Zcash Completes Two-Phase Emergency Upgrade to Fix Infinite Mint Bug, ZEC Rebounds 42%

Zcash Completes Two-Phase Emergency Upgrade to Fix Infinite Mint Bug, ZEC Rebounds 42%

N
News Editor 01
2026-07-24 07:00:16
Zcash rolled out a two-phase emergency upgrade after a critical Orchard vulnerability was disclosed. The bug could have allowed infinite minting of fake ZEC. No funds were lost. ZEC surged 42%.

On June 8, Zcash disclosed a severe vulnerability in its Orchard shielded pool — a logic flaw in the underlying circuit that could let an attacker mint unlimited fake ZEC. The bug was first identified and reported by ShieldedLabs, an independent technical support organization. Josh Swihart, co-founder of ZODL, detailed the fix process on X, explaining why the team chose a two-phase emergency upgrade instead of a single hard fork.

Phase One: Soft Fork Halts Orchard Transactions

The first phase was a soft fork. Swihart noted that a soft fork does not require all miners and nodes to upgrade immediately, but it can disable Orchard transaction processing at the chain rule level. The vulnerability manifested in two ways: new ZEC could contain an invisible but valid "zero," and change outputs might be slightly less than expected. By pausing Orchard, both potential exploit paths were blocked, giving the team time to verify the fix code thoroughly.

Phase Two: Hard Fork NU6.2 Patches the Root

On June 3, the NU6.2 hard fork activated on mainnet. It directly corrected the computation logic inside the Orchard circuit, restoring every ZEC transaction to the correct verification path. The hard fork also re-enabled Orchard transactions, bringing back normal privacy transfers. Orchard is Zcash's core shielded pool, responsible for verifying the legitimacy of all incoming ZEC — a failure there could have been catastrophic.

ShieldedLabs: Bug Patched, Zero Loss

ShieldedLabs emphasized that the Orchard bug could allow an attacker to create unlimited fake ZEC. However, chain monitoring showed no abnormal minting activity from the time the bug existed until the fix was applied. ShieldedLabs confirmed the vulnerability was never exploited in the wild, and the Zcash network recorded zero losses.

Mining Pools and Exchange Code Reviews

Swihart revealed that ViaBTC and Foundry, two major mining pools, played key roles in coordinating the emergency response. They requested code reviews, and the ZODL team responded to each query to prove the fix's reliability. The collaborative review process built enough trust for the upgrade to proceed quickly without risking a network split or asset freeze.

The incident highlights Zcash's behind-the-scenes quality control: disclose first, patch in stages, then verify with multiple parties — all while keeping the mainnet stable. ZEC price jumped 42% on the news, signaling market relief that the bug was contained.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.