PodBrowser
The Breakdown

Brutal Zcash Bug Sat Hidden for 4 Years

Friday, 5 June 2026 · 4 min read · Listen to the episode ↗

A critical soundness vulnerability in Zcash's Orchard zero-knowledge proof circuit went undetected for roughly four years before an emergency patch was deployed on June 1, 2026, and the flaw could have allowed unlimited counterfeit ZEC to be minted without detection. Because of Orchard's privacy properties, there is no cryptographic way to confirm whether exploitation occurred, leaving the true ZEC supply unknown.

A critical soundness vulnerability in the Zcash Orchard zero-knowledge proof circuit sat undetected for approximately four years, from the activation of Sapling in May 2022 until an emergency patch was deployed on June 1, 2026. The bug could have allowed invalid transactions to be accepted as legitimate, enabling double spending and the undetectable creation of unlimited counterfeit ZEC within the Orchard pool. The Zcash Foundation's initial June 3 blog post incorrectly stated there was no ability to inflate the total ZEC supply. Shielded Labs, led by Zuko Wilcox, Jason McGee, and Taylor Hornby, published a correction on June 4 clarifying that supply inflation was in fact possible.

Because of Orchard's privacy properties, there is no cryptographic way to determine whether the vulnerability was exploited before it was patched. The true supply of ZEC is therefore currently unknown. A future network upgrade is planned that would allow auditing of supply integrity, requiring examination of not only the total supply but also the supply within the privacy pool itself.

The market largely ignored the June 3 disclosure but crashed sharply after the more severe June 4 correction, with ZEC falling approximately 29 to 30 percent in a single day and nearly 47 percent over three days. The one-day drop ranked as the seventh worst in Zcash's nearly ten-year history, worse than its COVID drawdown and worse than the May 2021 Terra collapse. Zcash had been up approximately 1000 percent over the prior year before retracing roughly 50 percent of those gains. There is no evidence of outsized ZEC selling before the true severity became public.

Craig Sarm argued that exploitation before the patch was unlikely on two grounds. First, an attacker would have needed to examine the Zcash codebase more thoroughly than all core developers and security contributors combined. Second, any attacker holding the ability to mint unlimited ZEC would have had to resist selling during a historical bull run exceeding 20x. The security researcher who discovered the bug used an AI tool, specifically Claude Opus, to understand and confirm the vulnerability was real.

Zcash holders must now accept two separate unverifiable trust assumptions: that the original key ceremony, which involved six individuals each briefly holding part of a private key capable of undermining the chain's zero-knowledge proofs, was conducted legitimately, and that the infinite minting bug was never exploited during its four-year window.

Strategy filed an 8-K on June 1 disclosing the sale of 32 bitcoin between May 26 and May 31, 2026, generating approximately two and a half million dollars at an average net price of 77 thousand dollars per bitcoin. The 32 bitcoin represented 0.0038 percent of Strategy's total bitcoin treasury, and the sale was its first disclosed bitcoin transaction since December 2022. Polymarket's UMA oracles resolved a market asking whether Strategy would sell bitcoin by May 31 as No, despite the 8-K confirming sales occurred within that window. The no camp argued that absent public confirmation before June 1 there was nothing to resolve on by the deadline, while the yes camp argued the filing itself listed sale dates falling within the period, making the event date the governing factor. One participant bought 700,000 Yes shares at approximately 76 cents each after the sale news emerged, treating it as a near-certain arbitrage since each share pays one dollar on a Yes resolution. Yes odds had spiked from around 10 percent to approximately 80 percent before the No resolution was issued. The original market rules were event-based and required only that Strategy sell any bitcoin by the deadline with no announcement requirement, and a subsequent bulletin introducing a confirmation requirement was characterized as a retroactive rule change.

US spot Bitcoin ETFs ended a streak of 12 consecutive trading days of outflows totaling approximately four and a half billion dollars on June 4, recording 3.2 million dollars in net positive flows. BlackRock's IBIT led with 47.7 million dollars in inflows while MSBT added 9.9 million dollars. US Ethereum spot ETFs recorded 19.3 million dollars in net inflows on the same day. Hyperliquid spot ETFs recorded 12.2 million dollars in inflows that day and have recorded positive net flows every single day since launch, reaching 158 million dollars in cumulative inflows with no days of net outflows.

This summary was generated from the episode transcript and can contain mistakes.