Bitcoin Info News Logo
Bitcoin NewsAlt Coin NewsMiningBlockchain EventTop ProjectSponsored ArticlesPress Release
Bitcoin NewsAlt Coin NewsMiningBlockchain EventTop ProjectSponsored ArticlesPress Release
Sponsorship
Sponsorship
Home/Alt Coin News/Zcash Founder Confirms Orchard Bug Could Allow Unlimited ZEC Creation
Alt Coin News

Zcash Founder Confirms Orchard Bug Could Allow Unlimited ZEC Creation

Jamila Okonkwo
Bitcoin Info News Logo

Bitcoin Info News is an independent digital publication focused on Bitcoin, crypto markets, blockchain infrastructure, regulation, and adoption.

Follow on Google

Contact the editorial teamView newsroom and editorial contacts

Social

FacebookYouTubeTelegramXLinkedIn
Jamila Okonkwo
Published:Jun 5, 2026
Last updated:Jun 22, 2026
4 MIN READ
MakeBitcoin Info Newspreferred onGoogle

Zcash’s founder confirmed an Orchard protocol bug that could allow unlimited ZEC creation. Here’s what the flaw means and why it matters for the network.

Zcash founder Zooko Wilcox confirmed on June 4, 2026 that a critical bug in the Orchard shielded protocol could have allowed an attacker to create an unlimited amount of counterfeit ZEC, and that there is no cryptographic way to prove whether the flaw was exploited before it was patched.

The disclosure, co-authored by Wilcox, Jason McGee, and Taylor Hornby, was published on the Zcash Community Forum. It represents a significant escalation from earlier remediation messaging, which had framed the incident as resolved without evidence of exploitation.

Hornby discovered the vulnerability on May 29, 2026 while auditing Zcash for Shielded Labs. Orchard is the newest shielded pool in Zcash, designed to provide private transactions using the Halo 2 proving system. The bug resided in the circuit logic governing Orchard actions.

What the Orchard Bug Could Have Done

In Wilcox’s words: “The vulnerability could have been exploited to undetectably create an unlimited amount of counterfeit ZEC within Orchard.” That framing matters because it means any exploitation would have been invisible to outside observers, hidden by the same privacy guarantees that protect legitimate transactions.

“The vulnerability could have been exploited to undetectably create an unlimited amount of counterfeit ZEC within Orchard.”

— Zooko Wilcox, Zcash Community Forum

For any cryptocurrency, supply integrity is foundational. A fixed or predictable issuance schedule underpins scarcity assumptions and, by extension, market valuation. A flaw that permits unlimited token creation strikes at the core trust model.

ZEC was trading at $424.15 at press time, with a circulating supply of roughly 16.75 million coins and a market cap of approximately $7.17 billion.

ZEC Spot Price
$424.15
CoinGecko public market data for Zcash.

The token fell roughly 26.47% over the preceding 24 hours, with trading volume spiking to nearly $1.49 billion as markets reacted to the expanded disclosure.

ZEC 24h Change
-26.47%
CoinGecko public market data for Zcash.

The broader crypto market was already under pressure. The Fear & Greed Index sat at 12, firmly in “Extreme Fear” territory, meaning ZEC’s sell-off landed in an environment where risk appetite was already thin.

Why the Zcash Foundation’s Earlier Framing Fell Short

The Zcash Foundation’s initial remediation post on June 3 stated that “there is no evidence of unauthorized value creation.” That assessment was based on turnstile analysis, a method that checks the flow of ZEC between shielded pools and the transparent chain.

Wilcox’s June 4 follow-up made clear that turnstile checks are insufficient. Because Orchard’s privacy model prevents external observation of pool-internal activity, any counterfeit ZEC created and kept within Orchard would be invisible to turnstile-based audits. The post proposes a further network upgrade that would allow anyone to cryptographically prove supply integrity.

This gap between “no evidence of exploitation” and “exploitation cannot be ruled out” is the central tension. It echoes challenges faced by other privacy-focused protocols, where the same features that protect users can also obscure attacks. As regulators increasingly frame crypto as financial infrastructure, the ability to verify supply becomes a governance question, not just a technical one.

How the Bug Was Fixed

The response moved fast. The Zcash Foundation released Zebra 4.5.3, which temporarily disabled all Orchard actions via an emergency soft fork that activated at approximately 02:00 UTC on June 2, 2026. This effectively froze the vulnerable pool while a permanent fix was prepared.

Zebra 5.0.0 then activated NU6.2, a hard fork that re-enabled Orchard with a corrected circuit. That activation occurred on June 3, 2026 at 00:05 EDT, at block height 3,364,600. Affected software versions included halo2_gadgets prior to v0.5.0, orchard prior to v0.14.0, zcash_primitives prior to v0.28.0, zcashd v5.0.0 through v6.12.3, and zebrad below v4.5.1.

A separate Zcash Community Forum post confirmed that Orchard functionality was fully restored within days of the initial discovery.

What to Watch Next

The most consequential open question is whether the proposed follow-up network upgrade to prove supply integrity will gain traction. Wilcox’s post frames it as necessary for anyone to verify that no counterfeit ZEC exists in Orchard, which would require a new cryptographic mechanism or a shielded pool migration.

Such an upgrade would need to go through Zcash’s standard network-upgrade and ecosystem coordination process. Exchanges and wallet providers will likely monitor whether the Zcash community commits to a timeline. In an environment where policymakers are scrutinizing crypto governance, the speed and transparency of that process will shape perceptions of the project’s credibility.

For ZEC holders, the practical takeaway is straightforward: the immediate vulnerability is patched, but the question of whether it was exploited before May 29 remains formally unanswered. No action is required from users today, but the integrity proof upgrade, if it arrives, would be the definitive resolution.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Article Topics

Alt Coin News

Editor Picks

If You Only Read 3 Things Today

Fastest way to catch the signal before you keep scrolling.

#1 Iran Uses Bitcoin USDT to Bypass...#2 US Bitcoin ETFs Draw 987 Million...#3 VerifiedX Launches 15M Bitcoin Infrastructure Financing...

Most Read

1

Iran Uses Bitcoin, USDT to Bypass US Sanctions: FT

Sep 9, 2026•3 MIN READ
2

US Bitcoin ETFs Draw $987 Million in Weekly Inflows

Sep 9, 2026•3 MIN READ
3

VerifiedX Launches $15M Bitcoin Infrastructure Financing Round

Sep 9, 2026•2 MIN READ
4

Bitcoin ETFs Erase Most 2026 Losses, With $1B Left to Go

Sep 9, 2026•3 MIN READ
5

Block Applies to OCC for Builders Bank & Trust

Sep 9, 2026•3 MIN READ

Quick Categories

Bitcoin News
Alt Coin News
Mining
Blockchain Event
Top Project

Partnerships

Advertise With Us

Reach active Bitcoin readers, builders, and spenders.

Learn More
Megaphone
CoinMarketCap

Company

  • About Us
  • Authors
  • Masthead
  • Team Verification
  • Contact Us

Resources

  • RSS Feeds
  • Editorial Policy
  • Corrections Policy
  • Terms of Service
  • Privacy Policy
  • Disclaimer
  • Sitemap

Tools

Quick access to the site tools and map-driven utility pages.

BTC Merchant MapToolMerchants by CountryToolTop Merchant CountriesToolGovernment Holdings MapTool

Coverage

RSS Feeds

Follow the core desks readers use most across Bitcoin, altcoins, mining, events, and sponsored coverage.

Bitcoin NewsDeskAlt Coin NewsDeskMiningDeskBlockchain EventDeskTop ProjectDeskSponsored ArticlesDesk

© 2026 BitcoinInfoNews.com. All rights reserved.

Independent Bitcoin and crypto coverage with public trust, policy, and newsroom pages available sitewide.

Sponsored Articles
Press Release
Millionaire