{"id":17455,"date":"2026-06-05T08:15:53","date_gmt":"2026-06-05T15:15:53","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=17455"},"modified":"2026-06-05T08:22:21","modified_gmt":"2026-06-05T15:22:21","slug":"zec-drops-30-as-shielded-labs-reveals-more-about-infinite-counterfeit-bug","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/06\/05\/zec-drops-30-as-shielded-labs-reveals-more-about-infinite-counterfeit-bug\/","title":{"rendered":"ZEC Drops 30% as Shielded Labs Reveals More About Infinite Counterfeit Bug"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The advanced cryptography methods used for privacy seem to have some bugs as implemented. ZEC was originally an interesting project for privacy, but it seems to have fallen under the control of questionable people as it has been pumped and dumped here lately. And they were working with TradFi to allow tracking or privacy, so they wouldn&#8217;t get dropped from exchanges. And you have to wonder if these bugs might be included purposely as it&#8217;s great for spreading fear and keeping people away from the Bitcoin exit to TradFi&#8230;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cointelegraph.com\/news\/zec-tanks-30-after-ai-security-review-discovers-critical-zcash-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/cointelegraph.com\/news\/zec-tanks-30-after-ai-security-review-discovers-critical-zcash-vulnerability<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_e534626a-ef9e-428f-b88b-1fcac6824968\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<h5 class=\"wp-block-heading\">ZEC market capitalization fell by almost $3 billion over the past 24 hours following the disclosure of a critical vulnerability, despite it being patched already.<\/h5>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/s3-images.ctmedia.io\/media\/article-covers\/c-man-falling.jpg\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The price of ZEC fell on Thursday after further details were disclosed of a critical counterfeiting vulnerability in Zcash\u2019s Orchard pool that could theoretically allow a bad actor to mint an unlimited amount of ZEC.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to a post on X, security engineer Taylor Hornby, who was engaged by Shielded Labs, <a href=\"https:\/\/x.com\/zooko\/status\/2062644925590900980?s=20\" rel=\"noreferrer noopener\" target=\"_blank\">discovered<\/a> the bug on May 29 and <a href=\"https:\/\/cointelegraph.com\/news\/zcash-orchard-vulnerability-emergency-upgrade\" target=\"_blank\" rel=\"noreferrer noopener\">disclosed it<\/a> to the Zcash Open Development Lab (ZODL), which deployed an emergency response to fix the vulnerability with a hard fork activated on June 3.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, there are new concerns about the extent to which the vulnerability, which has existed since May 2022, has been used, <a href=\"https:\/\/cointelegraph.com\/markets\/zcash-is-running-its-own-bull-market-zec-price-paints-88-rally-setup\">leading Zcash<\/a> to fall more than 30% over the past 24 hours to $410 at the time of writing. Its market capitalization has shrunk by more than $3 billion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, BitMEX co-founder Arthur Hayes <a href=\"https:\/\/x.com\/CryptoHayes\/status\/2062723034369458520\">said<\/a> on Friday it is unlikely that ZEC has been illegally minted this way, though he acknowledged \u201cit cannot be formally cryptographically proved impossible.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cSadly, due to the Orchard Pool exploit, I had to dump our entire ZEC bag,\u201d he said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe Holy Trinity is dead,\u201d he added, referring to Zcash and the two other tokens he sold this week, Hyperliquid (HYPE) and Near Protocol (NEAR).<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/s3-images.ctmedia.io\/media\/content\/pasted-image-212.jpeg\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><em>ZEC crashes 30% in 24 hours after two months of solid gains. Source:<\/em><a href=\"https:\/\/www.tradingview.com\/symbols\/ZECUSD\/?exchange=COINBASE\"><em>TradingView<\/em><\/a><\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Claude assists in bug discovery&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Taylor used Claude Opus 4.8, which was released on May 28, a day before the discovery, to assist in a highly targeted review of the Orchard circuit, the cryptographic component underlying Zcash\u2019s Orchard shielded pool.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The critical bug allowed false inputs into an elliptic curve multiplication check, which means the math that is supposed to cryptographically verify transactions could be fooled.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Taylor built and tested a working <a href=\"https:\/\/cointelegraph.com\/news\/coordinated-crypto-stealer-campaign-trapdoor-detected-targeting-developers\">exploit<\/a>, which generated unlimited counterfeit ZEC.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIf he had run the same tool on Zcash mainnet it would have generated unlimited, undetectable counterfeit ZEC in his mainnet Zcash wallet,\u201d the security researchers <a href=\"https:\/\/x.com\/zooko\/status\/2062644925590900980\">said<\/a> on Friday.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The primary concern is that there is no cryptographic way to prove whether anyone had previously exploited it before it was patched, due to Orchard\u2019s privacy properties.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, Shielded Labs was \u201cnot overly concerned\u201d because the bug was subtle enough to evade years of expert review, and the discovery was a deliberate, highly skilled effort using cutting-edge tools and AI.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The firm is working with <a href=\"https:\/\/cointelegraph.com\/news\/foundry-digital-launched-zcash-mining-pool\">Zcash<\/a> developers on a proposed network upgrade to allow anyone to verify the integrity of the ZEC supply and to prove the nonexistence of counterfeit tokens in the Orchard pool, they stated.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Not the first counterfeiting vulnerability for Zcash<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Mert Mumtaz, co-founder and CEO of Solana tooling firm Helius, <a href=\"https:\/\/x.com\/mert\/status\/2062658091431182492\">said<\/a> that almost all privacy protocols have a variant of this same vulnerability.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThis same FUD comes back every five months as new people learn how privacy pools work,\u201d he said.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He explained that it is a theoretical risk in most zero-knowledge privacy protocols from circuit bugs that are hard to exploit or detect.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is not the first time a similar vulnerability in Zcash has been discovered. In 2018, a counterfeiting vulnerability in the cryptography underlying zk-proofs was discovered by the Electric Coin Company, which <a href=\"https:\/\/electriccoin.co\/blog\/zcash-counterfeiting-vulnerability-successfully-remediated\/\">remediated it<\/a> with no losses in 2019.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The advanced cryptography methods used for privacy seem to have some bugs as implemented. ZEC was originally an interesting project for privacy, but it seems to have fallen under the control of questionable people as it has been pumped and dumped here lately. And they were working with TradFi to allow tracking or privacy, so [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-17455","post","type-post","status-publish","format-standard","hentry","category-tech"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/17455","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=17455"}],"version-history":[{"count":3,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/17455\/revisions"}],"predecessor-version":[{"id":17458,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/17455\/revisions\/17458"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=17455"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=17455"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=17455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}