way to verify if the bug was exploited, meaning the entire ~$1.3 billion in the Orchard pool could have been minted from nothing. It is also mentioned that a similar counterfeiting bug was disclosed in 2019 but no exploitation was reported.