
Zcash founder Josh Swihart has detailed the emergency network upgrades deployed to fix a critical Orchard vulnerability that could have enabled unlimited counterfeit ZEC creation. As reported by ZODL founder Swihart on X, the team deployed a two-stage network upgrade after discovering the flaw in Zcash's Orchard shielded pool, the network's primary privacy-focused transaction system. The first step involved a soft fork that disabled Orchard transactions while allowing developers to reduce exploitation risk without publicly revealing details that could expose the network to further threats. A second upgrade, the NU6.2 hard fork, went live on June 3 and addressed the underlying vulnerability before Orchard transactions were restored. Mining pools and exchanges reviewed the emergency code changes, with ViaBTC and Foundry helping coordinate the response and verifying the emergency changes before activation.
Ripple CTO emeritus David Schwartz has entered the Zcash Orchard debate to address concerns about coins left in old Orchard addresses. As reported by multiple sources, Schwartz said users who do not move funds would not lose ownership if no exploit occurred. His explanation focused on consensus rules that decide which coins remain valid and who can spend them, emphasizing that migration does not need to punish passive holders because the network can still preserve ownership. Schwartz's broader point: consensus rules protect every ZEC owner, and protocol designers can define backward compatibility so passive holders retain valid, spendable coins even as the Orchard pool becomes a legacy layer. This development provides crucial clarity for users who may have missed the migration process or chose not to move their funds.
Shielded Labs and other Zcash contributors are developing a comprehensive recovery plan called Ironwood to address the Orchard crisis. As reported by multiple sources, the plan would isolate Orchard and limit new outgoing activity from the old pool, while using turnstile accounting to track coins that leave Orchard. A new shielded pool would then support safer private activity, allowing users to move funds into a cleaner environment while keeping stronger checks on supply. The goal is to rebuild confidence without forcing a careless wipeout of older balances, with the plan still needing community review and network support before activation. Zcash Open Development Lab founder Josh Swihart has indicated that a second Orchard-style pool could be considered for the NU7 upgrade window around late July.
ZEC has recovered more than 41% from its post-disclosure low after the vulnerability was patched and Orchard transactions were restored. As reported by crypto.news data cited by Swihart, ZEC rose 13.5% over the past 24 hours to $428.67, representing a recovery of about 41.5% from the June 5 low near $303. The market reaction was immediate when ZEC fell more than 30% in a single session following the May 29 disclosure, briefly touching its lowest level in over a month. The market was not pricing confirmed exploitation; it was pricing unverifiable risk, which is a different and arguably harder problem to resolve. BitMEX co-founder Arthur Hayes said he had exited his entire ZEC position after learning of the vulnerability, highlighting the severity of the crisis for high-profile investors.
Taylor Hornby, the security researcher who used Anthropic's Opus 4.8 AI model to discover the critical Orchard bug in Zcash, has announced plans to expand his AI-assisted audit work to other privacy-focused cryptocurrencies. As reported by CoinDesk, when asked on X whether he could look for flaws in Monero and other private cryptocurrencies, Hornby replied, 'Absolutely! I'll add Monero to my queue of things to audit.' Monero, which trades under the ticker XMR, is among the largest privacy-focused cryptocurrencies and hides transaction details by default compared to Zcash, where users can choose either transparent or shielded addresses. Hornby plans to apply for a Zcash coinholder grant to fund further work on his AI-assisted auditing approach, which he developed specifically for protocol review.