2 vulnerabilities, $1.5 million: Zcash’s most expensive “apology” in history
On September 30, the Zcash community voting concluded: 37 retrospective funding requests totaling $9.01 million were approved. The most eye-catching item—two Orchard counterfeit-bug bounties—came to $1.5 million in total: $750,000 each.
Whoever found a vulnerability that could “mint counterfeit money out of thin air” would get paid directly by the official.
The story starts on May 29. Security researcher Taylor Hornby used an AI model to audit Zcash’s privacy pool and uncovered a vulnerability that had been lurking for four years—one that, in theory, could mint unlimited fake $ZEC on-chain while leaving no trace.
There’s a backdoor in the treasury: it can create money from nothing, and the monitoring system can’t even capture it.
Once the news broke, ZEC’s price slashed in half in a single day, and more than $3 billion in market value simply evaporated.
But here’s the twist: the vulnerability was never actually exploited in the wild. The team patched it within three days. Then in July, they went even further—rolling out the Ironwood upgrade to fully seal off the old pool.
So paying out $1.5 million in bounties now isn’t because they’re heartbroken; it’s about sending a message—better to pay people to find problems first than wait for hackers to pick them up for free. Remember, they had already set aside a $1 million bounty pool back in April.
What does this mean for retail investors?
Security isn’t free, but trust collapse is far more expensive. A chain that’s willing to pay for bugs is more credible than one that pretends everything is fine.
One reminder, though: funding approval doesn’t automatically mean the market will take off. Don’t rush just because you see the words “approved.”
Do you think buying back trust for $1.5 million is worth it?
#zcash批准150万美元漏洞赏金
On September 30, the Zcash community voting concluded: 37 retrospective funding requests totaling $9.01 million were approved. The most eye-catching item—two Orchard counterfeit-bug bounties—came to $1.5 million in total: $750,000 each.
Whoever found a vulnerability that could “mint counterfeit money out of thin air” would get paid directly by the official.
The story starts on May 29. Security researcher Taylor Hornby used an AI model to audit Zcash’s privacy pool and uncovered a vulnerability that had been lurking for four years—one that, in theory, could mint unlimited fake $ZEC on-chain while leaving no trace.
There’s a backdoor in the treasury: it can create money from nothing, and the monitoring system can’t even capture it.
Once the news broke, ZEC’s price slashed in half in a single day, and more than $3 billion in market value simply evaporated.
But here’s the twist: the vulnerability was never actually exploited in the wild. The team patched it within three days. Then in July, they went even further—rolling out the Ironwood upgrade to fully seal off the old pool.
So paying out $1.5 million in bounties now isn’t because they’re heartbroken; it’s about sending a message—better to pay people to find problems first than wait for hackers to pick them up for free. Remember, they had already set aside a $1 million bounty pool back in April.
What does this mean for retail investors?
Security isn’t free, but trust collapse is far more expensive. A chain that’s willing to pay for bugs is more credible than one that pretends everything is fine.
One reminder, though: funding approval doesn’t automatically mean the market will take off. Don’t rush just because you see the words “approved.”
Do you think buying back trust for $1.5 million is worth it?
#zcash批准150万美元漏洞赏金
