

Zcash fell sharply after Shielded Labs disclosed a critical vulnerability in the Orchard privacy pool. The issue could have allowed counterfeit ZEC creation without detection, and the token slid as low as $442.6 before trading near $458 at press time.
The decline accelerated after market participants reacted to the disclosure, which also prompted fresh security concerns around Zcash’s supply integrity. CoinGecko data showed steep losses across one day, one week, and two weeks.
The token’s trading volume also rose as investors reassessed the risk. Daily spot volume climbed past $1.7 billion, while the market struggled with uncertainty over whether the flaw had ever been exploited.
Shielded Labs said security engineer Taylor Hornby found the vulnerability on May 29. The nonprofit said it hired him in April 2026 to search for protocol weaknesses before attackers could find them.
Hornby worked with Anthropic’s Opus 4.8 AI model during a focused review of the Orchard circuit. Shielded Labs said the flaw sat inside the cryptographic system behind Zcash’s most advanced privacy pool.
The organization said the weakness could have let an attacker create unlimited fake ZEC in Orchard without immediate detection. It later said Hornby wrote a full exploit that worked in a local testing environment.
Developers moved quickly after the discovery. Shielded Labs said Hornby reported the issue to the Zcash Open Development Lab, which coordinated an emergency fix on June 1. The team said the bug existed since Orchard launched in May 2022. That timeline means the flaw remained hidden for about four years before anyone found it. What mattered most to markets was the uncertainty. Shielded Labs said no cryptographic method could prove whether someone had used the bug before the fix.
Read More: Bitcoin Outflows, ZCash DSurged Over 13%, and TesserDAO Suffers Exploit
Arthur Hayes reacted sharply to the disclosure. He said, ‘The Holy Trinity is dead,’ and confirmed that he had sold his entire ZEC holding. Hayes said the risk mattered as privacy assets require strict confidence in supply integrity. He also wrote that “perfection” matters more than mere probability for privacy-focused systems.
Shielded Labs said the issue was fixed, but it also warned users not to rely only on its assessment. Instead, it proposed a network upgrade with a new shielded pool and turnstile accounting for Orchard coins.
The group also said it would continue to work with Hornby, push formal verification for the Orchard circuit, and hire a Head of Security and a cryptographer.
Zcash fell sharply after Shielded Labs disclosed a critical Orchard privacy pool vulnerability that could have enabled counterfeit ZEC creation. Although developers fixed the flaw quickly, uncertainty over possible past use continued to shake confidence. The episode shows how supply integrity and rapid disclosure remain vital in privacy-focused crypto.