Zcash developers have provided new details about how they handled a serious security flaw that could have allowed the creation of unlimited fake ZEC tokens.
Josh Swihart, founder of the Zcash Open Development Lab (ZODL), explained that the team acted quickly after discovering a critical vulnerability in Orchard, the network’s main privacy-focused transaction system.
According to Swihart, the response was carried out in two stages to protect the network while developers worked on a permanent fix.
The first step involved a soft fork that temporarily disabled Orchard transactions. This allowed the team to reduce the risk of exploitation without publicly revealing details that could have helped attackers take advantage of the flaw.
After that, developers launched a second update known as the NU6.2 hard fork on June 3. This upgrade fixed the underlying vulnerability and allowed Orchard transactions to resume safely.
The issue first became public after Shielded Labs revealed that a flaw in the Orchard system could have allowed an attacker to create unlimited counterfeit ZEC tokens without immediate detection.
Although the vulnerability was serious, Shielded Labs stated that it believes the chances of previous exploitation are low. However, the organization also acknowledged that there is no absolute cryptographic proof confirming the bug was never used.
Orchard plays a key role within the Zcash network because it enables private transactions using advanced cryptography that hides transaction details while still validating transfers.
Swihart said the emergency response involved close cooperation with mining pools, cryptocurrency exchanges, and other major ecosystem participants.
Several organizations requested reviews of the emergency code changes before supporting the upgrade. According to Swihart, major mining pools including ViaBTC and Foundry played important roles in helping coordinate the response and verify the fixes before activation.
The incident has also sparked discussions about longer-term improvements to the network.
Developers are considering a recovery proposal known as Ironwood, which would isolate the current Orchard pool, track funds leaving the system, and eventually guide users toward a new privacy pool with stronger safeguards and improved supply verification.
The vulnerability also attracted attention from outside the Zcash community.
Ripple CTO Emeritus David Schwartz addressed concerns about users who may leave funds in older Orchard addresses. He explained that if no exploit occurred before any migration process, users would still retain ownership of their coins because network consensus rules could continue recognizing those balances.
When news of the vulnerability first emerged, the market reacted sharply.
ZEC’s price fell dramatically as investors worried about the possibility that counterfeit coins could have entered circulation. Some prominent figures, including BitMEX co-founder Arthur Hayes, publicly stated that they had sold their ZEC holdings after learning about the issue.
However, investor confidence has gradually improved since the fix was implemented.
After dropping to around $303 on June 5, ZEC has recovered more than 41%, climbing back above $428 as concerns eased and the network returned to normal operations.
Swihart said the incident ultimately demonstrated the network’s ability to respond quickly to serious threats. He added that the vulnerability was successfully fixed, emergency procedures were tested, cooperation among ecosystem partners was strengthened, and developers are now aligned on a path forward to improve the network’s long-term security.







