Zcash fixes critical vulnerability: previously threatened the security of over 25,000 ZEC, worth approximately 6.5 million dollars
The privacy coin Zcash recently disclosed and fixed a critical security vulnerability that could have been exploited by malicious miners to transfer over 25,000 ZEC (approximately 6.5 million USD) from the deprecated Sprout privacy pool. Security researcher Alex "Scalar" Sol disclosed on March 23 that the vulnerability stemmed from the zcashd node skipping proof verification when processing transactions involving the Sprout pool.
The official statement indicated that the vulnerability had existed since July 2020 but had not been actively exploited, and user funds remained safe at all times. The development team has released version 6.12.0 to complete the fix, and mainstream mining pools have completed the upgrade deployment within a few days. Additionally, the unaffected Zebra full node implementation has the capability to trigger a chain fork, providing extra protection in the event of exploitation.
It was disclosed that although the Sprout pool closed to new deposits in November 2020, approximately 25,424 ZEC remained untransferred. Even if the vulnerability were exploited, Zcash's "turnstile" mechanism would prevent inflationary issuance, ensuring that the total supply would not be breached. This vulnerability was discovered with the assistance of AI, and the researcher will receive a total bounty of 200 ZEC (approximately 51,000 USD). It is worth noting that this is not the first time Zcash has encountered a significant vulnerability; as early as 2019, it had fixed a serious flaw that could lead to unlimited issuance.
You may also like

Stablecoin mergers: there will be no "winner takes all"

Warmonger Trump has forgotten about Americans waiting in airport lines for hours

Houthi Have a Checkpoint | Rewire News Morning Brief

The Money-Saving Philosophy of the AI Era: How to Spend Every Token Wisely

$240 Billion Dark Forest, The Fall of Iron Finance

3 hellos limit, where did your Claude Code limit go? A 28-day cache Bug, and an official response that encourages you to "use it sparingly."

How to Make Money on Polymarket Using AI?

Morning Report | YZi Labs strategically increases investment in Predict.fun; Drift Protocol suffers an attack with losses of at least $200 million; Coinbase's x402 joins the Linux Foundation

The $590 Billion Dream: How Did the Female Warren Buffett Fall from Grace?

Dialogue with the founder of Pantera: Bitcoin has reached escape velocity, traditional assets are being left behind

The growth dilemma of Base: everything was done right, yet users still leave

Predicting the World Cup "Showdown": Over 150 projects are gearing up, with a total investment of nearly 6 billion dollars

RootData launches the "A-Level Transparency Project Briefing," directly reaching the cryptocurrency listing decision-making chain

What does DeFi look like that Wall Street wants?

Drift Protocol Hack: Understanding One of the Largest Solana Ecosystem Breaches
Key Takeaways Drift Protocol, a decentralized exchange on Solana, experienced a $270 million hack, making it one of…

Navigating the Drift Protocol Security Incident: What You Need to Know
Key Takeaways On April 2, Drift Protocol experienced a security breach where a malicious actor gained administrative control.…

Upbit and Bithumb Designate DRIFT as a Trading Alert Item
Key Takeaways Upbit and Bithumb have labeled DRIFT as a “trading alert” asset following guidance from the Digital…

“Brother Maji” Faces Potential Liquidation with ETH Long Position
Key Takeaways “Brother Maji” currently holds a substantial 25x leveraged long position of 6,000 ETH. The position was…
