Zcash discloses a flaw, first discovered in-house last March and fixed in October, that may have allowed “infinite” counterfeiting
http://bitsonline.com/ ... via @wpeaster @whalepanda : People should stick to their field of expertise. US based centralized altcoin with optional privacy what 97% of the people don't use and that has been consistently losing value in the last 2 years with potentially compromised key ceremony. http://twitter.com/... Jessy Irwin / @jessysaurusrex : This is an exceptional example of using internal resources to find serious bugs and coordinating vulnerability disclosure, aka #vulnlifegoals. Great work, @zcashco, @zooko et al: Zcash Counterfeiting Vulnerability Successfully Remediated http://z.cash/... Tony Arcieri / @bascule : Challenge to all zero-knowledge cryptocurrencies: always be able to prove the total size of the money supply in zero knowledge http://twitter.com/... Rocco / @obstropolos : “This vulnerability is so subtle that it evaded years of analysis by expert cryptographers focused on zero-knowledge proving systems and zk-SNARKs.” Wild. Kudos to @zcashco @zooko and all involved for the control and removal of this vulnerability. http://z.cash/... Peter Todd / @peterktodd : (fixed) Zcash counterfeiting vulnerability: http://z.cash/... “This vulnerability is so subtle that it evaded years of analysis by expert cryptographers focused on zero-knowledge proving systems” Reality is bleeding edge crypto is risky; second inflation bug they've had. Robert Hackett / @rhhackett : Big: Zcash discloses vulnerability that could have allowed “infinite counterfeit” cryptocurrency. Some projects appear still to be vulnerable. http://fortune.com/...
Context & Ripple Effects
Zcash has staked its entire value proposition on zero-knowledge proofs since its 2016 launch on the Zerocash protocol — which means the soundness of those proofs is not one feature among many but the whole ballgame. The newly disclosed flaw, found internally last March and patched by October, sat squarely in that core: it could have permitted 'infinite' counterfeiting of ZEC, undetectable by design because shielded transactions hide the very data an auditor would check.
The disclosure lands in a familiar arc. It echoes Cory Fields' responsible disclosure of a chain-splitting bug in Bitcoin Cash as another case of a critical flaw caught and fixed before exploitation, and it prefigures the far more damaging 2022 Orchard shielded-pool vulnerability Zcash disclosed years later — a reminder that counterfeiting-class bugs in proof systems are a recurring failure mode, not a one-off.
First-order effects
- ZEC holders and exchanges must reassess whether past Zcash issuance can be trusted as fully sound — the fix prevents future exploitation, but the episode puts the project's audit depth under immediate scrutiny.
- Zcash's coordinated-disclosure handling earns public praise from security figures like Jessy Irwin, turning the incident into a partial credibility win for the team's internal review process even as the underlying flaw dents confidence in zk-SNARK soundness.
Second-order effects
- Rival privacy coins face the same question by association: if Zcash's heavily reviewed proofs harbored an 'infinite' inflation bug, every shielded-pool design becomes suspect to exchanges and institutional counterparties weighing listing risk.
- External auditors and independent cryptographers gain leverage — projects whose proof systems resist casual verification will be pushed to fund third-party review, since in-house discovery alone no longer reads as sufficient assurance.
Third-order effects
- If the pattern holds across Zcash's own history — this flaw, then the Orchard pool bug — the structural lesson is that privacy-preserving ledgers concentrate catastrophic single-point-of-failure risk inside their cryptography, favoring designs with formal verification and external verifiability over opaque trusted setups.
- Regulators and custodians already wary of optional-privacy assets gain a concrete argument: a currency whose supply integrity depends on unexploited-but-plausible proof bugs is harder to treat as a settlement-grade asset than transparent chains where double-spends are publicly checkable.
The trend: Privacy cryptocurrencies keep discovering counterfeiting-class vulnerabilities in their zero-knowledge proof systems, making internal audit capacity and disclosure discipline the real competitive differentiator in shielded-payment design.