Grayscale Chief Legal Officer Craig Salm said on June 5 in a post on X that Zcash’s Orchard pool bug is unlikely to be exploited before it is fixed. He argued that anyone claiming the issue would be abused prior to remediation must assume two conditions are both true, and he does not see that as a likely outcome.
Two conditions he says must both hold
Salm said the first condition is that someone studied the Zcash codebase more deeply than the project’s core developers. He referred to teams tied to the ecosystem, including Electric Coin Company, Zcash Open Development Lab, Shielded Labs, and the Zcash Foundation. The second condition is that whoever found the issue resisted the incentive to drain the Orchard pool and sell fake ZEC during what he described as a historic bull market of more than 20x.
His conclusion was blunt: “In my view, that is unlikely.”
Top-tier security reputation cited
Salm also said Zcash’s development and security community ranks among the best in the industry. He pointed to the protocol’s work on artificial intelligence-related risk, saying Zcash is ahead of other protocols on that front. In his view, the speed of model improvement means AI risk will eventually affect every protocol, while Zcash developers have already moved early and others are still catching up.
Possible upgrade path mentioned
He also raised a possible future network upgrade that would allow anyone to verify the integrity of Zcash supply and prove that no fake Zcash exists in the Orchard pool. That, he said, would be an even better outcome.
His comments came as the market continued to focus on the Zcash vulnerability. The source article said the remarks also served as a public vote of confidence in the Zcash development team and helped ease tension after Arthur Hayes’ sale of ZEC drew market attention.

