Charts
DataOn-chain
VIP
Market Cap
API
Rankings
CoinOSNew
CoinClaw🦞
Language
  • 简体中文
  • 繁体中文
  • English
Leader in global market data applications, committed to providing valuable information more efficiently.

Features

  • Real-time Data
  • Special Features
  • AI Grid

Services

  • News
  • Open Data(API)
  • Institutional Services

Downloads

  • Desktop
  • Android
  • iOS

Contact Us

  • Chat Room
  • Business Email
  • Official Email
  • Official Verification

Join Community

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|Legacy

Zcash Vulnerability That Put Millions of Dollars of ZEC at Risk Has Been Fixed

CN
Decrypt
Follow
3 hours ago
AI summarizes in 5 seconds.

A security researcher discovered a critical vulnerability in Zcash nodes that could have allowed malicious miners to drain more than 25,000 ZEC from the network's deprecated Sprout shielded pool—a sum worth about $6.5 million at writing.


Alex "Scalar" Sol disclosed the flaw on March 23, according to a disclosure report released Tuesday, revealing that zcashd nodes were skipping proof verification for transactions involving the legacy Sprout pool. The bug was not exploited and all users' funds remain safe, according to the disclosure.


The vulnerability spanned releases from July 2020 through the present, with Zcash developers releasing v6.12.0 on Tuesday to contain the fix. Major mining pools moved quickly to patch their systems—Luxor mining pool confirmed deployment on March 25, while F2Pool, ViaBTC, and AntPool all deployed the fix by March 26, according to the same report.





The Zebra full node implementation was not affected by the vulnerability, the report said, and would have triggered a chain fork if exploitation had been attempted, providing an additional layer of network protection.


Sol, who discovered the vulnerability using AI assistance, reported it to Shielded Labs on March 23. The organization coordinated with the Zcash Open Development Lab (ZODL), whose engineer Jack "str4d" Grigg authored the patch.


For his disclosure, Sol will receive a 200 ZEC total bounty—valued above $51,000—with Shielded Labs, ZODL, the Zcash Foundation, and Bootstrap each contributing 50 ZEC.


The Sprout pool was closed to new deposits in November 2020, making it a deprecated but still-active component holding approximately 25,424 ZEC that users have not yet migrated to newer shielded pool versions.


While the vulnerability could have allowed draining these funds, the Zcash Open Development Team (ZODL) said that Zcash's "turnstile" mechanism would have prevented broader supply inflation. The turnstile requires that any coins leaving the Sprout pool must have verifiably entered it, creating a safeguard against the creation of new tokens beyond the network's total circulation of around 16.63 million ZEC.


This isn’t the first big vulnerability that the network has faced. Back in 2019, the network patched a bug described as an “infinite counterfeit” crypto generator, though it was patched out before becoming a major issue for the privacy coin network.


Zcash is the biggest gainer over the last 24 hours among the top 100 coins by market cap, per CoinGecko data, rising more than 14% to a recent price above $255. The price of the privacy coin skyrocketed last fall from a price of about $50 to a multi-year peak near $700, but has fallen alongside Bitcoin and other cryptocurrencies in recent months.


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

极度恐慌别慌!注册币安领600 USDT,10%低费抄底!
广告
|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Selected Articles by Decrypt

2 hours ago
Crypto Startup Uses Polymarket to Bet on Its Own Fundraise, Blindsiding Backers
2 hours ago
If You Hold Solana on Magic Eden\\\'s Wallet, It\\\'s Time to Move It or Lose It
3 hours ago
California Tightens AI Contract Rules as Fight With Trump Admin Grows
View More

Table of Contents

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Related Articles

avatar
avatarbitcoin.com
23 minutes ago
Moody’s Assigns Ba2 Rating to $100M Bitcoin-Backed Revenue Bonds From New Hampshire Authority
avatar
avatarcoindesk
53 minutes ago
Bitcoin enters the public bond market as Moody’s gives a first-of-its-kind crypto deal a rating
avatar
avatarbitcoin.com
1 hour ago
Mercado Libre Ends Mercado Coin Program, Cites No Official Reason
avatar
avatarbitcoin.com
2 hours ago
Global Markets Rise as Trump and Iran Signal End to Military Operations
avatar
avatarDecrypt
2 hours ago
Crypto Startup Uses Polymarket to Bet on Its Own Fundraise, Blindsiding Backers
APP
Windows
Mac

X

Telegram

Facebook

Reddit

CopyLink