ZEC drops 30% as Shielded Labs reveals more about infinite counterfeit bug
Crypto · · 1 min read · cointelegraph.com ↗
ZEC drops 30% as Shielded Labs reveals more about infinite counterfeit bug
ZEC fell on Thursday after further details were disclosed of a critical counterfeiting vulnerability in Zcash's Orchard pool that could theoretically allow a bad actor to mint an unlimited amount of ZEC.
Security engineer Taylor Hornby, engaged by Shielded Labs, discovered the bug on May 29 and disclosed it to the Zcash Open Development Lab (ZODL), which deployed an emergency response to fix the vulnerability with a hard fork activated on June 3.
However, new concerns about the extent to which the vulnerability has been used since May 2022 led Zcash to fall more than 30% over 24 hours to $410. Its market capitalization shrunk by more than $3 billion.
BitMEX co-founder Arthur Hayes said it is unlikely ZEC has been illegally minted, though "it cannot be formally cryptographically proved impossible." He added: "Sadly, due to the Orchard Pool exploit, I had to dump our entire ZEC bag."
Taylor used Claude Opus 4.8 to assist in a targeted review of the Orchard circuit — the cryptographic component underlying Zcash's shielded pool. The critical bug allowed false inputs into an elliptic curve multiplication check. He built and tested a working exploit that generated unlimited counterfeit ZEC.
Shielded Labs said they are "not overly concerned" because the bug was subtle enough to evade years of expert review. The firm is working with Zcash developers on a proposed network upgrade to verify the integrity of the ZEC supply.
Mert Mumtaz at Helius said almost all privacy protocols have a variant of this same vulnerability, noting it's a theoretical risk in most zero-knowledge privacy protocols from circuit bugs that are hard to exploit or detect. This is not the first time — a similar Zcash counterfeiting vulnerability was discovered in 2018 and remediated with no losses in 2019.