Zcash Patches Critical Double-Spend Bug in Orchard Privacy Pool
The Zcash Foundation disclosed a critical vulnerability in the Orchard Action circuit, discovered on May 29 by researcher Taylor Hornby. The flaw could have allowed double spending, but was never exploited. Developers executed a two-stage emergency fix: first a soft fork to halt Orchard transactions, then a full network upgrade (NU6.2) to permanently restore functionality. The total ZEC supply was never at risk, and no unauthorized coins were created. Node operators were urged to upgrade to Zebra 5.0.0. Despite concerns about block explorer downtime, the network continued functioning normally. ZEC price remained unaffected, up over 50% in the last 30 days.
Key facts
- Critical bug in Zcash's Orchard pool could have enabled double spending; no exploitation detected.
- Developers executed a two-stage fix: temporary soft fork then permanent network upgrade NU6.2.
- Zcash's turnstile mechanism confirmed no unauthorized coins were created; supply safe.
- Node operators urged to upgrade to Zebra 5.0.0; network functioned normally despite explorer lag.
- ZEC price unaffected, up over 50% in 30 days and over 1,000% in a year.