What's Hot

    Bitcoin Reverses 24-Hour Rally as Glassnode Flags 8M BTC at a Loss

    06/09/2026

    Bitcoin investor says he stopped paying taxes to stack more BTC

    06/09/2026

    Kristin Smith pushes Senate to protect crypto developers in CLARITY Act

    06/09/2026
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    CoinFlashDaily | Crypto Currency News
    • Home
    • Business

      Kraken Parent Payward Buys Reap Technologies in $600M Deal

      06/09/2026

      Ethereum Foundation Sees 2 More High-Profile Departures

      06/09/2026

      World Liberty-Linked AI Financial Flags Going Concern

      06/08/2026

      5 Crypto Companies Shutter This Week in Market Slump

      06/07/2026

      Novogratz Appears in Court Over Failed BitGo Deal: Report

      06/07/2026
    • News
      1. Business
      2. Analysis
      3. View All

      Kraken Parent Payward Buys Reap Technologies in $600M Deal

      06/09/2026

      Ethereum Foundation Sees 2 More High-Profile Departures

      06/09/2026

      World Liberty-Linked AI Financial Flags Going Concern

      06/08/2026

      5 Crypto Companies Shutter This Week in Market Slump

      06/07/2026

      Ethereum Price Structure ‘Weakening’ as Traders Focus on $1.8K Support

      06/09/2026

      XRP May Reach $10 By 2027—But Bearish Conditions Could Push It Below $1, Expert Says

      06/09/2026

      Bitmine’s Ether Holdings Reach 5.54M ETH After Latest Purchase

      06/09/2026

      What’s Going Wrong With XRP? Expert Points To 2 Major Bearish Flips In These Key Metrics

      06/09/2026

      Kristin Smith pushes Senate to protect crypto developers in CLARITY Act

      06/09/2026

      The Future of Perps in America

      06/09/2026

      Zcash price jumps as Ironwood plan targets counterfeit token concerns 

      06/09/2026

      Why Crypto Bled and Bounced

      06/09/2026
    • Analysis
      1. Bitcoin
      2. Ethereum
      3. Eurozone
      4. Monero
      5. View All

      Bitcoin price tests $60k as Saylor hints at more buying

      06/07/2026

      Why Cardano’s social activity surges as ADA crashes

      06/07/2026

      AVAX price crashes to early 2021 support, is a bottom forming?

      06/06/2026

      Dogecoin price nears $0.067 risk zone after 25% monthly crash

      06/05/2026

      Ethereum Price Structure ‘Weakening’ as Traders Focus on $1.8K Support

      06/09/2026

      Bitmine’s Ether Holdings Reach 5.54M ETH After Latest Purchase

      06/09/2026

      Will it Push Ether’s Price Lower?

      06/08/2026

      Bitmine Buys $52M ETH, Tom Lee Says Fundamentals Strong

      06/07/2026

      Digital Euro: Aspirations of a Sovereign Alternative to Crypto-Assets

      01/04/2021

      Bug Found in Decoy Algorithm for Privacy Coin Monero

      01/11/2021

      Ethereum Price Structure ‘Weakening’ as Traders Focus on $1.8K Support

      06/09/2026

      XRP May Reach $10 By 2027—But Bearish Conditions Could Push It Below $1, Expert Says

      06/09/2026

      Bitmine’s Ether Holdings Reach 5.54M ETH After Latest Purchase

      06/09/2026

      What’s Going Wrong With XRP? Expert Points To 2 Major Bearish Flips In These Key Metrics

      06/09/2026
    • Markets
    • Events
    Button
    CoinFlashDaily | Crypto Currency News
    Home»News»Ethereum News»Rotten Apples in the Orchard
    Ethereum News

    Rotten Apples in the Orchard

    adminBy admin06/07/2026没有评论5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Subscribe to Bankless or sign in

    It’s been a tough week for Zcash.

    On May 29th, using Opus 4.8, security researcher Taylor Hornby found a critical vulnerability in Orchard, Zcash’s newest and largest shielded pool, while researching the protocol for Shielded Labs, an independent Zcash Zcash The first cryptocurrency to develop zero-knowledge encryption for private peer-to-peer payments. Use Zcash Learn Zcash Current price (USD) $ 0 Outstanding…View Profile” class=”stubHighlight”>Zcash Zcash support organization. He disclosed it privately to Zcash Open Development Lab (ZODL), one of the protocol’s core teams, which confirmed it within hours and started coordinating a response.

    Because too much public detail could’ve handed an attacker the blueprint, the fix came in stages.

    • June 2nd: an emergency soft fork disabled Orchard transactions. 
    • June 3rd: the NU6.2 hard fork re-enabled the pool with a corrected circuit, the rulebook that defines a valid private transaction.

    Simple, done. A serious bug, found and fixed before any known exploit… or so we thought.

    Yesterday, a full post-mortem revealed the vulnerability was a counterfeiting bug that could have allowed someone to mint unlimited fake ZEC inside Orchard and that there was no way to test whether it had been exploited.

    Though the teams still assess prior exploitation as unlikely, this new context twisted the story from “Zcash patched a bug” into “Zcash patched a bug that could have created counterfeit ZEC inside Orchard, with no formal way to prove whether it did.”

    https://t.co/v7BiOdzU9E

    — zooko🛡🦓🦓🦓 ⓩ (@zooko) June 4, 2026

    What Orchard is, And What Broke

    Orchard is Zcash’s newest shielded pool, the private layer where amounts, senders, and recipients stay hidden.

    Like other privacy systems, it runs on zero-knowledge proofs. Users prove a transaction followed the rules without revealing the details, and those rules live in the circuit.

    The bug was in that circuit, had been since Orchard launched in May 2022, and could have allowed anyone to mint counterfeit ZEC inside Orchard that the network would treat as real. And because Orchard hides amounts and ownership, those units could sit in the pool with no obvious public trace.

    In other words, as of now, because Orchard is private, there’s no way to inspect its history and conclusively show no counterfeit ZEC was ever created before the fix.

    The assessment that prior exploitation was “unlikely” holds up for good reason: the flaw was buried, hard to find, and demanded specialized expertise. But the market is pricing proof, not probability. Until Zcash can confirm no counterfeit ZEC was minted, the protocol is effectively asking users to trust what it cannot yet prove.

    Enjoying this article?

    Subscribe to Bankless or sign in

    https://t.co/oRMstGLqp5

    — Zcash Open Development Lab (@zodl_co) June 3, 2026

    So What Happens Next?

    Zcash needs a way to prove no counterfeit ZEC remains inside Orchard, or at least force the books into a state where fake ZEC can’t hide.

    This fix will likely come from two processes: first auditing the supply and then making this class of bug much harder to miss again.

    To address the audit, Zooko, Zcash’s founder, proposed migrating the shielded supply into a new Orchard pool. Turnstile accounting caps how much value can leave a pool at how much legitimately entered it. Force Orchard’s funds through that turnstile and any fake ZEC hits a wall: more value would try to leave than the chain can prove ever entered. A detailed proposal for this path is due next week.

    For the second, Josh Swihart of ZODL is pointing toward formal verification. It means writing down the rules in a machine-checkable form, then proving the circuit actually follows those rules. It doesn’t replace human judgment entirely, but it moves the hardest part from “trust that the auditors caught everything” to “prove the critical constraints are actually there.”

    There are two ways Zcash course-correct. A formally verified version of that same new pool could be the interim step, in principle targeting the NU7 upgrade at the end of July, though nothing’s committed.

    The cleaner long-term answer is Tachyon, a new shielded protocol being designed around simpler foundations and formal-verification tooling. The goal is to cut the hand-coded complexity that made Orchard so hard to reason about, allowing its circuits to be checked far more rigorously. A verified Orchard pool would bridge the gap until Tachyon arrives.

    https://t.co/Q6Y7JjQzb3

    — Josh Swihart 🛡 (@jswihart) June 5, 2026


    Welcome to the era where AI surfaces protocol-breaking bugs. 

    Here’s the prompt that broke Zcash:

    bro basically said “look for bugs that could exploit zcash”

    that’s the prompt that found an exploit in a 10 billion dollar protocol pic.twitter.com/4S7PJ2BeYZ

    — Frank (@frankdegods) June 4, 2026

    While we wait for updates on if any counterfeit ZEC did in fact make it into Orchard, make sure the projects behind your tokens have the kind of relationship with security researchers and engineers that Zcash does. Pray if you want, but verify the process. That relationship is why Zcash may have caught this before an attacker did, as Tayvano notes.

    It may feel like I’m banging your head against a wall, but I’ll say it anyway. We’re standing in a new paradigm with both feet, and it can break protocols securing north of $10 billion.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    The Future of Perps in America

    06/09/2026

    Why Crypto Bled and Bounced

    06/09/2026

    Pump.fun Launches GO, a Bounty Platform for ANY Task

    06/08/2026

    Bitmine Launches $300M Preferred Offering at 9.5%

    06/07/2026
    Add A Comment

    Leave A Reply Cancel Reply

    Top Posts

    Millennials Are Quitting Job to Become Day Traders

    01/20/2021

    Jack Dorsey Says Bitcoin Will Unite The World

    01/15/2021

    Hong Kong Customs Arrest Four in Crypto Laundering Bust

    01/15/2021

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    Bitcoin Reverses 24-Hour Rally as Glassnode Flags 8M BTC at a Loss

    06/09/2026

    Bitcoin investor says he stopped paying taxes to stack more BTC

    06/09/2026

    Kristin Smith pushes Senate to protect crypto developers in CLARITY Act

    06/09/2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook Twitter Instagram Pinterest
    • Home
    • Business
    • Markets
    • News
    • Contact us
    © {2025-2026} Coinflashdaily.com.

    Type above and press Enter to search. Press Esc to cancel.