Zcash was hit by a sharp credibility blow after researcher Taylor Hornby disclosed a critical flaw in the Orchard shielded pool on May 29, 2026. The market reaction was immediate: ZEC fell more than 34% in 24 hours. At the time referenced in the source, the token had dropped from above $600 to $398, with market capitalization at roughly $6.5 billion and trading volume up 44%.
The move stood out even in a weak market. The broader crypto market was down about 2.69% on the same day, while ZEC fell more than ten times as much. That gap points to a project-specific selloff rather than a broad risk-off move.
The flaw was found inside Orchard’s proving circuit
The issue was located in Orchard, the privacy pool that relies on zero-knowledge proofs to conceal transaction details. According to the source material, the bug came from a missing constraint in the elliptic curve multiplication circuit, one of the mathematical components used in the ZK proof system.
The concern was serious. An attacker could theoretically have created counterfeit coins inside the Orchard pool without easy detection. Because Zcash transactions are shielded by design, observers cannot inspect the chain in the same way they would on a transparent ledger to confirm whether fake coins had ever been minted. The flaw had reportedly been present since Orchard launched in 2022, remaining undiscovered for four years.
Hornby reportedly built a working exploit on his own machine to verify the issue and privately reported it the same day. The source says he was working with Shielded Labs and used Anthropic’s Claude Opus 4.8 AI during the discovery process.
Emergency response led to the NU6.2 upgrade
Zcash developers moved within days. First came an emergency soft fork that temporarily disabled Orchard transactions. Then, on June 3, 2026, at around block 3,364,600, the NU6.2 upgrade went live.
The update patched the affected circuit and restored Orchard using a corrected verifying key. Based on the published information, no funds were reported lost and no confirmed exploit was detected. Transactions in the transparent pool and the Sapling pool continued to operate normally throughout the incident.
The unresolved question is whether the flaw was used before the patch
The pressure on ZEC is tied less to the existence of a patch and more to what cannot be proven after the fact. The bug has been fixed, yet the market still lacks a way to demonstrate that it was never exploited before the repair. In a privacy-focused system, that uncertainty carries unusual weight.
The source also states that BitMEX co-founder Arthur Hayes exited his entire ZEC position after concerns around the pool exploit surfaced, saying privacy systems must be fully verifiable. In a market already focused on trust, that kind of move can feed additional selling.
Next proposal would aim to prove no counterfeit ZEC exists in Orchard
Shielded Labs and Zcash co-founder Zooko Wilcox are working on a proposed network upgrade meant to show that no counterfeit ZEC exists in the Orchard pool. The plan described in the source involves launching a new shielded pool and moving existing Orchard coins through an upgraded turnstile accounting system.
That mechanism is already used to protect the total cap of 21 million ZEC from inflation. The proposed change would extend that protection into the private pool itself, allowing supply verification without exposing user privacy. No timeline has been announced for the proposal so far.

