Zcash Founder Zooko Discloses Critical Orchard Pool Forgery Flaw
BlockBeats reported on June 5 that Zcash founder Zooko said security researcher Taylor Hornby identified a critical forgery vulnerability in Zcash's Orchard shielded pool on May 29 and reported it to the Zcash Open Development Lab (ZODL). ZODL then coordinated an emergency response across the ecosystem, with a patch completed on June 2.
Shielded Labs said the issue is real and exploitable. In a local test setup, exploit code written by Taylor was able to create unlimited, undetectable forged ZEC. Because of Orchard's privacy design, it is not possible to cryptographically prove whether the bug was exploited before the fix was deployed, though Shielded Labs believes the probability of prior exploitation is low.
Shielded Labs is evaluating a network upgrade proposal that would introduce a new shielded pool and apply turnstile accounting to all tokens originating from the Orchard pool. The aim is to allow anyone to verify the integrity of Zcash's supply and prove that no forged ZEC remains in the Orchard pool.