COINPURO - Crypto Currency Latest News logo COINPURO - Crypto Currency Latest News logo
cryptonews 2026-06-08 11:19:25

Ripple CTO Says Zcash Holders Are Safe, But the Bug That Could Have Created Fake ZEC for 4 Years Cannot Be Disproven

Ripple CTO Emeritus David Schwartz stepped into the Zcash crisis on June 7, offering a measured reassurance to ZEC holders rattled by the disclosure of a critical zero-knowledge proof vulnerability in the Orchard shielded pool. His position: passive holders who never move their coins will not lose their funds, provided the bug was never actually exploited. That condition is doing enormous structural work in a sentence that sounds like comfort. The core paradox is this. The Orchard vulnerability, patched via an emergency NU6.2 hard fork on June 2, theoretically allowed undetected counterfeit ZEC generation for nearly four years. Zcash’s own developers cannot prove the exploit was never triggered, because the privacy architecture that makes ZEC valuable also makes supply auditing cryptographically impossible. Schwartz’s reassurance is accurate on its own terms. It cannot be a guarantee. This one paragraph has massive implications for Zcash. Hardly surprising the price has plummeted. "The vulnerability could have been exploited to undetectably create an unlimited amount of counterfeit zcash:native within Orchard. Because of the privacy properties of Orchard,… https://t.co/72v9Zafneu — Gareth Jenkinson (@gazza_jenks) June 5, 2026 ZEC fell more than 30% in a single session following the May 29 disclosure, briefly touching its lowest level in over a month. The market was not pricing confirmed exploitation; it was pricing unverifiable risk, which is a different and arguably harder problem to resolve. What Schwartz’s statement actually means for holders, and whether it changes anything structurally, is what the rest of this article addresses. Source: Tradingview Discover: The Best Crypto to Diversify Your Portfolio The Orchard Pool Bug: What the Vulnerability Actually Means for ZEC Zcash’s Orchard pool was introduced with Network Upgrade 5 (NU5) in May 2022, the network’s most advanced privacy layer, built on Halo 2-based zk-SNARKs designed to eliminate the trusted setup requirement of earlier Sapling circuits. The vulnerability resided in an under-constrained element within the elliptic-curve multiplication gadget inside the halo2_gadgets crate. In plain terms, crafted inputs could bypass validity checks and produce counterfeit ZEC that still passed verification. Zcash engineer Taylor Hornby discovered the flaw on May 29, 2026, reportedly with the assistance of AI-assisted formal methods. He confirmed a fully working exploit in a local regtest environment, and that running the same exploit on mainnet would have generated unlimited, undetectable real ZEC. The exposure window ran from Orchard’s mainnet activation in May 2022 through June 1, 2026, for approximately 4 years. Affected software included all halo2_gadgets versions before v0.5.0, orchard before v0.14.0, and zcashd versions v5.0.0 through v6.12.3. Straight from Zooko "We want to emphasize that we believe prior exploitation of the Orchard vulnerability is unlikely. But users should not have to trust our assessment, or anyone else’s, when it comes to the integrity of the Zcash supply." MUCH MUCH LOWER https://t.co/tlTRSWY1cH — Roger (@degendeez) June 6, 2026 Shielded Labs and developers responded rapidly, pushing Zebra 4.5.3 as an emergency soft fork to temporarily disable Orchard transactions, then activating the NU6.2 hard fork via Zebra 5.0 at block 3,364,600 on June 2 at 12:05 PM UTC+8. The circuit is now corrected. Here is the part that matters for holders: the patch closes the vulnerability going forward, but cannot retroactively prove supply integrity was maintained during those four years. That window is permanently opaque. Ripple Schwartz’s Reassurance: What It Means and What It Cannot Prove The discussion surfaced after crypto commentator Nate, known on X as @satorinakamoto, challenged whether Zcash could prove the vulnerability had never been triggered, given the network’s opacity. Schwartz, co-creator of the XRP Ledger and one of the more technically credible voices in the industry, responded directly: ‘They’ll eventually be a bit lonely in the deprecated pool, but they’ll still be safe and accessible.’ His broader point: consensus rules protect every ZEC owner, and protocol designers can define backward compatibility so passive holders retain valid, spendable coins even as the Orchard pool becomes a legacy layer. If there was no exploit, everyone is safe whether they move their coins or not. They'll eventually be a bit lonely in the deprecated pool, but they'll still be safe and accessible. — David 'JoelKatz' Schwartz (@JoelKatz) June 7, 2026 The stated reassurance is that holders will not forfeit assets. That is true conditionally; if no exploit occurred, unmoved funds in older pools remain intact. The condition itself, however, is the entire problem. Shielded Labs stated explicitly in its disclosure: ‘There is no definitive way to determine, using only cryptography, whether such exploitation occurred.’ Schwartz’s credentials lend his statement genuine weight. What they cannot lend it is certainty about a four-year window inside a privacy coin’s most opaque layer. This is not a dismissal of Schwartz’s view. His framing, that passive holders are safe absent confirmed exploitation, is technically coherent. The actual framing is that ‘absent confirmed exploitation’ is not a condition anyone can verify, including Zcash’s own developers. Both statements can be simultaneously true. The market is pricing the gap between them. Discover: The Best Token Presales The post Ripple CTO Says Zcash Holders Are Safe, But the Bug That Could Have Created Fake ZEC for 4 Years Cannot Be Disproven appeared first on Cryptonews .

最阅读新闻

coinpuro_earn
阅读免责声明 : 此处提供的所有内容我们的网站,超链接网站,相关应用程序,论坛,博客,社交媒体帐户和其他平台(“网站”)仅供您提供一般信息,从第三方采购。 我们不对与我们的内容有任何形式的保证,包括但不限于准确性和更新性。 我们提供的内容中没有任何内容构成财务建议,法律建议或任何其他形式的建议,以满足您对任何目的的特定依赖。 任何使用或依赖我们的内容完全由您自行承担风险和自由裁量权。 在依赖它们之前,您应该进行自己的研究,审查,分析和验证我们的内容。 交易是一项高风险的活动,可能导致重大损失,因此请在做出任何决定之前咨询您的财务顾问。 我们网站上的任何内容均不构成招揽或要约