Zcash weighs new shielded pool after Orchard bug
Zcash developers are considering a new shielded pool and accounting rules after an Orchard vulnerability raised questions about supply verification.
Intelligence analysis by GPT-5.4 Mini

Shielded Labs says it is exploring a network upgrade that could add a new shielded pool and “turnstile accounting” to make coins leaving Orchard easier to verify. The discussion follows an emergency fix for a flaw that may have allowed counterfeit ZEC inside Orchard, while the token sold off sharply after disclosure.
Zcash found a crack in one of its hidden-money rooms, and people are discussing how to build a safer room next time. It is like finding a mistake in a lock and then deciding whether to add a second lock and a better checklist.
Analysis
What happened
Zcash developers and researchers are debating whether a new shielded pool should be added after a recently patched Orchard vulnerability raised questions about supply verification. Shielded Labs, a Swiss-based Zcash support organization, said it is exploring a proposed upgrade that would introduce a new shielded pool and add “turnstile accounting” for coins moving out of Orchard. The group said the idea still needs more explanation and community review, and it plans to publish a follow-up post next week on how the upgrade would work and what tradeoffs it may bring.
Why the fix is being discussed
According to Shielded Labs, the Orchard bug could have allowed a bad actor to create counterfeit ZEC inside the pool. The group said there is no cryptographic way to prove whether the issue was exploited before it was fixed, though it believes prior exploitation was unlikely. Zcash developers had temporarily suspended Orchard transactions after finding the flaw and then restored functionality through an emergency network upgrade.
Market and technical reaction
The disclosure hit the market hard. CoinGecko data cited in the article shows ZEC fell by about 50% on Friday, dropping from a daily high of $550.30 to as low as $264.80 before recovering to $308.07 at the time of writing. Some community figures argued the market overreacted because the bug was fixed, while others said the incident shows why bug-finding and rapid patching matter in layer-1 systems.
Longer-term debate
The incident revived discussion around formal verification. Zcash developer and cryptography researcher Sean Bowe argued that shielded protocols should eventually be made formally verifiable. Josh Swihart said the flaw was in handwritten circuit rules rather than the underlying cryptography, and Wei Dai said expanding formal verification is likely the only long-term answer.
Key points
- Shielded Labs is exploring a new shielded pool and turnstile accounting after the Orchard bug.
- The group said the flaw could have allowed counterfeit ZEC, but prior exploitation is believed unlikely.
- Zcash temporarily suspended Orchard transactions and restored them through an emergency network upgrade.
- ZEC fell sharply after the disclosure before partially recovering.
- The incident renewed debate over formal verification as a long-term security solution.
If the proposed upgrade works, it could make Zcash's shielded system easier to verify and restore confidence in ZEC supply integrity. A stronger verification setup could also reduce the chance that a similar bug causes the same level of market shock again.
The proposal could take time to explain, review, and implement, and the article says it is still under community discussion. If the fix or the new pool design adds complexity without fully solving verification concerns, confidence in the shielded system could remain fragile.



