Brutal Zcash Bug Sat Hidden for 4 Years
Friday, 5 June 2026 · 4 min read · Listen to the episode ↗
A critical soundness vulnerability lurked inside the Zcash Orchard zero-knowledge proof circuit for roughly four years before an emergency patch on June 1, 2026, and because of Orchard's privacy properties there is no cryptographic way to determine whether an attacker silently minted unlimited counterfeit ZEC during that window.
A critical soundness vulnerability existed in the Zcash Orchard zero-knowledge proof circuit from approximately May 2022 until an emergency fix on June 1, 2026, a span of roughly four years. The bug could have allowed an attacker to undetectably mint an unlimited quantity of counterfeit ZEC within the Orchard pool. Because of Orchard's privacy properties, there is currently no cryptographic way to determine whether the vulnerability was exploited before it was patched, meaning it is genuinely unknown whether the true ZEC supply has been inflated. A future network upgrade is planned to enable supply auditing, though that process will require vetting both the total supply and the supply within the privacy pool itself.
The Zcash Foundation's initial June 3 disclosure described the bug as not enabling inflation of the total ZEC supply, a claim that was directly contradicted by a subsequent post from Zuko Wilcox, Jason McGee, and Taylor Hornby clarifying the true severity. ZEC did not react significantly to the initial disclosure but crashed sharply once the corrected severity became public, falling approximately 29 to 30 percent in a single day and nearly 47 percent over three days. David Kanellis noted the three-day loss was worse than Zcash's COVID crash and worse than the May 2021 Terra-related wipeout, ranking as the seventh worst one-day drop in Zcash's history across nearly ten years. Despite this, ZEC had been up approximately 1,000 percent over the prior year and remained up around 500 percent even after the roughly 50 percent retracement.
There was no evidence of outsized ZEC selling before the corrected severity was made public. Craig Sarm argued that believing the vulnerability was exploited requires assuming an attacker examined the Zcash codebase more thoroughly than all core developers and security contributors combined, and also that the attacker resisted selling counterfeit ZEC during a historical 20x-plus bull run, which he considers unlikely. The security researcher who discovered the bug used an AI tool, specifically Claude Opus, to understand and confirm the vulnerability was real.
The disclosure represents a second instance in which Zcash holders must trust without verification that nothing went wrong. The first was the original key ceremony in which six individuals each briefly held part of a private key that, if all six had colluded and combined their shares, would have constituted a master key capable of undermining Zcash's zero-knowledge proofs entirely. Both episodes place a structural ceiling on the assurances the network can offer its users.
Strategy filed an 8-K on June 1 disclosing the sale of 32 bitcoin between May 26 and May 31, generating approximately 2.5 million dollars at an average net price of 77,000 dollars per bitcoin. The 32 bitcoin represented 0.0038 percent of Strategy's total bitcoin treasury according to Galaxy, and the sale was Strategy's first disclosed bitcoin sale since December 2022.
A Polymarket prediction market had asked whether MicroStrategy would sell any bitcoin by May 31, 2026, with odds ranging between roughly 10 and 30 percent before the sale was disclosed. Despite Strategy's own 8-K listing 32 bitcoin as sold within the May 26 to May 31 window, UMA oracles resolved the market No on the basis that no on-chain data or credible reporting confirmed the sale before the deadline. One participant had purchased 700,000 Yes shares at approximately 76 cents each after the news broke, treating it as near-certain arbitrage since each share pays one dollar on a Yes resolution. The dispute centers on whether the event date or the confirmation date governs resolution, with the original market rules being event-based and a subsequent bulletin introducing a confirmation-based standard that traders characterized as a retroactive rule change. Polymarket comment sections filled with accusations of fraud and rule manipulation following the outcome.
US spot bitcoin ETFs recorded 12 consecutive trading days of outflows totaling approximately 4.5 billion dollars before the streak broke on June 4 with 3.2 million dollars in net positive flows. BlackRock's IBIT recorded 47.7 million dollars in net inflows on that day and MSBT saw 9.9 million dollars. US spot Ethereum ETFs recorded 19.3 million dollars in net inflows on the same day, while Solana spot ETFs saw no activity. Hyperliquid spot ETFs recorded 12.2 million dollars in inflows on that day, bringing total cumulative inflows to 158 million dollars with no days of net outflows recorded so far.
This summary was generated from the episode transcript and can contain mistakes.