Zcash Fixes Four-Year-Old Critical Vulnerability in Orchard Shielded Pool After 50% Price Crash
By
James Halver
Toasted to a respectable shade. No regrets, no crumbs left.
Summary
Zcash completed a two-phase emergency network upgrade to fix a critical vulnerability in its Orchard shielded pool that went undetected for four years. The flaw could have theoretically allowed unlimited undetectable counterfeit ZEC creation. The vulnerability disclosure triggered a 50% price collapse in ZEC, but after the fix was confirmed complete by Electric Coin Company CEO Josh Swihart, confidence began restoring and ZEC's price started recovering.
Key quotes
· 1 pulledJosh Swihart, CEO of Electric Coin Company — the primary developer of Zcash — posted on X on June 7 confirming the fix was complete and the network secure, as ZEC began its recovery from the lows reached after the vulnerability disclosure.
You might also wanna read
Proof-of-Concept Exploit Released for Critical NGINX Heap Buffer Overflow (CVE-2026-42945)
A proof-of-concept exploit for CVE-2026-42945, a critical heap buffer overflow vulnerability in NGINX's ngx_http_rewrite_module that has exi

GitHub patches critical remote code execution vulnerability in under six hours after AI-assisted discovery
GitHub patched a critical remote code execution vulnerability in under six hours last month. The flaw, discovered by Wiz Research using AI m
MongoBleed Vulnerability (CVE-2025-14847): Critical MongoDB Security Flaw Explained
MongoBleed (CVE-2025-14847) is a critical security vulnerability affecting MongoDB databases since 2017. The bug exists in the zlib1 message
Security Researcher Discovers Critical Data Vulnerability in Sports Insurer Portal, Faces Legal Threats Instead of Cooperation
A diving instructor and platform engineer discovers a critical security vulnerability in a sports insurer's portal during a dive trip, expos
A critical OpenZFS bug: how a trivial error caused devastating consequences
The article describes a critical bug discovered and fixed in OpenZFS, a popular filesystem. The bug involves a function that converts betwee
Critical LangChain Core Vulnerability (CVE-2025-68664) Allows Serialization Injection Attacks
Cyata Research discloses LangGrinch (CVE-2025-68664), a critical vulnerability in LangChain Core that allows serialization injection attacks
