AI Audit Finds Zcash Orchard Bug; THORChain Integration Delayed
Zcash security researcher Taylor Hornby discovered a critical four-year-old vulnerability in the Orchard shielded pool on May 29 using an AI-assisted audit; an emergency hard fork (NU6.2) fixed it by June 3. THORChain, still offline following a separate $10.7M exploit, had planned ZEC as its next chain integration.

THORChain remains offline three weeks after a $10.7M vault exploit
According to MEXC News reporting from 5 June 2026, THORChain has remained offline since approximately 15 May 2026, following a $10.7 million exploit targeting a GG20 threshold-signature scheme used by one of its vaults. An attacker joined the network as a node operator and drained a single vault; four other vaults were not affected. The THORChain community approved recovery plan ADR028 on 29 May, and developers released version 3.19 with a corrected GG20 implementation and an additional key-verify safety step. According to the same reporting, the restart process — covering node software upgrades, fund migration, and trading resumption — was expected to require several more days as of 5 June.
AI-assisted audit exposes four-year-old soundness bug in Zcash's Orchard circuit
On 29 May 2026, Taylor Hornby, an independent security researcher contracted by Shielded Labs, discovered a critical vulnerability in Zcash's Orchard zero-knowledge proof circuit. Hornby was conducting an ongoing protocol audit and used Anthropic's Claude Opus 4.8 — released the day before, on 28 May — as part of a targeted review of the Orchard implementation. Within hours of disclosure to ZODL (Zcash Open Development Lab) engineers, the team confirmed the issue and began developing a coordinated fix. The vulnerability had been present in the Orchard codebase since Orchard's activation in May 2022, approximately four years without prior detection.
The vulnerability could have permitted unlimited counterfeit ZEC within Orchard
The flaw was a soundness vulnerability in the implementation of the Orchard zero-knowledge proof circuit in the halo2_gadgets crate. In a zero-knowledge system, soundness ensures that only valid transactions are accepted. This bug allowed a prover to supply false inputs to an elliptic curve multiplication step while still passing the circuit's consistency check. According to Shielded Labs, successful exploitation could have generated unlimited, undetectable counterfeit ZEC within the Orchard pool. The Zcash Foundation noted that no evidence of exploitation was found and that the total 21 million ZEC supply cap remained intact throughout, protected by Zcash's turnstile mechanism.
Orchard disabled June 2 via soft fork; NU6.2 hard fork restores it June 3
ZODL engineers coordinated privately with miners and exchanges beginning the evening of 31 May. A first soft-fork activation attempt encountered deployment challenges; engineers produced a second patch targeting block height 3,363,426, which activated at approximately 02:00 UTC on 2 June. This soft fork, implemented via Zebra 4.5.3, rejected all Orchard-containing transactions as a precautionary measure while the circuit fix was finalised. On 3 June at 00:05 EDT, the NU6.2 hard fork activated at block height 3,364,600, re-enabling Orchard with a corrected zero-knowledge proof circuit. The Zcash Foundation confirmed this was the second security-driven protocol upgrade in Zcash's history since the network launched in 2016.
ZEC falls 31 percent and RUNE drops 21 percent in the seven days after disclosure
ZEC traded at $364.97 as of 5 June 2026, down 31.27 percent over the preceding seven days (CoinPaprika, 05 June 2026). THORChain's native token RUNE traded at $0.3297, down 21.36 percent over the same period (CoinPaprika, 05 June 2026). Transparent ZEC transactions continued without interruption during the Orchard disable window on 2–3 June; the Zcash network itself was not halted. No exploitation of the Orchard vulnerability has been confirmed.
THORChain's planned ZEC integration is on hold until restart completes
According to MEXC News, THORChain had positioned Zcash as its next planned chain integration, scheduled ahead of Monero. The emergency Zcash network upgrades during 2–3 June added a further delay to that timeline. THORChain has not publicly confirmed a restart date as of 5 June 2026. The Zcash Foundation announced plans to formally verify the Orchard circuit following the incident and is exploring a new shielded pool with turnstile accounting to allow independent verification of the ZEC supply.
Primary source: Source ↗
Cryptocurrencies are highly volatile and involve significant risk. You may lose part or all of your investment.
All information on Coinpaprika is provided for informational purposes only and does not constitute financial or investment advice. Always conduct your own research (DYOR) and consult a qualified financial advisor before making investment decisions.
Coinpaprika is not liable for any losses resulting from the use of this information.