An AI-assisted review uncovered a flaw in Zcash's Orchard pool that could let attackers mint unlimited ZEC, triggering a 50% crash before the token rebounded to $530.
An AI-assisted review uncovered a flaw in Zcash's Orchard pool that could let attackers mint unlimited ZEC, triggering a 50% crash before the token rebounded to $530.

An AI-assisted review uncovered a flaw in Zcash's Orchard pool that could let attackers mint unlimited ZEC, triggering a 50% crash before the token rebounded to $530.
Zcash fell 50% to $250 on June 5 after a critical Orchard pool bug was disclosed, then rebounded to $530 as developers finalized the Ironwood upgrade targeting late July.
"This combination enforces a bound on the circulating supply of ZEC through the use of the existing turnstile mechanism," Sean Bowe, a Zcash developer, said. "The amount of ZEC that anyone can transact with is no more than the amount that is supposed to exist."
The Orchard pool, introduced in May 2022 as part of the NU5 upgrade, was the first shielded environment using Halo 2 zero-knowledge proofs without a trusted setup. An AI-assisted security review by external researchers surfaced the flaw in early 2026, leading to a quiet patch before Ironwood was formally proposed. The upgrade was jointly developed by ZODL, Tachyon, Valar Group, the Zcash Foundation, and Shielded Labs. It introduces a redesigned Orchard circuit with a flag that disables payments to other users within the compromised pool while preserving the ability to generate change notes. The turnstile mechanism ensures that every ZEC exiting the old pool must pass through supply verification before entering the new pool.
The activation target at block height 3,417,100 coincides with zcashd end-of-support. Testnet trials, ecosystem coordination, and final security audits remain outstanding before mainnet activation. Wallet providers supporting Orchard are expected to offer one-click migration tooling, and the new pool preserves existing Orchard addresses, avoiding disruptive key rotation for active users.
$21M in shorts liquidated as ZEC doubles from crash low
The token's recovery from $250 to $530 was partly mechanical. Data from CoinGlass shows approximately $21 million in ZEC short positions were liquidated over two days, amplifying the rally as traders rushed to cover. Trading volumes nearly doubled to around $1 billion, representing roughly 10% of Zcash's circulating market capitalization. The Relative Strength Index climbed to 77, indicating overbought conditions.
Despite the price recovery, on-chain data reveals caution among some holders. Nearly 800,000 ZEC tokens — worth roughly $400 million at current prices — have been withdrawn from the Orchard pool since the disclosure, one of the largest outflows on record for the shielded pool.
Anthropic audit finds no additional bugs
Anthropic's Mythos audit of Zcash's codebase found no serious bugs, strengthening confidence after the Orchard scare, according to a report published this week. The independent third-party review covered the redesigned Orchard circuit and associated zero-knowledge proof circuits, all of which passed formal verification.
ZEC faces resistance at $550, with support at $416, according to technical analysis. A confirmed failure to hold above $500 could trigger a retest of the $300 area. The Ironwood upgrade is expected to activate on mainnet in late July, pending testnet trials and final security audits.
This article is for informational purposes only and does not constitute investment advice.