01 LEDGER — the exploit record - zero motion - every row sourced
Beware: what the proof could not prove
“there's no way of knowing if anyone exploited the vulnerability to steal money.”
“it's impossible to know if it's been exploited... until Sprout addresses are deprecated”
B2cite
- claim
- B2
- last verified
- 2026-08-22
- confidence
- high
- GHSA-ww9q-8r59-xv46 / CVE-2026-54496 (Orchard soundness, CVSS 9.3) GitHub · accessed 2026-08-22
- ZODL — Orchard Vulnerability Successfully Remediated (2 Jun 2026) ZODL · 2026-05-29 · accessed 2026-08-22
- Zcash Community Forum — The Orchard Counterfeiting Vulnerability—And Next Steps (4 Jun 2026) Zcash Community Forum · 2026-06-04 · accessed 2026-08-22
- Schneier on Security — Critical Zcash Vulnerability Found and Fixed (Jun 2026) Schneier on Security · accessed 2026-08-22
B1cite
- claim
- B1
- last verified
- 2026-08-22
- confidence
- high
- ECC — Zcash Counterfeiting Vulnerability Successfully Remediated (5 Feb 2019) Electric Coin Company · 2018-03-01 · accessed 2026-08-22
- ZF — Concerning the Sprout Vulnerability CVE-2019-7167 Zcash Foundation · accessed 2026-08-22
- ZIP 209, Prohibit Out-of-Range Chain Value Pool Balances Zcash Improvement Proposals · accessed 2026-08-22
The two windows are B1 and B2. The corpus states their combined span as an approximation rather than as a count of days: they span roughly six of the chain's ~9.8 years, and nothing computed afterwards narrows that span.
C2C2cite
- claim
- C2
- last verified
- 2026-08-22
- confidence
- high
- ZODL — Zcashd Sprout Verification Vulnerability (31 Mar 2026) ZODL · 2026-05-29 · accessed 2026-08-22
- ZODL — Several Zcash Vulnerabilities Remediated (Apr 2026) ZODL · accessed 2026-08-22
- GHSA-ww9q-8r59-xv46 / CVE-2026-54496 (Orchard soundness, CVSS 9.3) GitHub · accessed 2026-08-22
The four figures above are counted from the fourteen rows below, not asserted separately. Strike a row you do not accept and the counts move with it.
The ledger
high primary source or two independent secondaries · med one reputable secondary
- B1
Sprout counterfeiting — BCTV14 soundness (CVE-2019-7167)critical · CVE-2019-7167
window: 28 Oct 2016 → 28 Oct 2018
found 1 Mar 2018 · fixed 28 Oct 2018 (Sapling, block 419,200, silently) · disclosed 5 Feb 2019 (341 days later)detectable from public data: NOconfidence: highB1last verified 2026-08-22B1cite
- claim
- B1
- last verified
- 2026-08-22
- confidence
- high
- ECC — Zcash Counterfeiting Vulnerability Successfully Remediated (5 Feb 2019) Electric Coin Company · 2018-03-01 · accessed 2026-08-22
- ZF — Concerning the Sprout Vulnerability CVE-2019-7167 Zcash Foundation · accessed 2026-08-22
- ZIP 209, Prohibit Out-of-Range Chain Value Pool Balances Zcash Improvement Proposals · accessed 2026-08-22
- B2
Orchard Action circuit soundness — missing copy constraint (CVE-2026-54496)critical · CVE-2026-54496 · GHSA-ww9q-8r59-xv46
window: 31 May 2022 → 1 Jun 2026 (4 years, 1 day)
found 29 May 2026, 23:53 · fixed soft fork 2 Jun 2026 (block 3,363,426); NU6.2 hard fork 3 Jun 2026 (block 3,364,600) · disclosed 4 Jun 2026 (forum); GHSA/CVE 15 Jun 2026detectable from public data: NOconfidence: highB2last verified 2026-08-22B2cite
- claim
- B2
- last verified
- 2026-08-22
- confidence
- high
- GHSA-ww9q-8r59-xv46 / CVE-2026-54496 (Orchard soundness, CVSS 9.3) GitHub · accessed 2026-08-22
- ZODL — Orchard Vulnerability Successfully Remediated (2 Jun 2026) ZODL · 2026-05-29 · accessed 2026-08-22
- Zcash Community Forum — The Orchard Counterfeiting Vulnerability—And Next Steps (4 Jun 2026) Zcash Community Forum · 2026-06-04 · accessed 2026-08-22
- Schneier on Security — Critical Zcash Vulnerability Found and Fixed (Jun 2026) Schneier on Security · accessed 2026-08-22
- B3
PING and REJECT remote side-channels (CVE-2019-16930, CVE-2019-17048)high · CVE-2019-16930 · CVE-2019-17048
window: Launch → Sep 2019 (Sprout + Sapling)
found 2019 · fixed zcashd 2.0.7-3 · disclosed 24 Sep 2019detectable from public data: NOconfidence: highB3last verified 2026-08-22B3cite
- claim
- B3
- last verified
- 2026-08-22
- confidence
- high
- ECC — New Release: 2.0.7-3 (24 Sep 2019) Electric Coin Company · 2019-09-24 · accessed 2026-08-22
- Tramèr, Boneh, Paterson — Remote Side-Channel Attacks on Anonymous Transactions, USENIX Security 2020 USENIX · accessed 2026-08-22
- B4
Sandblasting spam attack (Sapling Woodchipper)mid
window: Jun 2022 → Nov 2023
found ~mid-Jun 2022 · fixed ZIP 317 (default in zcashd v5.5.0, Apr 2023); spam stopped entering the mempool ~Nov 2023 · disclosed public by Oct 2022detectable from public data: YESconfidence: highB4last verified 2026-08-22B4cite
- claim
- B4
- last verified
- 2026-08-22
- confidence
- high
- Protos — Zcash chain triples in size thanks to $10-a-day spam attack Protos · accessed 2026-08-22
- Sandblasting Retrospective (ZCG arboretum notes) GitHub · 2022-05-31 · accessed 2026-08-22
- ZIP 317 (proportional transfer fee) Zcash Improvement Proposals · accessed 2026-08-22
- B5
zcashd skipped Sprout proof verification for 5.7 yearshigh
window: Jul 2020 → Mar 2026
found 23 Mar 2026 (reported) · fixed zcashd 6.12.0 · disclosed 31 Mar 2026detectable from public data: PARTIALconfidence: highB5last verified 2026-08-22B5cite
- claim
- B5
- last verified
- 2026-08-22
- confidence
- high
- ZODL — Zcashd Sprout Verification Vulnerability (31 Mar 2026) ZODL · 2026-05-29 · accessed 2026-08-22
- Decrypt — Zcash devs patch vulnerability, millions at risk (Mar 2026) Decrypt · accessed 2026-08-22
- B6
Turnstile accounting bypass via duplicate block headerhigh
window: zcashd v5.0.0 → v6.12.0
found 4 Apr 2026 · fixed zcashd 6.12.1 · disclosed ~17 Apr 2026detectable from public data: PARTIALconfidence: highB6last verified 2026-08-22B6cite
- claim
- B6
- last verified
- 2026-08-22
- confidence
- high
- ZODL — Several Zcash Vulnerabilities Remediated (Apr 2026) ZODL · accessed 2026-08-22
- B7
Orchard identity-rk crash, identity-epk consensus gap and signed-overflow pool accounting (Apr 2026)high · GHSA-452v-w3gx-72wg
window: zcashd v5.0.0 / Zebra v1.0.0 → zcashd v6.12.0 / Zebra v4.3.0
found 4 Apr 2026 · fixed zcashd 6.12.1 / Zebra 4.3.1+ · disclosed ~17 Apr 2026detectable from public data: YESconfidence: highB7last verified 2026-08-22B7cite
- claim
- B7
- last verified
- 2026-08-22
- confidence
- high
- ZODL — Several Zcash Vulnerabilities Remediated (Apr 2026) ZODL · accessed 2026-08-22
- B8
Viewing-key leak via memo Reply-Tomid
window: ECC iOS ref wallet 0.3.7-105 (6 May 2021) → Nighthawk 1.9+
found Jul 2021 · fixed wallet updates (post-0.3.7-105 ECC iOS reference wallet; post-1.9 Nighthawk) · disclosed 13 Jul 2021detectable from public data: PARTIALconfidence: highB8last verified 2026-08-22B8cite
- claim
- B8
- last verified
- 2026-08-22
- confidence
- high
- ECC — Privacy-leak bug in Nighthawk and ECC wallets (13 Jul 2021) Electric Coin Company · 2021-07-13 · accessed 2026-08-22
- B9
Linkability research: round-trips, anonymity-set shrinkage and mining fingerprintsmid
window: ongoing → ongoing
found 2017-2019 · fixed not applicable -- usage-pattern research findings, not a software defect with a patch · disclosed 2017-2019detectable from public data: N/Aconfidence: highB9last verified 2026-08-22B9cite
- claim
- B9
- last verified
- 2026-08-22
- confidence
- high
- Quesnelle — On the linkability of Zcash transactions, arXiv:1712.01210 (4 Dec 2017) arXiv · 2017-12-04 · accessed 2026-08-22
- Kappos, Yousaf, Maller, Meiklejohn — An Empirical Analysis of Anonymity in Zcash, USENIX Security 2018 USENIX · accessed 2026-08-22
- Biryukov, Feher — Privacy and Linkability of Mining in Zcash, IEEE CNS 2019 orbilu.uni.lu · accessed 2026-08-22
- B10
The 2026 advisory wave -- 41 Zebra advisories in five monthshigh · CVE-2026-34377 · CVE-2026-41583 · CVE-2026-44497 · CVE-2026-52735
window: Mar 2026 → Aug 2026
found Mar-Aug 2026 · fixed various point releases across zcashd and Zebra, Mar-Aug 2026; several required a second or third re-fix · disclosed Mar-Aug 2026detectable from public data: YESconfidence: highB10last verified 2026-08-22B10cite
- claim
- B10
- last verified
- 2026-08-22
- confidence
- high
- zcash/zcash security disclosures GitHub · accessed 2026-08-22
- ZcashFoundation/zebra advisories (pages 1–5) GitHub · 2026-08-22 · accessed 2026-08-22
- z.cash — zcashd deprecation / EOL Zcash · accessed 2026-08-22
- B11
ViaBTC 53% hashrate concentrationhigh
window: Sep 2023 → Sep 2023
found not separately dated in the corpus · fixed Coinbase raised confirmations from 40 to 110 and moved to limit-only trading; no protocol-level fix · disclosed 15 Sep 2023detectable from public data: YESconfidence: highB11last verified 2026-08-22B11cite
- claim
- B11
- last verified
- 2026-08-22
- confidence
- high
- crypto.news — Coinbase limits Zcash trading (ViaBTC) crypto.news · accessed 2026-08-22
- B12
Ledger drops v1 (pre-Sapling) transaction supportmid
window: Nov 2025 → 2026
found not separately dated in the corpus · fixed partial: Ledger Live added shielded-input-to-transparent sending ~Jul 2026 · disclosed 15-16 Nov 2025detectable from public data: YESconfidence: medB12last verified 2026-08-22B12cite
- claim
- B12
- last verified
- 2026-08-22
- confidence
- med
- The Defiant — Ledger draws heat as pre-2018 Zcash holders face dropped support The Defiant · accessed 2026-08-22
- B13
Pre-launch trio: InternalH collision, Faerie Gold, proof errormid
window: not applicable → not applicable
found 2016 (pre-launch) · fixed pre-launch, before mainnet (28 Oct 2016) · disclosed 26 Apr 2016detectable from public data: N/Aconfidence: highB13last verified 2026-08-22B13cite
- claim
- B13
- last verified
- 2026-08-22
- confidence
- high
- ECC — Fixing Vulnerabilities in the Zcash Protocol (26 Apr 2016) Electric Coin Company · 2016-04-26 · accessed 2026-08-22
- B14
Trusted setups still load-bearing: the 2016 Ceremony and 2018 Powers of Tauhigh
window: 2016 → ongoing
found 2016 / 2018 · fixed not applicable -- ongoing trust assumption; Sprout and Sapling still rest on the 2016/2018 ceremony parameters · disclosed 2016 / 2018 (Snowden's participation revealed Apr 2022)detectable from public data: N/Aconfidence: highB14last verified 2026-08-22B14cite
- claim
- B14
- last verified
- 2026-08-22
- confidence
- high
- ECC — The Design of the Ceremony Electric Coin Company · accessed 2026-08-22
- CoinDesk — Zcash and the Art of Security Theater (14 Nov 2016) CoinDesk · 2016-11-14 · accessed 2026-08-22
- CoinDesk — Zcash Completes 'Powers of Tau' (13 Apr 2018) CoinDesk · 2018-04-13 · accessed 2026-08-22
- Wikipedia — Zcash Wikipedia · accessed 2026-08-22
The Orchard soundness flaw, in full
window 31 May 2022 → 1 Jun 2026 (4 years, 1 day)
root cause — halo2_gadgets/src/ecc/chip/mul/incomplete.rs · L309-310
// the incomplete double-and-add loop kept the base constant across rows via q_mul_2, // but never tied it to the real base point g_d - the base was free. - region.assign_advice(|| "x_p", self.double_and_add.x_p, row + offset, || x_p)?; - region.assign_advice(|| "y_p", self.y_p, row + offset, || y_p)?; + if row == 0 { + region.copy_advice(|| "base", self.base, 0, self.double_and_add.x_p, row)?; + } // consequence: pk_d = [ivk]·g_d was never enforced, so the same note stays // spendable under fresh nullifiers. Consensus only rejects repeated ones.
The two removed lines are the assignment the root cause names, at the file and lines it names. The three added lines are the shape of the constraint that was missing, reconstructed from that description rather than copied from the upstream commit.
ZIP 209 rejects any block that would drive a pool's balance below zero, so what a pool can pay out is bounded by what provably entered it. That is the layer at which the 21 million cap held. It says nothing about which notes inside the pool were real: forged and legitimate notes are indistinguishable once they are in, so the value a counterfeiter could have realised would have come out of other holders, not out of new supply. Both readings - unlimited counterfeit, and the cap intact - are true, at different layers.
GitHub · ZODL · Zcash Community Forum · Schneier on Security
B2cite
- claim
- B2
- last verified
- 2026-08-22
- confidence
- high
- GHSA-ww9q-8r59-xv46 / CVE-2026-54496 (Orchard soundness, CVSS 9.3) GitHub · accessed 2026-08-22
- ZODL — Orchard Vulnerability Successfully Remediated (2 Jun 2026) ZODL · 2026-05-29 · accessed 2026-08-22
- Zcash Community Forum — The Orchard Counterfeiting Vulnerability—And Next Steps (4 Jun 2026) Zcash Community Forum · 2026-06-04 · accessed 2026-08-22
- Schneier on Security — Critical Zcash Vulnerability Found and Fixed (Jun 2026) Schneier on Security · accessed 2026-08-22
timeline — patched before it was told
T2022-05-31cite
- claim
- T2022-05-31
- last verified
- 2026-08-22
- confidence
- high
- Zcash: Upgrade NU5 Zcash · accessed 2026-08-22
T2026-05-28cite
- claim
- T2026-05-28
- last verified
- 2026-08-22
- confidence
- high
- Zcash Community Forum — The Orchard Counterfeiting Vulnerability—And Next Steps (4 Jun 2026) Zcash Community Forum · 2026-06-04 · accessed 2026-08-22
T2026-05-29cite
- claim
- T2026-05-29
- last verified
- 2026-08-22
- confidence
- high
- ZODL — Orchard Vulnerability Successfully Remediated (2 Jun 2026) ZODL · 2026-05-29 · accessed 2026-08-22
T2026-06-01cite
- claim
- T2026-06-01
- last verified
- 2026-08-22
- confidence
- high
- ZF — Zebra 4.5.3 and 5.0.0: Emergency Soft Fork and NU6.2 Activation Zcash Foundation · 2026-06-02 · accessed 2026-08-22
T2026-06-03cite
- claim
- T2026-06-03
- last verified
- 2026-08-22
- confidence
- high
- Zcash: Upgrade NU6 2 Zcash · accessed 2026-08-22
T2026-06-04cite
- claim
- T2026-06-04
- last verified
- 2026-08-22
- confidence
- high
- The Block — Zcash vulnerability, ZEC drops 31% (4 Jun 2026) The Block · 2026-06-04 · accessed 2026-08-22
- BitMEX Blog — Why Zcash Crashed Nearly 50% in 48 Hours bitmex.com · accessed 2026-08-22
T2026-06-04-2cite
- claim
- T2026-06-04-2
- last verified
- 2026-08-22
- confidence
- high
- CoinDesk, "Arthur Hayes dumps zcash holdings after Orchard Pool vulnerability revealed" (2026-06-05) CoinDesk · 2026-06-05 · accessed 2026-08-22
T2026-06-15cite
- claim
- T2026-06-15
- last verified
- 2026-08-22
- confidence
- high
- GHSA-ww9q-8r59-xv46 / CVE-2026-54496 (Orchard soundness, CVSS 9.3) GitHub · accessed 2026-08-22
- Crypto Briefing — Zcash jumps 25% as Anthropic Mythos audit finds no critical flaws (15 Jun 2026) Crypto Briefing · 2026-06-15 · accessed 2026-08-22
T2026-07-28cite
- claim
- T2026-07-28
- last verified
- 2026-08-22
- confidence
- high
- ZIP 258, Deployment of the NU6.3 Network Upgrade Zcash Improvement Proposals · 2026-07-28 · accessed 2026-08-22
- The Block — Zcash activates Ironwood (28 Jul 2026) The Block · 2026-07-28 · accessed 2026-08-22
The confirmation on 30 May and the private coordination with miners and exchanges on 31 May are not separate rows in the corpus timeline; they are recorded inside B2's own account, opposite. Block heights appear here in the rows' own wording because the timeline's height field is unset on all nine of them.
Why the residual cannot be cleared
the bound — what a turnstile can and cannot do
A turnstile bounds what a pool may pay out by what provably entered it. It cannot tell a forged note from a real one already inside the pool; it can only refuse to let the pool go negative. A pool that ran on an unsound circuit is therefore settled by being emptied, and by nothing else - which is why the question B1 opened in 2016 is still open.
Sprout has not emptied in about eight years: it still holds roughly 22,000 to 25,400 ZEC under the 2016 ceremony parameters. Orchard has been exit-only since 28 July 2026, and roughly 708,841 ZEC remain inside it, in a pool whose supply is not yet verifiable.
C3cite
- claim
- C3
- last verified
- 2026-08-22
- confidence
- high
- ZIP 209, Prohibit Out-of-Range Chain Value Pool Balances Zcash Improvement Proposals · accessed 2026-08-22
- ZIP 308 (Sprout→Sapling migration) Zcash Improvement Proposals · accessed 2026-08-22
- crypto.news — Why 30% of Zcash supply is in the shielded pool (29 May 2026) crypto.news · 2026-05-29 · accessed 2026-08-22
- CoinDesk — Zcash and the Art of Security Theater (14 Nov 2016) CoinDesk · 2016-11-14 · accessed 2026-08-22
C9cite
- claim
- C9
- last verified
- 2026-08-22
- confidence
- med
- ZIP 258, Deployment of the NU6.3 Network Upgrade Zcash Improvement Proposals · 2026-07-28 · accessed 2026-08-22
- CipherScan — Ironwood migration tracker CipherScan · 2026-08-22 · accessed 2026-08-22
what this is not — the claim is narrower than the accusation
Nothing on this page says that counterfeiting occurred. The claim is the narrower and harder one: for the length of two windows the property that would have ruled it out did not hold, and no analysis performed afterwards can restore it. The balances still sitting in those two pools are the measure of what remains unresolved, and this site publishes them as an open quantity rather than as an accusation.
16 marketing claims are set against the same record on Contradictions, and the same events sit on one axis with the funding and governance strands on the timeline.