AI Audit Finds Zcash Orchard Bug; THORChain Integration Delayed

By Bartek

08 Jun 2026 (about 1 month ago)

4 min read

Share:

Zcash security researcher Taylor Hornby discovered a critical four-year-old vulnerability in the Orchard shielded pool on May 29 using an AI-assisted audit; an emergency hard fork (NU6.2) fixed it by June 3. THORChain, still offline following a separate $10.7M exploit, had planned ZEC as its next chain integration.

AI Audit Finds Zcash Orchard Bug; THORChain Integration Delayed

Key facts

  • Researcher Taylor Hornby used an AI-assisted audit to find a four-year-old soundness bug in Zcash's Orchard circuit on May 29; NU6.2 hard fork fixed it by June 3.
  • The bug could have permitted unlimited undetectable counterfeit ZEC creation; no exploitation was detected and the supply cap remained intact.
  • THORChain remained offline approximately three weeks after a separate $10.7M exploit, with ZEC planned as its next chain integration before the Zcash vulnerability emerged.

THORChain remains offline three weeks after a $10.7M vault exploit

According to MEXC News reporting from 5 June 2026, THORChain has remained offline since approximately 15 May 2026, following a $10.7 million exploit targeting a GG20 threshold-signature scheme used by one of its vaults. An attacker joined the network as a node operator and drained a single vault; four other vaults were not affected. The THORChain community approved recovery plan ADR028 on 29 May, and developers released version 3.19 with a corrected GG20 implementation and an additional key-verify safety step. According to the same reporting, the restart process — covering node software upgrades, fund migration, and trading resumption — was expected to require several more days as of 5 June.

AI-assisted audit exposes four-year-old soundness bug in Zcash's Orchard circuit

On 29 May 2026, Taylor Hornby, an independent security researcher contracted by Shielded Labs, discovered a critical vulnerability in Zcash's Orchard zero-knowledge proof circuit. Hornby was conducting an ongoing protocol audit and used Anthropic's Claude Opus 4.8 — released the day before, on 28 May — as part of a targeted review of the Orchard implementation. Within hours of disclosure to ZODL (Zcash Open Development Lab) engineers, the team confirmed the issue and began developing a coordinated fix. The vulnerability had been present in the Orchard codebase since Orchard's activation in May 2022, approximately four years without prior detection.

The vulnerability could have permitted unlimited counterfeit ZEC within Orchard

The flaw was a soundness vulnerability in the implementation of the Orchard zero-knowledge proof circuit in the halo2_gadgets crate. In a zero-knowledge system, soundness ensures that only valid transactions are accepted. This bug allowed a prover to supply false inputs to an elliptic curve multiplication step while still passing the circuit's consistency check. According to Shielded Labs, successful exploitation could have generated unlimited, undetectable counterfeit ZEC within the Orchard pool. The Zcash Foundation noted that no evidence of exploitation was found and that the total 21 million ZEC supply cap remained intact throughout, protected by Zcash's turnstile mechanism.

Orchard disabled June 2 via soft fork; NU6.2 hard fork restores it June 3

ZODL engineers coordinated privately with miners and exchanges beginning the evening of 31 May. A first soft-fork activation attempt encountered deployment challenges; engineers produced a second patch targeting block height 3,363,426, which activated at approximately 02:00 UTC on 2 June. This soft fork, implemented via Zebra 4.5.3, rejected all Orchard-containing transactions as a precautionary measure while the circuit fix was finalised. On 3 June at 00:05 EDT, the NU6.2 hard fork activated at block height 3,364,600, re-enabling Orchard with a corrected zero-knowledge proof circuit. The Zcash Foundation confirmed this was the second security-driven protocol upgrade in Zcash's history since the network launched in 2016.

ZEC falls 31 percent and RUNE drops 21 percent in the seven days after disclosure

ZEC traded at $364.97 as of 5 June 2026, down 31.27 percent over the preceding seven days (CoinPaprika, 05 June 2026). THORChain's native token RUNE traded at $0.3297, down 21.36 percent over the same period (CoinPaprika, 05 June 2026). Transparent ZEC transactions continued without interruption during the Orchard disable window on 2–3 June; the Zcash network itself was not halted. No exploitation of the Orchard vulnerability has been confirmed.

THORChain's planned ZEC integration is on hold until restart completes

According to MEXC News, THORChain had positioned Zcash as its next planned chain integration, scheduled ahead of Monero. The emergency Zcash network upgrades during 2–3 June added a further delay to that timeline. THORChain has not publicly confirmed a restart date as of 5 June 2026. The Zcash Foundation announced plans to formally verify the Orchard circuit following the incident and is exploring a new shielded pool with turnstile accounting to allow independent verification of the ZEC supply.

Primary source: Source ↗

Cryptocurrencies are highly volatile and involve significant risk. You may lose part or all of your investment.

All information on Coinpaprika is provided for informational purposes only and does not constitute financial or investment advice. Always conduct your own research (DYOR) and consult a qualified financial advisor before making investment decisions.

Coinpaprika is not liable for any losses resulting from the use of this information.

Share:
Go back to All News