This is terrible news for any protocol, and I feel for the
$ZEC team given how top notch they are.
But given the complexity of what is being built in this industry, bugs like this are also bound to happen. Even if you audit often, even if you hire good firms, cryptography and blockchain infrastructure are unforgiving.
At
@DuskFoundation we made a conscious decision to spend a large part of the first half of 2026 on hardening and heavily auditing our own network.
Far from sexy and it does not generate headlines. And sadly enough, no matter how big the network upgrade is, this kind of work is often not perceived as "delivering".
But it is exactly the work you want done before privacy blockchain infrastructure is trusted with large amounts of real value.
More broadly, I think the industry needs to spend less time rolling its own cryptography in isolation, and more time standardizing, reviewing and formally verifying the shared primitives we all end up relying on.
In an ideal world, we formally verify as much as possible up and down the stack.
🚨UPDATE: Zcash founder confirms a critical Orchard bug capable of minting unlimited counterfeit zcash:native remained active from May 2022, until it was patched June 1 using Claude Opus 4.8.