🖨 Zcash discloses vulnerability that could have allowed infinite counterfeit cryptocurrency

Zcash($ZEC) released a notification earlier today regarding a serious security vulnerability. Originally identified by an internal engineer in March, and subsequently patched during the October "Sapling" network upgrade, this vulnerability could have allowed an attacker to mint an unlimited amount of tokens without being identified by the broader ecosystem. At a deeper level, a hacker may have bene able to circumvent a crucial protocol check point, and transform a zero-knowledge proof of one statement into a valid-looking proof of a different statement, thus breaking the soundness of the proving system. This issue likely exists in all platforms using zero knowledge proofs, but the Zcash team doesn't believe the vulnerability was exploited before the upgrade.

Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.
Mentioned Assets

Suggested Research Based on your Watchlists

Create a new watchlist
Mentioned Assets