Zcash developers completed an emergency hard fork this week after an audit found a critical soundness bug in the Orchard shielded pool, the network’s main privacy layer. The flaw, hidden in two lines of circuit code since May 2022, could have let an attacker mint counterfeit ZEC with no on-chain trace. ZEC fell more than 45% in 24 hours as the disclosure spread, trading near $273 on June 5 after briefly topping $600 earlier in the rally. Maelstrom CIO Arthur Hayes sold his entire position, saying he could not be sure the token’s supply was still sound.
A shielded pool is the part of Zcash that hides transaction amounts and addresses using zero-knowledge proofs, so coins can move without revealing who sent what. The bug lived inside the cryptographic circuit that validates those private transfers.
- Security researcher Taylor Hornby found an under-constrained element in Zcash’s Orchard circuit on May 29 while auditing for Shielded Labs, using Anthropic’s Claude Opus 4.8 to build a working proof-of-concept exploit.
- The flaw could have allowed undetectable counterfeit ZEC inside the shielded pool. It was present from Orchard’s launch in May 2022 until the fix shipped on June 1.
- An emergency soft fork disabled Orchard on June 2, and the NU6.2 hard fork re-enabled it with corrected code on June 3, only the second security-driven upgrade in Zcash’s history.
- ZEC dropped roughly 45% to about $273 by June 5. Arthur Hayes liquidated his full position, completing the unwind of his “Holy Trinity” portfolio.
Published: June 5, 2026, 16:00 UTC
What the bug actually did
The vulnerability was an under-constrained input to an elliptic-curve multiplication inside the Orchard proof circuit, specifically in the halo2_gadgets code that Zcash relies on to verify shielded transactions. In plain terms, the circuit was supposed to reject mathematically invalid inputs but did not, so false values could pass a check that should have failed them.
That gap created a path to forge ZEC inside the pool with no on-chain signature. Taylor Hornby, an independent security engineer auditing the protocol for Shielded Labs, identified the issue on May 29. He used Anthropic’s Claude Opus 4.8 alongside a custom tool to write an exploit that minted counterfeit ZEC in a local test environment, confirming the flaw was real rather than theoretical.
The bug had been live since the Orchard pool activated in May 2022. The Zcash Foundation said it found no evidence of exploitation and no impact on user privacy. The harder problem is proof: because Orchard hides transaction data by design, there is no cryptographic way to confirm that no counterfeit ZEC was created during the four-year window. The flaw is unrelated to Zcash’s separate work on quantum-recoverable wallets announced earlier this year.
The emergency response
Zcash moved fast once the flaw was confirmed. A temporary soft fork activated at mainnet block 3,363,426 around 02:00 UTC on June 2, switching off Orchard actions across the network while engineers prepared corrective code. The patch itself landed on June 1.
The NU6.2 hard fork then activated at block 3,364,600 on June 3, re-enabling Orchard with a fixed circuit. The Foundation described it as only the second security-driven protocol upgrade in the network’s history since 2016, a rare step that required coordinated action from node operators, miners, and exchanges within days.
Why the market reacted hard
ZEC had been one of 2026’s standout performers, surging past $600 and briefly overtaking monero by market capitalization before the disclosure. The bug erased much of that. The token slid more than 45% over 24 hours to around $273, with The Block reporting liquidations topping $100 million as leveraged positions unwound.
Arthur Hayes amplified the move. The Maelstrom CIO and BitMEX co-founder, who had publicly championed the privacy token, said on X that he sold his entire ZEC holding. He called counterfeiting extremely unlikely but said it could not be cryptographically ruled out, enough to shake his confidence in the token’s supply. Hayes added he might buy back in if those concerns prove unfounded. The sale completed the unwind of his self-described “Holy Trinity” portfolio, which had also held HYPE and NEAR.
What comes next
Shielded Labs has proposed a follow-up upgrade to let anyone verify that ZEC’s supply has not been secretly inflated. The plan would deploy a new shielded pool and route coins leaving Orchard through turnstile accounting, a method that tracks value moving in and out of a pool so the total can be checked against the known supply. It would need to pass Zcash’s governance process before activation.
The team is also launching a project to formally verify the Orchard circuit using mathematical proof methods, and has opened searches for a Head of Security and a Cryptographer. The episode is likely to draw fresh scrutiny to other zero-knowledge systems that depend on hand-written circuits, where a single under-constrained value can sit undetected for years.
Frequently asked questions
Was any counterfeit ZEC actually created?
The Zcash Foundation says there is no evidence the bug was exploited and no sign of unauthorized value creation. Because Orchard is private by design, however, there is no way to prove cryptographically that no counterfeiting happened during the four-year window the flaw was live.
Is Zcash safe to use now?
The NU6.2 hard fork on June 3 re-enabled the Orchard pool with corrected circuit code, and shielded transactions are functioning again. Shielded Labs has proposed an additional upgrade to let users independently verify the network’s total supply.
How was the bug found?
Researcher Taylor Hornby discovered it during a protocol audit for Shielded Labs on May 29, using Anthropic’s Claude Opus 4.8 and a custom tool to build a working exploit that minted counterfeit ZEC in a local test environment.








