Zcash’s ZEC token plunged on June 5, 2026, after a public disclosure revealed that a critical flaw in the Orchard shielded pool could have permitted counterfeit value inside the privacy system. Engineers had already patched the vulnerability, but the disclosure introduced a harder problem: the same privacy properties that conceal Orchard transactions prevented a definitive cryptographic audit of whether the flaw had previously been exploited.

At 7:35 a.m. Eastern on June 5, The Block reported ZEC trading near $310 after reaching about $630 on June 4. Its point-in-time account said the token had fallen as low as roughly $250 before recovering and cited CoinGlass estimates of at least $116 million in liquidations across 19,160 traders during the preceding 24 hours. The publication cautioned that exchange liquidation feeds are incomplete and can undercount forced closures.

CoinDesk’s report, updated at 10:19 a.m. Eastern, similarly described a decline approaching 50% over 24 hours and cited approximately $118 million in CoinGlass liquidations. Those figures were contemporaneous snapshots rather than a consolidated daily close, and ZEC traded continuously across multiple venues. They establish the scale and direction of the repricing, not one universal execution price.

A repaired circuit, disclosed uncertainty

Security researcher Taylor Hornby discovered the soundness vulnerability on May 29 while auditing Orchard for Shielded Labs. According to the Zcash Foundation, engineers confirmed the report and coordinated privately with miners, exchanges and other infrastructure operators while preparing a fix.

An emergency soft fork activated at approximately 02:00 UTC on June 2 at mainnet block 3,363,426, temporarily rejecting transactions and blocks containing Orchard actions. The NU6.2 network upgrade then activated at mainnet block 3,364,600 at 00:05 Eastern on June 3. It re-enabled Orchard using a corrected circuit and a new verifying key.

ZIP 257, the protocol record documenting the response, identifies the defect as a soundness flaw in Orchard’s variable-base scalar-multiplication gadget. In practical terms, the circuit could accept a proof for an invalid state transition. The ZIP says the flaw could have allowed balance violations and theft, which explains why Orchard was disabled before the corrected circuit was publicly deployed.

The market shock followed a disclosure posted late on June 4 by Zcash co-founder Zooko Wilcox, researcher Jason McGee and Hornby. They said a locally tested exploit could generate an unlimited amount of undetectable counterfeit ZEC inside Orchard and that cryptography alone could not prove whether anyone had used it before remediation. They did not claim to have found evidence of a mainnet exploit.

Two claims with different boundaries

The Zcash Foundation’s June 3 account used narrower language. It said there was no evidence of unauthorized value creation and argued that Zcash’s turnstile mechanism protected the total ZEC supply across value pools. Its description characterized the potential harm as double-spending within Orchard without the ability to inflate the network-wide supply.

Those statements were not fully equivalent. Shielded Labs addressed what could have existed invisibly inside Orchard; the Foundation emphasized what could exit shielded pools and affect publicly tracked aggregate balances. As of June 5, the surviving records did not independently resolve that distinction or prove the complete historical integrity of Orchard’s internal balance.

That uncertainty mattered because monetary scarcity is part of ZEC’s investment case. The emergency upgrade closed the known vulnerability for new transactions, but a software patch could not retroactively produce evidence that the privacy system had never accepted counterfeit value. The June 5 selloff therefore represented more than a reaction to vulnerable code: it was a rapid repricing of what market participants believed could be verified about the asset’s past.

Primary sourceShielded Labs authors — The Orchard Counterfeiting Vulnerability and Next Steps

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.