Zcash plummets 30% as Shielded Labs reveals a major bug that went undetected for four years
Zcash plummets 30% as Shielded Labs reveals a major bug that went undetected for four years
Publish Date: 2026-06-05 01:46:00
Source Domain: www.coindesk.com
Privacy-focused zcash (ZEC) has taken a beating in the past 24 hours, falling roughly 30% to $400 amid broader market weakness. The selling accelerated after Shielded Labs, a nonprofit Zcash developer, disclosed a critical vulnerability in the blockchain’s Orchard privacy pool that could have threatened the integrity of the token’s supply.
Late Thursday, Shielded Labs published a detailed disclosure on X, revealing a vulnerability that, if exploited, could have allowed an attacker to create an unlimited number of counterfeit ZEC tokens, completely undetected. Think of it as someone secretly gaining access to the Federal Reserve’s dollar printing press, except in this case, even the Fed wouldn’t be able to tell these extra dollars were printed.
The vulnerability was discovered on May 29 by Taylor Hornby, a security engineer engaged by Shielded Labs in April 2026 specifically to identify protocol vulnerabilities before malicious actors could. Working with Anthropic’s recently released Opus 4.8 AI model, Hornby conducted a highly targeted review of the Orchard circuit, which is the cryptographic system underpinning Zcash’s most advanced privacy pool.
Shielded Labs said Hornby wrote a complete exploit which, when tested in a local testing environment, generated unlimited, undetectable counterfeit ZEC. Shielded Labs added that if the same tool had been run on Zcash mainnet, it would have generated unlimited, undetectable counterfeit tokens in his mainnet wallet.
Imagine an attacker quietly printing unlimited counterfeit ZEC and holding them undetected. The damage to trust in the supply and, by extension, the token’s market value could have been severe.
Hornby immediately disclosed the vulnerability to the Zcash Open Development Lab (ZODL), which coordinated an emergency fix on June 1, closing it within days of discovery.
Bug undetected for four years
Still, what appears to be a proactive approach to fixing bugs has not impressed markets. That’s possibly because, as Shielded…