NEWS
The Orchard Bug Forced Zcash to Open an Empty Pool
Zcash froze Orchard, patched the circuit in NU6.2, then opened Ironwood at zero so the 21 million cap can be checked at the turnstile.
The Zcash Foundation shipped Zebra 4.5.3 and 5.0.0 in early June 2026 to close a soundness bug in the Orchard privacy circuit. The first release froze Orchard actions. The second, Zebra 5.0.0, turned on NU6.2 with a corrected proving key.
That patch stopped new fake proofs. It did not prove that every old Orchard note was real, which is why the network later opened a pool that started at zero.
The Foundation Froze Orchard for 1,174 Blocks
On Friday, May 29, 2026, Taylor Hornby, an independent researcher on a Shielded Labs protocol audit, found a critical soundness flaw in the Orchard zero-knowledge circuit and told Zcash Open Development Lab engineers that evening. ZODL’s Daira-Emma Hopwood, Kris Nuttycombe, and Jack Grigg confirmed it within hours. Private talks with miners and exchanges started on the evening of Sunday, May 31, while the nature of the flaw stayed off the public patch notes.
The Foundation’s emergency soft fork that disabled Orchard is Zebra 4.5.3. After height 3,363,426 on mainnet, nodes reject any transaction or block that still carries Orchard actions. A first try at height 3,363,366, 60 blocks earlier in zcashd v6.12.4, missed because some mining pools had not upgraded, and the NU6.2 consensus changes in ZIP 257 record that the successful cutover ran through zcashd v6.12.5 and Zebra 4.5.3 instead. The fork held at about 02:00 UTC on June 2, 2026.
A direct circuit patch would have shown too much to anyone who could read the new code, so the first move was simply to turn Orchard off. Sapling and transparent payments kept moving. The Foundation called this the second security-driven protocol upgrade in Zcash history since the 2016 launch.
THE 50-HOUR WINDOW
- May 29, 2026: Hornby discloses the Orchard circuit flaw to ZODL core engineers that evening.
- May 31, 2026: Private coordination with miners and exchanges begins, with the bug still undescribed in public code.
- June 2, 2026: The Orchard-disabling soft fork holds at mainnet height 3,363,426 after the earlier height misses.
- June 3, 2026: NU6.2 activates at 00:05 EDT at height 3,364,600 and Orchard reopens on the corrected circuit.
That gap is 1,174 blocks with the privacy pool switched off. Zebra 5.0.0 and zcashd v6.20.0 then re-enabled Orchard against a new pinned verifying key, because a circuit fix cannot ride in as a quiet software patch. Testnet used disable height 4,048,500 and NU6.2 height 4,052,000 as a scheduled cutover rather than an emergency.
Zebra 4.5.3 and 5.0.0: Emergency Soft Fork and NU6.2 Activation
🚨 Zebra 5.0.0 is out – all node operators should upgrade now.
⚡ NU6.2 activated, re-enabling Orchard with a corrected circuit.
🔒 Total ZEC supply confirmed intact throughout.
Read the full update:…
— Zcash Foundation 🛡️ (@ZcashFoundation) June 3, 2026
A Missing Constraint Let Fake Notes Prove as Real
Soundness, in this setting, means a verifier should accept only a real spend. The hole sat in the halo2_gadgets crate used by Orchard: the incomplete double-and-add loop in the variable-base scalar multiplication gadget kept a per-row base constant and never tied that base to the real point. A prover could run the loop against a free point and still pass, so the diversified-address check could be satisfied for keys that did not belong to the note.
In practice that meant a spend could look valid while minting extra notes inside Orchard, or spending the same note more than once with different nullifiers. Hornby, using Anthropic’s Opus 4.8 after that model landed on May 28, 2026, built a working exploit on a local regtest chain. Shielded Labs said the same tool, pointed at mainnet, would have produced an unlimited amount of counterfeit ZEC in a mainnet wallet, with no obvious on-chain signature, because the private inputs are exactly what the proof hides.
The vulnerability could have been exploited to undetectably create an unlimited amount of counterfeit ZEC within Orchard. Because of the privacy properties of Orchard, there is no way to cryptographically prove whether the vulnerability was exploited before it was remediated.
Zooko Wilcox, Jason McGee, and Taylor Hornby, Shielded Labs, June 4, 2026
The Foundation’s public note used milder language, a double-spend inside Orchard with no path to grow the total coin count. Those two descriptions are not a fight over one number. One is about notes that can exist inside the shielded set. The other is about coins that can leave it.
The bug had been live since NU5 turned Orchard on, on May 31, 2022. Hornby’s work log put the exposure at 4 years, 1 day, and 10 hours. Affected code included all halo2_gadgets releases before v0.5.0, orchard before v0.14.0, zcash_primitives before v0.28.0, zcashd v5.0.0 to v6.12.3, and zebrad releases below v4.5.1. User privacy was not the failure mode. The proofs could lie about value.
Zcash’s Turnstile Caps What a Broken Pool Can Export
Zcash does not keep all value in one bucket. Transparent coins, the old Sprout pool, Sapling, Orchard, and the protocol lockbox each have a running balance, and consensus rejects a block that would pull more out of a pool than ever went in. That rule is the turnstile. It is why a rotten proving circuit is not, by itself, a license to print coins the rest of the chain must honor.
During the June response, operators used that tally as ground truth. The Foundation said the turnstile showed the total supply intact, with no evidence of unauthorized value creation, and that Sapling and transparent traffic never stopped. The earlier Orchard emergency patch was the freeze that bought time for a new verifying key. It was not a statement that every note already in Orchard had a clean history.
Zcash’s turnstile invariant caps the value that can ever leave a shielded pool by the value that entered it. Privacy and verifiability inside the same protocol. That is not an accident. That is good engineering, and it is what kept the worst case bounded.
Charles Guillemet, CTO, Ledger, on X, June 5, 2026
Zcash has walked this path before. A counterfeiting flaw in the original Sprout proving system sat in the protocol until Sapling, and the company disclosed it in February 2019 after the window had already closed. The lesson that stuck was accounting at the pool boundary, not a claim that the next circuit would be perfect. Guillemet also noted that Opus 4.8 catches this class of missing constraint on roughly one in four generic runs, which is another way of saying the cost of finding the next hole just fell.
WHAT WE KNOW
- The exploit: Hornby’s tool minted unbounded fake ZEC inside Orchard on regtest, so the bug was real and usable.
- The freeze: Mainnet rejected Orchard actions from height 3,363,426 until NU6.2 at height 3,364,600.
- The cap: The turnstile still limits what can leave a pool to what went in, which is how the 21 million supply rule is enforced across pools.
WHAT IS UNCONFIRMED
- Mainnet theft: There is no cryptographic test that can show, from the chain alone, whether anyone used the hole before June 1, 2026.
- Trapped fakes: If counterfeit notes exist, they show up only as a shortfall when Orchard is drained, not as a line item today.
Craig Salm, chief legal officer at Grayscale, put the prior-exploit case this way: a thief would have needed to out-read the combined Zcash engineering groups and then declined to empty the pool through the turnstile during a large bull run. Shielded Labs reached a similar view, that prior use “seems unlikely,” and still refused to treat that view as proof. The honest product after June was not a blog line about no known exploit. It was a gate, and then a new empty pool.
Ironwood Opened at Block 3,428,143 With Zero Coins
NU6.2 stopped new fake proofs. Value created under the old verifying key still sat in Orchard. Ironwood, specified as NU6.3, is the answer to that leftover: a fresh shielded pool on the corrected Orchard circuit, sealed off from the old one, so a user who runs a node can independently verify circulating supply without trusting a lab’s hunch.
Ironwood activated at block 3,428,143 on July 28, 2026. From that height, wallets route new shielded payments to Ironwood. Orchard no longer accepts inflows. Coins leave Orchard only through the turnstile, which will not pay out more than the recorded deposits. If fake notes exist, they stay inside the closed pool. Ironwood itself started at zero.
THREE CONSENSUS STEPS
| Step | Software | Mainnet height | What changed |
|---|---|---|---|
| Orchard freeze | Zebra 4.5.3, zcashd v6.12.5 | 3,363,426 | Rejects Orchard actions until the next upgrade |
| NU6.2 | Zebra 5.0.0, zcashd v6.20.0 | 3,364,600 | Reopens Orchard on the fixed circuit and a new verifying key |
| Ironwood (NU6.3) | Zebra with NU6.3 rules | 3,428,143 | Opens an empty pool and makes Orchard withdraw-only |
Migration is voluntary. A wallet that has not added the new path can leave coins sitting in Orchard, spendable only as withdrawals. Pine Analytics, in its Q3 2026 note, said 87% of Orchard balances had moved within five weeks of the July 28 switch, and that Ironwood held 3.84 million ZEC by August 31. Shielded supply in that note was 4.86 million ZEC, or 28.7% of the visible total, after wallets pulled back 440k of the 745k ZEC that had been unshielded in June.
That 3.84 million figure is the new pool on August 31, not the old pool on July 28. The two are different stacks. Ironwood also ships extra review that Orchard never had at launch, including formal verification work and quantum-recoverable note records under ZIP 2005, but the monetary change is simpler than the cryptography: the clean pool begins empty, and the dirty one can only shrink.
ZEC Sold Off on Disclosure, Then Printed $1,298
The Foundation’s June 3 note landed before the full Hornby write-up. Shielded Labs published on June 4, 2026, and the market had to price a four-year window that cannot be audited from the outside. Pine Analytics put ZEC at $407 on June 30, then at $836 on August 31, after Ironwood was live and most Orchard balances had already moved.
OKX’s daily history then shows a September run that the June wire never saw. The Sept 9 session printed a high of $1,298.00. The Sept 11 session opened at $1,168.98 and closed at $1,082.58. Those prints sit on top of the pool migration, and on top of Grayscale’s Zcash product moving from a trust into a listed fund, which Pine put at $155 million in assets on June 30 and $346 million on August 31.
None of that price path proves the old Orchard notes were clean. It prices the response: a freeze, a new key, a one-way gate, and an empty pool. The same sequence is why a later rally should not be read as the June bug having been small. The bug was large inside one pool. The architecture kept it from becoming a 21 million cap break, and the market eventually traded that distinction.
What Node Operators Had to Upgrade Before NU6.2
The Foundation’s line to operators was blunt: move to Zebra 5.0.0 as soon as possible, or to 4.5.3 if 5.0.0 could not land before the NU6.2 height. The Zebra 5.0.0 release notes warn that a node which follows the wrong fork after height 3,364,600 has to sync from scratch, or from a state backup taken before that height. Arya Solhi at the Foundation wrote the Zebra patches that made the cutover possible on that client.
WHO HAD TO MOVE
- Full nodes: Operators on zebrad below v4.5.1, or on zcashd v5.0.0 to v6.12.3, were on affected code until the hotfix and NU6.2 builds.
- Miners: Pools that missed the first freeze height forced a 60-block retry, so hash power that lagged consensus risked mining orphan work.
- Wallets: ZODL shipped new mobile SDKs, because proofs built on the old circuit fail after the verifying key change.
- Exchanges and light servers: Services that still accepted Orchard bundles during the freeze window would have been on the discarded chain.
A later, quieter cut was the planned shift off zcashd toward the Foundation’s Zebra stack, with a July 18, 2026 target for that handoff ahead of Ironwood. Wallet users were told that Orchard funds would need a migrate step and might sit idle until their app supported it. The people with skin in the game were not only holders staring at a chart. They were the operators who had to be on 5.0.0 before height 3,364,600, and later on NU6.3 before height 3,428,143, or they would watch the network go on without them.
Frequently Asked Questions
What Was the Zcash Orchard Soundness Bug?
GitHub logged it as GHSA-ww9q-8r59-xv46 and CVE-2026-54496, a missing copy constraint in halo2_gadgets so the spend check could pass for an arbitrary incoming viewing key. ZIP 257 states the error was in the circuit code only, and that the Action statement in the protocol spec was as intended. Two extra copy constraints and a new verifying key closed it at NU6.2.
Could the Orchard Bug Inflate the Total ZEC Supply?
Not across pools. ZIP 209, deployed May 21, 2019, made turnstile checks a consensus rule, so a block that would drive a pool balance below zero is invalid. Fake notes could exist inside Orchard. They could not be unshielded beyond the ZEC that verifiably entered that pool, which is how the 21 million cap still binds even when one circuit fails.
What Is the Zcash Turnstile?
It is a per-pool running total, updated when a block connects, covering Sprout, Sapling, Orchard, transparent funds, and the lockbox. Nodes already report those balances in ordinary RPC output, so an observer can compare expected inflows with observed outflows without decrypting any shielded memo. Ironwood uses the same gate as the exit from old Orchard.
What Did Zebra 5.0.0 and NU6.2 Change?
They select the FixedPostNu6_2 verifying key for new Orchard proofs, reject proofs that are not the canonical length of 2720 + 2272 bytes times the number of Orchard actions, and advertise network protocol version 170150 with consensus branch ID 0x5437f330. Pre-NU6.2 proofs still verify only under the old insecure key, which is why a hard fork was required.
What Is Ironwood in Zcash?
It is the shielded pool created by NU6.3 at height 3,428,143 on July 28, 2026, documented as ZIP 258. It reuses the patched Orchard protocol with a fresh note commitment tree and nullifier set, starts at zero, and leaves old Orchard withdraw-only so any bogus value cannot keep circulating.
Who Discovered the Orchard Vulnerability?
Taylor Hornby, a former Electric Coin Company security engineer, under a Shielded Labs contract that began in April 2026. He used a custom audit harness with Anthropic’s Opus 4.8, which had been released on May 28, 2026, the day before he reported the flaw at 11:53 p.m. to ZODL.
Orchard can only shrink from here. Ironwood began at zero, and every coin that walks out of the old pool has to fit the recorded deposits. That is the check the June patch could not perform on its own.
Disclaimer: This article is news reporting and analysis of a completed Zcash protocol upgrade and later pool migration. It is informational only and is not investment advice, trading advice, or a recommendation to buy, sell, or hold ZEC or any related fund. Readers should consult a licensed financial adviser or crypto-asset specialist who can review their own situation before making any investment decision. Heights, pool balances, software versions, and prices are taken from the named protocol documents, Foundation and Shielded Labs posts, Pine Analytics, and OKX as of the dates given in the piece, and those figures can change as the chain and the market move.
-
GAMING3 months agoThe $5.99 Game That Won Steam’s 2026 Summer Sale
-
ENTERTAINMENT5 months agoDon Lee Joins Hemsworth as Extraction 3 Starts Shooting
-
NEWS3 months agoYouTube Shorts Retires Dislikes and Swaps Likes for Hearts
-
NEWS3 months agoNEURA Robotics Is Spending Its $1.4B on a Machine Stack
-
AUTO5 months agoKawasaki Bets the New Z1100 Against Its Own Supercharger
-
BUSINESS4 months agoNorway’s Export Bank Backs Nscale’s $790 Million Narvik Loan
-
AUTO5 months agoThe Kawasaki Z1100 Awakens Sugomi With Less Peak Power
-
GAMING3 months agoGame of Thrones Dragonfire Follows Boston’s Conquest Playbook
