
Zcash has successfully completed a follow-up security audit using Anthropic's Mythos system, which found no additional serious vulnerabilities in the protocol following the recent Orchard flaw disclosure. According to founder Zooko Wilcox, the audit was conducted at the request of Shielded Labs after the discovery of a vulnerability that could theoretically have allowed unlimited creation of counterfeit ZEC. In a June 13 post on X, Wilcox thanked Anthropic for helping protect Zcash users and confirmed that the review did not identify any other serious bugs in the network. The audit results come less than a week after the Zcash ecosystem rushed to contain a flaw in Orchard, the blockchain's primary shielded transaction pool, with the defect potentially enabling an attacker to create unlimited counterfeit ZEC.
The audit results come less than a week after the Zcash ecosystem rushed to contain a flaw in Orchard, the blockchain's primary shielded transaction pool. According to Shielded Labs, the defect could theoretically have enabled an attacker to create an unlimited amount of counterfeit ZEC, though previous exploitation appeared unlikely. Security researcher Taylor Hornby found the critical vulnerability on May 29 during an AI-assisted audit using Anthropic's Opus 4.8 system. Work on fixing the issue began before the flaw became public, with developers first deploying a soft fork that temporarily disabled Orchard transactions while technical details remained confidential. A second upgrade, the NU6.2 hard fork, went live on June 3 and restored Orchard with a corrected circuit and new verifying key, while Sapling and transparent transactions operated normally throughout. The vulnerability remained undetected for approximately four years before researchers identified it on May 29, 2026, highlighting the challenges in privacy-preserving systems where shielded transactions intentionally hide transaction details.
Following the fix, teams across the Zcash ecosystem continued reviewing the protocol for additional risks, with Shielded Labs and other contributors now focused on further security-hardening measures. According to Wilcox's June 13 update, several organizations remain involved in the effort, including the Zcash Foundation, Tachyon Group, Valar Group, Shielded Labs, and Zcash Open Development Lab. The disclosure noted that Orchard's privacy properties mean the network cannot cryptographically prove the flaw was never exploited before the fix, though the Zcash Foundation confirmed there was no evidence of unauthorized value creation and that the turnstile mechanism confirmed total supply remained intact. The incident exposed unique challenges in privacy-preserving systems, where researchers could not conclusively prove that nobody had exploited the flaw before discovery, forcing the network to rely on available evidence, forensic analysis, and the absence of observable anomalies rather than definitive proof of non-exploitation.
The Orchard disclosure triggered a sharp sell-off in ZEC, with the token falling from around $558 to $264 before stabilizing near $320, according to crypto derivatives analytics firm Block Scholes. This represents a roughly 50% single-day drop that occurred between June 4 and June 5 before rebounding to $478.70 on June 9. ZEC has since fallen back to around $417 as investors reduced exposure to risk assets amid escalating tensions between the United States and Iran. Technical indicators show that the post-crash recovery is facing resistance, with ZEC falling below the 38.2% Fibonacci retracement level at $418.60 after failing to hold gains near $478.70. The token remains below the Supertrend resistance at roughly $465, which continues to cap upside attempts. The incident demonstrates how zero-knowledge systems place more trust in the correctness of cryptographic circuits and verification logic, making audits, formal verification, and peer review even more critical than traditional blockchain trust models.