Unable to reply again, but I've always assumed Charles knew who I was given that folks at IOG knew who I was. And given I haven't leaked anything (and indeed knew nothing about this drama beyond what Monad has posted) then I've not got anything to worry about.
So silly how this is blowing up just because I defended someone's freedom to discuss.
Now that 15th position has been breached by Cardano, it's going to be a rapid plummet down to below 20th from here.
Cardano members, switch over to Canton.
Not All Privacy Protocols are Created Equal
The ZEC flaw proved why cryptographic foundations matter.
COTI Garbled Circuits are Built Different
โ Compute on encrypted inputs through MPC
โ No single proving circuit
โ Built on symmetric-key cryptography
๐ก๏ธ Privacy you can verify
@planetmaaz But it may still have the same issue of it not being suitable for high volume use cases. Traders for example want to know their transaction will go through immediately during times of high demand
just woke up and seeing a fair bit of fake info
- first, there is no *known* exploit. the possibility of a bug has always existed, so there is no new information. what's happened is a highly advanced zcash expert spent a lot of resources trying to find bugs and *patched* one. that's all the information that's new: that a bug was patched.
- again, all signs show no exploit but you can not 100% guarantee this until the next network upgrade, which core devs are working on right now. Eta soon.
- you can NOT have infinite total ZEC supply EVEN if this bug was exploited.
What would instead happen is that the single orchard pool would be insolvent assuming no social recovery. Now for all purposes, that would still be catastrophic but very different than people implying you can just bridge out infinite amounts (you cant)
So tl dr - you cant have infinite supply bridging out, that's not possible. you CAN have a case where ppl in the shielded pool get insolvent if and only if the bug was exploited. my money is on the bug not being exploited but to prove this for everyone, the next upgrade will help you verify it yourself
The worst case scenario for $ZEC just became reality ๐จ
- vulnerability discovered inside Orchard
- Zcashโs main shielded pool active since May 2022
- remained unnoticed for more than 4 years
- discovered on May 29, 2026 by security researcher Taylor Hornby
- using Claude Opus 4.8 as part of the review process
the vulnerability
- could create counterfeit ZEC
- unlimited amounts
- completely undetectable inside Orchard
Taylor reportedly built a working exploit
- generated counterfeit ZEC
- successfully tested it
- exploit considered real
the problem
- Orchard is private
- privacy hides transaction details
- privacy hides balances
- privacy hides supply flows
which means
- nobody can prove the vulnerability was never exploited
- nobody can prove counterfeit ZEC was never created
- nobody can prove the circulating supply was never affected
even the Zcash team admits this
โThere is no definitive way to determine whether exploitation occurred.โ
the Zcash team is now discussing
- a new shielded pool
- migration away from Orchard
- turnstile accounting
- supply verification mechanisms
- formal verification of Orchard
Probably one of the most frightening vulnerabilities ever discovered in a privacy coin.