
265,000 ZEC Withdrawn From Exchange; AI Discovers Critical Zcash Counterfeit-Minting Bug
Zcash is navigating a critical counterfeiting vulnerability disclosure while advancing its Ironwood upgrade, driving ZEC price momentum and regulatory scrutiny.
An entity withdrew 265,000 ZEC tokens (approximately $107 million) from an exchange within two days. Separately, an AI system identified a critical bug in Zcash that could have enabled unlimited counterfeit minting, threatening the integrity of the protocol.
Zcash Bug: the flaw that shielded pools couldn't hide
A soundness bug hiding in Zcash's Orchard shielded pool since 2022 meant someone could theoretically forge zero-knowledge proofs and mint unlimited ZEC from nothing — and the network would have accepted every fake transaction as genuine.
A security engineer found it with $200 of AI compute. Four years of silent exposure, caught by a tool that barely existed when the bug was introduced.
Here's the uncomfortable cut: the very privacy architecture that makes Zcash meaningful is also what makes a bug like this so hard to catch. Shielded pools hide balances by design. That same opacity means counterfeit supply could have grown invisibly. You can't have one without the other.
Developers patched it in five days, which is genuinely impressive. But "no evidence of exploitation" is a much weaker statement when the whole point of the system is that transactions are unobservable. The contrarian case for privacy coins rests on them actually working. This time they got lucky.
Related storylines
- Zcash Counterfeiting Bug Hidden Four YearsZcash critical bug discovery and details
- Zcash Ironwood Upgrade AdvancesZcash protocol security and upgrades