Critical Zcash Vulnerability Found and Fixed
A researcher found a critical flaw in Zcash's Orchard privacy pool that could have let attackers mint ZEC. Zcash says it has been fixed.
Intelligence analysis by GPT-5.4 Mini
Bruce Schneier highlights a serious bug in Zcash’s newest shielded transaction system: a check that looked like it enforced rules did not actually do so. That gap could have allowed fraudulent transactions to pass as valid and create coins from nothing.
A lock on a piggy bank looked strong, but one tiny part did not really work. That meant someone might have slipped in fake money and the bank could still have said it was real. The lock is fixed now, but nobody knows if anyone already took cash.
Analysis
What happened
On May 29, security researcher Taylor Hornby found a critical vulnerability in Zcash’s Orchard privacy pool, the newest and most advanced shielded transaction system in the cryptocurrency. Schneier says Zcash hired Hornby specifically to look for issues like this, and he found one quickly enough to be embarrassing.
Why the bug was serious
The Orchard pool was introduced in 2022 and is designed to let users send and receive ZEC while keeping transaction details private. It uses zero-knowledge proofs so the network can verify a transaction without learning the amounts or participants. The flaw, as described in the post, was that a specific check intended to validate transaction inputs was not actually enforcing the rules it seemed to enforce. In practice, that meant an attacker could have supplied false inputs, and the proof system would still have accepted the transaction as valid.
Schneier summarizes the consequence starkly: the bug could have let someone generate ZEC from nothing.
What is known now
The good news is that the issue has been fixed. The bad news is that there is no way to know whether anyone exploited it before the patch. That uncertainty is central to the post’s criticism of blockchain systems: if the system is fragile enough that a hidden flaw can create money, users may never learn whether the ledger was compromised in the real world.
Bottom line
This is both a specific Zcash security incident and a broader warning about the trust assumptions behind blockchain-style systems. The fix closes the immediate hole, but the article argues that the underlying model remains fragile.
Key points
- A security researcher found a critical flaw in Zcash's Orchard privacy pool on May 29.
- The Orchard pool is Zcash's newest shielded transaction system and uses zero-knowledge proofs.
- The bug could have let an attacker feed false inputs and generate ZEC from nothing.
- Zcash says the issue has been fixed, but past exploitation cannot be ruled out.
The flaw was found and fixed, which closes the immediate path for counterfeit ZEC creation. Zcash can also use the incident to harden the Orchard system and improve confidence in its checks.
The article says there is no way to know whether the flaw was exploited before the fix, so any theft could be invisible. It also suggests the incident feeds a broader concern that blockchain systems can hide serious accounting failures until after the damage is done.



