Incident case file
Sign in to watchZcash Orchard — Critical Undetectable Counterfeiting Vulnerability Disclosed (AI-Assisted Discovery)
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: N/A — white-hat discovery by security researcher Taylor Hornby (commissioned by Shielded Labs). No known exploitation. Proof-of-concept generated counterfeit ZEC only in local test environment. Vulnerability patched before public disclosure. Because Orchard is a privacy pool, cryptographic determination of whether exploitation occurred between May 2022 and June 2026 is impossible by design.
Timeline: May 2022 — Zcash Orchard shielded pool activated. The critical counterfeiting vulnerability is introduced into the codebase at this time, remaining undetected through multiple human security audits over four years. May 29, 2026 — Security researcher Taylor Hornby, commissioned by Shielded Labs, discovers the critical counterfeiting vulnerability in Zcash's Orchard pool using Anthropic Claude Opus 4.8 and a custom AI-assisted audit framework. Hornby writes a complete proof-of-concept program that successfully generates counterfeit ZEC in local testing. Immediate responsible disclosure to the Zcash security team. June 2, 2026 ~02:00 UTC — Zcash deploys emergency soft fork at block 3,363,426, disabling all Orchard shielded transactions to prevent any potential exploitation while the fix is prepared. June 3, 2026 ~00:05 EDT — Zcash deploys hard fork NU6.2 at block 3,364,600, fixing the under-constrained ZK circuit element. Vulnerability fully patched before any public disclosure. June 4, 2026 — Zcash founder Zooko Wilcox publishes details on the Zcash Community Forum. WuBlockchain reports the disclosure publicly. June 5, 2026 — CoinDesk publishes: 'Zcash plummets 38% as developer reveals a major bug that went undetected for four years.' Yahoo Finance, Decrypt, Unchained, and Sherwood amplify the story. ZEC price drops 38-50% on the news. Zooko Wilcox, Jason McGee and Taylor Hornby publish joint disclosure noting: the vulnerability was present for four years, prior exploitation is considered unlikely but cannot be cryptographically proven due to Orchard's privacy properties, and the remediation window was narrow. The Zcash community begins discussion of integrating AI-assisted security reviews as a standard practice for future protocol upgrades.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)