Zcash($ZEC) released a notification earlier today regarding a serious security vulnerability. Originally identified by an internal engineer in March, and subsequently patched during the October "Sapling" network upgrade, this vulnerability could have allowed an attacker to mint an unlimited amount of tokens without being identified by the broader ecosystem. At a deeper level, a hacker may have bene able to circumvent a crucial protocol check point, and transform a zero-knowledge proof of one statement into a valid-looking proof of a different statement, thus breaking the soundness of the proving system. This issue likely exists in all platforms using zero knowledge proofs, but the Zcash team doesn't believe the vulnerability was exploited before the upgrade.