There's a lot of confusion about the recently patched Zcash bug. Here's how to actually understand it.
If the bug had been exploited before the patch (very unlikely it was), it would have looked like the shielded pool getting drained. Whoever minted the counterfeit shielded ZEC would want to sell fast, before anyone else found the same bug. And remember, the market for ZEC is almost entirely transparent ZEC, not shielded. You can't dump freshly minted shielded ZEC on Binance or Coinbase without unshielding it first.
The losers in that scenario are shielded holders who sit still. The transparent portion of Zcash is fully visible, so it's trivial to enforce that transparent ZEC never exceeds max supply. If you try to unshield more than the cap, you'll get stopped at the door.
So if you hold transparent ZEC (anyone trading, on an exchange, or doing price discovery on ZEC) there's no marginal effect on you. The loss falls entirely on shielded holders.
The team's next step is a new turnstile and a fresh shielded pool in the coming upgrade, which will confirm the shielded pool was not inflated. Think of it as taking headcount at the end of the field trip--that will make sure no extra kids snuck onto the bus.
But while AI found this bug, AI will also deliver the fix for the whole category: formal verification. I'm very bullish on this as the path to harden all software across the industry. Formally verified cryptography can't have implementation bugs by construction.
Right now AI is surfacing vulnerabilities across all our software--browsers, OSes, and blockchains are no exception. We're in the awkward adolescence where every wart is getting magnified and put on full display. But formally verified software is the only path forward for mission-critical software, and Zcash has put it front and center on their roadmap to deliver.
Privacy is too important not to.
(Dragonfly holds $ZEC and continues to. I'm personally an investor in ZODL.)
zcash is starting to feel exactly like the early days of bitcoin. some of the smartest ppl contributing to the project. some of the biggest midwits on the other side. bugs and existential threats. vomit-inducing price volatility. but also insanely asymmetric upside if it catches on.
Zcash has unparalleled cryptographers, security engineers, and security researchers. And the community is heavily focused on continuous improvement and hardening the network. That's why it engages world class security researchers to look for bugs. And that's why the recent potential exploit was found. It wasn't by accident and it's a vote of confidence, not a cause for alarm. When it comes to any L1, there will be bugs. What's important is that there are world class researchers focused on hardening the network and staying ahead of the bad guys. This has always been and always will be the dynamic of building software that is secure. Onward.