On June 8, Zcash disclosed a severe vulnerability in its Orchard shielded pool — a logic flaw in the underlying circuit that could let an attacker mint unlimited fake ZEC. The bug was first identified and reported by ShieldedLabs, an independent technical support organization. Josh Swihart, co-founder of ZODL, detailed the fix process on X, explaining why the team chose a two-phase emergency upgrade instead of a single hard fork.
Phase One: Soft Fork Halts Orchard Transactions
The first phase was a soft fork. Swihart noted that a soft fork does not require all miners and nodes to upgrade immediately, but it can disable Orchard transaction processing at the chain rule level. The vulnerability manifested in two ways: new ZEC could contain an invisible but valid "zero," and change outputs might be slightly less than expected. By pausing Orchard, both potential exploit paths were blocked, giving the team time to verify the fix code thoroughly.
Phase Two: Hard Fork NU6.2 Patches the Root
On June 3, the NU6.2 hard fork activated on mainnet. It directly corrected the computation logic inside the Orchard circuit, restoring every ZEC transaction to the correct verification path. The hard fork also re-enabled Orchard transactions, bringing back normal privacy transfers. Orchard is Zcash's core shielded pool, responsible for verifying the legitimacy of all incoming ZEC — a failure there could have been catastrophic.
ShieldedLabs: Bug Patched, Zero Loss
ShieldedLabs emphasized that the Orchard bug could allow an attacker to create unlimited fake ZEC. However, chain monitoring showed no abnormal minting activity from the time the bug existed until the fix was applied. ShieldedLabs confirmed the vulnerability was never exploited in the wild, and the Zcash network recorded zero losses.
Mining Pools and Exchange Code Reviews
Swihart revealed that ViaBTC and Foundry, two major mining pools, played key roles in coordinating the emergency response. They requested code reviews, and the ZODL team responded to each query to prove the fix's reliability. The collaborative review process built enough trust for the upgrade to proceed quickly without risking a network split or asset freeze.
The incident highlights Zcash's behind-the-scenes quality control: disclose first, patch in stages, then verify with multiple parties — all while keeping the mainnet stable. ZEC price jumped 42% on the news, signaling market relief that the bug was contained.

