← Radar

Incident case file

Sign in to watch

Zcash Orchard — Critical Undetectable Counterfeiting Vulnerability Disclosed (AI-Assisted Discovery)

Incident date June 5, 2026

1 views

ResolvedZcashProtocol Vulnerability / ZK CircuitCluster: ZCASH-ORCHARD-2026-06

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: N/A — white-hat discovery by security researcher Taylor Hornby (commissioned by Shielded Labs). No known exploitation. Proof-of-concept generated counterfeit ZEC only in local test environment. Vulnerability patched before public disclosure. Because Orchard is a privacy pool, cryptographic determination of whether exploitation occurred between May 2022 and June 2026 is impossible by design.

Funds moved to: N/A — no funds stolen. Market impact: ZEC price declined approximately 38-50% following public disclosure on June 5 2026 (Yahoo Finance: '38%'; BitMEX Blog: '~50% in 48 hours, from $624 to $309'). Arthur Hayes liquidated ZEC position post-disclosure. No on-chain theft detected.
N/A — no attacker wallets. Vulnerability location: Orchard shielded pool proof verification circuit, present since Orchard activation (May 2022). Root cause: under-constrained element in the ZK circuit allowing invalid inputs to pass an elliptic curve multiplication check. A valid-looking proof could be constructed that violated the conservation of value invariant, enabling unlimited undetectable ZEC counterfeiting. Discovery method: Taylor Hornby used Anthropic Claude Opus 4.8 (newly released

Timeline: May 2022 — Zcash Orchard shielded pool activated. The critical counterfeiting vulnerability is introduced into the codebase at this time, remaining undetected through multiple human security audits over four years. May 29, 2026 — Security researcher Taylor Hornby, commissioned by Shielded Labs, discovers the critical counterfeiting vulnerability in Zcash's Orchard pool using Anthropic Claude Opus 4.8 and a custom AI-assisted audit framework. Hornby writes a complete proof-of-concept program that successfully generates counterfeit ZEC in local testing. Immediate responsible disclosure to the Zcash security team. June 2, 2026 ~02:00 UTC — Zcash deploys emergency soft fork at block 3,363,426, disabling all Orchard shielded transactions to prevent any potential exploitation while the fix is prepared. June 3, 2026 ~00:05 EDT — Zcash deploys hard fork NU6.2 at block 3,364,600, fixing the under-constrained ZK circuit element. Vulnerability fully patched before any public disclosure. June 4, 2026 — Zcash founder Zooko Wilcox publishes details on the Zcash Community Forum. WuBlockchain reports the disclosure publicly. June 5, 2026 — CoinDesk publishes: 'Zcash plummets 38% as developer reveals a major bug that went undetected for four years.' Yahoo Finance, Decrypt, Unchained, and Sherwood amplify the story. ZEC price drops 38-50% on the news. Zooko Wilcox, Jason McGee and Taylor Hornby publish joint disclosure noting: the vulnerability was present for four years, prior exploitation is considered unlikely but cannot be cryptographically proven due to Orchard's privacy properties, and the remediation window was narrow. The Zcash community begins discussion of integrating AI-assisted security reviews as a standard practice for future protocol upgrades.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)