This was originally sent to subscribers of Messari's Unqualified Opinions. Click here to become a subscriber and access all of our historical content.
Dan McArdle- February 5, 2019
A massive story today (Fortunegot the deets) regarding a security vulnerability in ZCash’s core zk-snarks cryptography. The ZCash team confirmed that one of their internal engineers discovered an “infinite inflation bug” in March, and subsequently patched the vulnerability discreetly during the network’s October "Sapling" upgrade.
The bug could have allowed an attacker to mint an unlimited amount of tokens without being identified by the broader ecosystem by circumventing a crucial protocol check point, and transforming a zero-knowledge proof of one statement into a valid-looking proof of a different statement. Incredibly, this issue likely existed/exists in all platformsusing zero knowledge proofs, but the Zcash team claims it doesn't believe the vulnerability was exploited before the upgrade.
Unfortunately, there’s no way to be sure one way or another.
Dan weighs in…