Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • Indices
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Indices
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Blockchain News

Zcash Activates NU6.2 Hard Fork Following Double-Spend Risk Discovery

The vulnerability was caught before any known exploitation occurred, and the response marks only the second security-driven protocol upgrade in Zcash's history.

Written By Dhara Chavda
Published 2026-06-03·Updated 3 months ago
Make The Crypto Times preferred on GoogleGoogle
Zcash Activates NU6.2 Hard Fork Following Double-Spend Risk Discovery
Show AI Summary
Zcash network’s NU6.2 hard fork upgrade enhances security by fixing a critical vulnerability
The upgrade marks a significant milestone in Zcash’s history, being only its second security-driven protocol upgrade since 2016
Resolution of the soundness bug protects the integrity of Zcash’s shielded transaction pool, preserving user trust in the network

The Zcash network has successfully completed the NU6.2 hard fork upgrade, re-enabling the Orchard shielded pool with a corrected zero-knowledge proof circuit after a critical vulnerability forced an emergency suspension earlier this week.

According to an announcement from the Zcash Foundation, NU6.2 activated at block height 3,364,600 on Mainnet at approximately 00:05 EDT on Wednesday, June 3. The upgrade closes a soundness vulnerability that, if exploited, could have allowed double-spending within Orchard — Zcash’s privacy-focused transaction pool that holds a substantial portion of the network’s shielded ZEC.

Zebra 4.5.3 and 5.0.0: Emergency Soft Fork and NU6.2 Activation

🚨 Zebra 5.0.0 is out – all node operators should upgrade now.

⚡ NU6.2 activated, re-enabling Orchard with a corrected circuit.

🔒 Total ZEC supply confirmed intact throughout.

Read the full update:…

— Zcash Foundation 🛡️ (@ZcashFoundation) June 3, 2026

The successful activation marks only the second security-driven protocol upgrade in Zcash’s history since the network launched in 2016, and concludes a five-day emergency response that ran from initial disclosure on May 29 to full resolution on June 3.

What the Bug Could Have Done

The Zcash Foundation has now publicly disclosed the technical nature of the vulnerability that triggered the emergency response. The issue was a soundness bug in the implementation of the Orchard zero-knowledge proof circuit in the halo2_gadgets crate.

In zero-knowledge proof systems, “soundness” is the property that ensures only valid transactions and state transitions are accepted by the network. A soundness vulnerability means the system could be tricked into accepting something it should have rejected. In this case, the bug could have allowed the Orchard pool to accept invalid state transitions — which the Foundation says could potentially have enabled double-spending of funds within Orchard.

Critically, the Foundation emphasized that the vulnerability could not have been used to inflate the total ZEC supply. Zcash’s turnstile mechanism, which tracks the total ZEC balance across all value pools (Sprout, Sapling, Orchard, transparent, and lockbox), enforces invariants on how value can flow between them. That mechanism provided what the Foundation called “a ground truth that ecosystem participants could use to confirm the supply cap remained intact, even while the Orchard circuit fix was being developed.”

The vulnerability was caught before any known exploitation occurred. There is no evidence of unauthorized value creation, and user privacy was not affected throughout the incident. Sapling and transparent transactions continued operating normally.

The Five-Day Response Timeline

The response began on Friday, May 29, when independent security researcher Taylor Hornby — conducting an ongoing protocol audit on behalf of Shielded Labs — discovered the vulnerability and responsibly disclosed it to ZODL core engineers that evening.

Within hours, ZODL engineers Daira-Emma Hopwood, Kris Nuttycombe, and Jack Grigg confirmed the issue and began evaluating remediation options. Private coordination with miners and exchanges began the evening of Sunday, May 31, while details of the flaw were kept private to minimize the risk of exploitation before a fix could be deployed.

A first soft-fork activation attempt encountered coordination challenges during patch deployment. ZODL engineers responded by producing a second patch targeting block height 3,363,426, which successfully activated at approximately 02:00 UTC on June 2. This soft fork — implemented through Zebra 4.5.3 — temporarily rejected all Orchard-containing transactions and blocks while the proper circuit fix was being finalized.

The Foundation explained the indirect approach: “A direct patch would have revealed too much about the nature of the flaw to anyone with access to the updated code. Disabling Orchard as a first step limited the disclosure of vulnerability details while the circuit fix was finalized.”

Initial estimates suggested Orchard could be re-enabled by 14:00 EDT on June 2, but the actual NU6.2 hard fork activation occurred approximately 10 hours later than initially anticipated, at 00:05 EDT on June 3.

Why a Hard Fork Was Required

The choice between a soft fork and a hard fork was not arbitrary. NU6.2 required a hard fork because remediating a zero-knowledge proof circuit bug involves updating the pinned verifying key — a change that cannot be made through a node software patch alone.

Zebra 5.0.0 implements the NU6.2 upgrade and routes Orchard proofs to a per-circuit verifying key (InsecurePreNu6_2 and FixedPostNu6_2), permanently closing the vulnerability that the 4.5.3 soft fork temporarily mitigated. The Foundation has strongly urged all node operators to upgrade to Zebra 5.0.0, warning that nodes that did not upgrade before the mainnet activation height will need to either sync from scratch or restore from a backed-up state taken before the activation height.

The vulnerability affected a wide range of versions: all versions of halo2_gadgets prior to v0.5.0, all versions of orchard prior to v0.14.0, all versions of zcash_primitives prior to v0.28.0, zcashd v5.0.0 through v6.12.3, and zebrad versions below v4.5.1.

The Coordinated Response Model

The Foundation framed the incident as a demonstration of the security model that has evolved around Zcash since launch. “This upgrade succeeded because the necessary pieces were already in place: ongoing security review by independent researchers, established responsible disclosure procedures, experienced protocol engineers, and a network of independent participants who acted quickly when required.”

The response required voluntary cooperation from miners, node operators, infrastructure operators, exchanges, wallet providers, and other network participants — all acting independently around the shared goal of protecting users and preserving network integrity. Cake Wallet, which had only added shielded Zcash support in January 2026 with Orchard transactions enabled by default, was among the wallet providers affected; ZEC functionality within Cake Wallet was temporarily frozen during the upgrade window.

“Unlike contentious forks sometimes seen across the industry, this was a security response,” the Foundation wrote. “The issue was discovered, responsibly disclosed, confirmed, remediated, and resolved in a few days.”

The Foundation specifically thanked Hornby for the disclosure, Shielded Labs for supporting the independent security research, and ZODL engineers Hopwood, Nuttycombe, and Grigg for their remediation work. Arya Solhi of the Zcash Foundation was credited with developing the Zebra patches that enabled the network upgrade.

A Sensitive Moment for Zcash

The NU6.2 activation arrives during a particularly significant stretch for the Zcash ecosystem. The privacy coin has been one of the standout performers of 2026, with ZEC having rallied over 1,200% since its 2024 lows on the back of post-quantum security roadmaps, the closure of an SEC investigation, and Grayscale’s filing to convert its existing Zcash Trust into a U.S.-listed spot ETF — the first such filing for any privacy-focused cryptocurrency.

The Orchard pool itself, introduced with the NU5 network upgrade in May 2022, has grown rapidly to hold over 4.5 million ZEC. It is built on the Halo 2 proving system and was the first Zcash pool to eliminate the trusted setup requirement that had long been a criticism of the network’s older Sprout and Sapling pools. The Foundation described Orchard as “the centerpiece of Zcash’s privacy architecture.”

The successful NU6.2 activation now closes a significant security exposure in that infrastructure without any user funds lost, any privacy compromised, or any inflation of the ZEC supply. For an ecosystem positioning itself as a serious institutional privacy primitive—backed by an active ETF application, a post-quantum roadmap, and a recent treasury position of $36.69 million held by the Zcash Foundation—the demonstrated ability to respond to a critical bug within five days without exploitation is itself a meaningful signal.

The next major protocol milestone for Zcash remains the FCMP++ upgrade, which focuses on transaction throughput and privacy composability. With NU6.2 now in place, that roadmap can continue forward.

Also Read: Zcash Block Halt Rumor Debunked After Faulty Node Confusion

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Zcash (ZEC)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Trezor Breach Explodes as 67,000 More U.S Customers Are Exposed
Trezor Breach Explodes as 67,000 More U.S Customers Are Exposed
XRP Takes Over The Swamp in Ripple’s $5M Deal with Florida
XRP Takes Over The Swamp in Ripple’s $5M Deal with Florida
AMC CEO Adam Aron Demands Robinhood Stop Trading its Stock Tokens
AMC CEO Adam Aron Demands Robinhood Stop Trading its Stock Tokens
National Sheriffs’ Association Takes Neutral Position on CLARITY Act
National Sheriffs’ Association Takes Neutral Position on CLARITY Act
Bitcoin Price Prediction September 2026 Can BTC Reach $90K or Retest $72K
Bitcoin Price Prediction September 2026: Can BTC Reach $90K or Retest $72K?

Find Us on Socials

You may also like

a16z Crypto: Blockchains Must Go Beyond Throughput for Onchain Finance

a16z Crypto: Blockchains Must Go Beyond Throughput for Onchain Finance

Robinhood Chain Revenue Hits New All-Time High With $3.8M Daily Fee

Robinhood Chain Revenue Hits New All-Time High With $3.8M Daily Fee

ARK Invest and Glassnode logos displayed alongside a Bitcoin symbol

Bitcoin Leads Ethereum, Solana As ARK-Glassnode Map Decentralization

Grayscale Warns AI Could Raise Demand for Crypto Privacy 

Grayscale Warns AI Could Raise Demand for Crypto Privacy 

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information