Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Zcash Fixes Critical Vulnerability As ZEC Holds $600 Support

Zcash Fixes Critical Vulnerability As ZEC Holds $600 Support

NewsbtcNewsbtc2026/06/04 07:03
By:Newsbtc

Zcash has patched a dangerous vulnerability in its privacy-focused infrastructure that could have enabled double-spending, deploying an emergency network upgrade to prevent exploitation.

Zcash Fixes Critical Bug With Emergency Upgrade

On Wednesday, the Zcash Foundation revealed that developers had fixed a serious vulnerability in its Orchard shielded pool, which could have allowed invalid state transitions, potentially enabling double-spending within the pool.

According to the report, Zcash researcher Taylor Hornby, who is conducting an ongoing protocol audit on behalf of Shielded Labs, discovered a critical soundness vulnerability in the Orchard zero-knowledge proof circuit on May 29 and disclosed the issue to Zcash Open Development Lab (ZODL) core engineers that same day.

var rnd = window.rnd || Math.floor(Math.random()*10e6); var pid607465 = window.pid607465 || rnd; var plc607465 = window.plc607465 || 0; var abkw = window.abkw || ''; var absrc = 'https://servedbyadbutler.com/adserve/;ID=172179;size=0x0;setID=607465;type=js;sw='+screen.width+';sh='+screen.height+';spr='+window.devicePixelRatio+';kw='+abkw+';pid='+pid607465+';place='+(plc607465++)+';rnd='+rnd+';click=CLICK_MACRO_PLACEHOLDER'; document.write('
');
if (!window.AdButler){(function(){var s = document.createElement("script"); s.async = true; s.type = "text/javascript";s.src = "https://servedbyadbutler.com/app.js";var n = document.getElementsByTagName("script")[0]; n.parentNode.insertBefore(s, n);}());}
var AdButler = AdButler || {}; AdButler.ads = AdButler.ads || []; var abkw = window.abkw || ""; var plc366606 = window.plc366606 || 0; (function(){ var divs = document.querySelectorAll(".plc366606:not([id])"); var div = divs[divs.length-1]; div.id = "placement_366606_"+plc366606; AdButler.ads.push({handler: function(opt){ AdButler.register(172179, 366606, [728,90], "placement_366606_"+opt.place, opt); }, opt: { place: plc366606++, keywords: abkw, domain: "servedbyadbutler.com", click:"CLICK_MACRO_PLACEHOLDER" }}); })();

“A soundness vulnerability is one that could allow the system to accept something it should reject. In this case, successful exploitation could have allowed the Orchard pool to accept invalid state transitions, potentially permitting double-spending of funds within Orchard, though with no ability to inflate the total ZEC supply, which is protected by Zcash’s turnstile mechanism,” the foundation explained.

After identifying the vulnerability, Zcash developers, miners, and infrastructure operators coordinated privately to prepare a fix, keeping details confidential to avoid potential exploits.

The first soft fork attempt faced technical challenges, but engineers quickly released a revised patch that successfully activated on June 2, temporarily disabling Orchard-related transactions. On June 3, the network completed a full hard fork upgrade, NU6.2, restoring Orchard functionality with the corrected code and permanently resolving the vulnerability.

var rnd = window.rnd || Math.floor(Math.random()*10e6); var pid607472 = window.pid607472 || rnd; var plc607472 = window.plc607472 || 0; var abkw = window.abkw || ''; var absrc = 'https://servedbyadbutler.com/adserve/;ID=172179;size=0x0;setID=607472;type=js;sw='+screen.width+';sh='+screen.height+';spr='+window.devicePixelRatio+';kw='+abkw+';pid='+pid607472+';place='+(plc607472++)+';rnd='+rnd+';click=CLICK_MACRO_PLACEHOLDER'; document.write('
');
if (!window.AdButler){(function(){var s = document.createElement("script"); s.async = true; s.type = "text/javascript";s.src = "https://servedbyadbutler.com/app.js";var n = document.getElementsByTagName("script")[0]; n.parentNode.insertBefore(s, n);}());}
var AdButler = AdButler || {}; AdButler.ads = AdButler.ads || []; var abkw = window.abkw || ""; var plc452518 = window.plc452518 || 0; (function(){ var divs = document.querySelectorAll(".plc452518:not([id])"); var div = divs[divs.length-1]; div.id = "placement_452518_"+plc452518; AdButler.ads.push({handler: function(opt){ AdButler.register(172179, 452518, [728,90], "placement_452518_"+opt.place, opt); }, opt: { place: plc452518++, keywords: abkw, domain: "servedbyadbutler.com", click:"CLICK_MACRO_PLACEHOLDER" }}); })();

The Foundation said there was no evidence that the bug was exploited, as no unauthorized value creation was detected. In addition, they affirmed that the total ZEC supply remains safe and the issue did not affect the privacy of funds held in any Zcash pool.

ZEC Holds Key Support Amid Network Confusion

Following the upgrade, news that the network was offline circulated on social media, creating confusion among community members. Some reports claimed that Zcash had failed to produce blocks for over four hours.

However, Mert Mumtaz, CEO of Solana infrastructure firm Helius, dismissed these reports, affirming that the network was never down and that explorer apps were connected to a bad node.

var rnd = window.rnd || Math.floor(Math.random()*10e6); var pid607473 = window.pid607473 || rnd; var plc607473 = window.plc607473 || 0; var abkw = window.abkw || ''; var absrc = 'https://servedbyadbutler.com/adserve/;ID=172179;size=0x0;setID=607473;type=js;sw='+screen.width+';sh='+screen.height+';spr='+window.devicePixelRatio+';kw='+abkw+';pid='+pid607473+';place='+(plc607473++)+';rnd='+rnd+';click=CLICK_MACRO_PLACEHOLDER'; document.write('
');
if (!window.AdButler){(function(){var s = document.createElement("script"); s.async = true; s.type = "text/javascript";s.src = 'https://servedbyadbutler.com/app.js';var n = document.getElementsByTagName("script")[0]; n.parentNode.insertBefore(s, n);}());}
var AdButler = AdButler || {}; AdButler.ads = AdButler.ads || []; var abkw = window.abkw || ''; var plc452519 = window.plc452519 || 0; (function(){ var divs = document.querySelectorAll(".plc452519:not([id])"); var div = divs[divs.length-1]; div.id = "placement_452519_"+plc452519; AdButler.ads.push({handler: function(opt){ AdButler.register(172179, 452519, [728,90], 'placement_452519_'+opt.place, opt); }, opt: { place: plc452519++, keywords: abkw, domain: 'servedbyadbutler.com', click:'CLICK_MACRO_PLACEHOLDER' }}); })();

In a series of X posts, Zcash blockchain explorer CipherScan confirmed the issue, explaining that its nodes were upgrading to support the recent NU6.2 network upgrade.

“What actually happened: Zcash pushed a coordinated network upgrade (NU6.2) that required all node operators to update. During that transition, some block explorers, including ours, showed stale or missing data while we upgraded,” the post stated.

“That’s the explorer being out of sync, not the blockchain being broken. Important distinction. (…) Block explorers are just readers. They pull data from a node, parse it, and display it. If the node is upgrading or resyncing, the explorer goes stale,” the explorer continued.

Despite the confusion, ZEC’s price continued to defy the broader market trend, rallying over 8% intraday to retest the $636 around on Wednesday morning. Notably, the cryptocurrency has soared roughly 20% over the past two days while most of the market bled.

After failing to reclaim the $630 local resistance, the cryptocurrency dropped toward the $600 support, briefly falling below it before bouncing again. As of this writing, Zcash trades at $612, a 9.5% increase in the weekly timeframe.

Zcash Fixes Critical Vulnerability As ZEC Holds $600 Support image 2 ZEC’s performance in the one-week chart. Source: ZECUSDT on
0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!