Cautious Thorchain update compounds ZCash woes as vulnerability headache grows

- THORChain remains paused weeks after a $10.7 million exploit as developers verify vault security before restarting,
- A separate critical vulnerability in Zcash’s Orchard shielded pool has forced THORChain to delay its planned ZEC integration.
- ZEC fell roughly 40% after the Orchard flaw was disclosed, prompting Arthur Hayes to dump his entire position.
THORChain has remained offline for three weeks since it experienced a $10.7 million vault exploit.
THORChain initially planned to integrate ZEC support into its platform, but even that is now delayed after a critical flaw was discovered in Zcash’s Orchard shielded pool. That decision could not have come at a worse time for ZEC, which has taken a beating since the AI–discovered vulnerability was revealed.
What happened to THORChain and when will it restart?
THORChain has been offline for three weeks following a major security breach that resulted in the loss of $10.7 million from one of its vaults.
The problem at THORChain started with a flaw in a security system called the GG20 threshold signature scheme. An attacker was able to join the network as a node operator and exploit this weakness to drain funds from a single vault. The other four vaults were not affected.
THORChain’s developers released a fix (version 3.19) several days ago, but the network is yet to resume normal operations.
The team even added a new safety step called “key verify” to ensure every remaining vault is secure before operations resume. The restarting process will include node operators moving to the new software version, migrating funds, and finally reopening trading. Barraford estimated that this process will take several days to complete once it begins.
The recovery plan, called ADR028, aims to cover the $10.7 million loss without creating new RUNE tokens or diluting existing holders. Instead, the protocol’s own money will be used, and any remaining loss will be shared with synthetic asset holders. The protocol is also offering the hacker a bounty to return the funds.
What was the Zcash bug, and why did it cause such a big price drop?
Zcash was supposed to be THORChain’s next chain integration, ahead of Monero, but that timeline slipped after security researcher Taylor Hornby, working under contract with Shielded Labs, discovered a soundness bug in Zcash’s Orchard shielded pool.
The bug has been present in the Orchard protocol “rulebook” since it launched in May 2022. Hornby used Anthropic’s Opus 4.8 model to create a working example of the exploit in a test environment and confirmed it could produce fake tokens in a local test environment.
An emergency soft fork quickly temporarily disabled Orchard transactions on June 2, and a hard fork (NU6.2) reactivated the pool with a corrected circuit on June 3. The five-day turnaround from discovery to resolution was only the second security-driven protocol upgrade in Zcash’s ten-year history.
When the bug was disclosed, ZEC dropped roughly 40% within 24 hours. CoinMarketCap data showed the token trading near $333, down from a 52-week high above $700.
Arthur Hayes, the chief investment officer at Maelstrom and co-founder of BitMEX, said on X that he liquidated his entire ZEC position. Hayes previously set a public price target of 10% of Bitcoin’s value for ZEC, but the 30% drop forced him to rethink.
He left open the possibility of buying back the tokens if his concerns about supply integrity proved unfounded.
Blockchain intelligence firm Arkham flagged at least one large holder who watched more than half the value of a $174 million ZEC position evaporate without selling.
Shielded Labs, the organization that fixed the bug, explained that it is cryptographically impossible to determine whether or not the bug was ever used due to the four-year window before it was found, but the firm also stated that it is unlikely the bug could have evaded years of expert review if it was active.
Just discovering the vulnerability required AI-assisted auditing techniques, and the remediation window was narrow once the flaw became known.
The smartest crypto minds already read our newsletter. Want in? Join them.
FAQs
What is the Zcash Orchard vulnerability?
A soundness bug in the Orchard zero-knowledge proof circuit, present since May 2022, could have allowed an attacker to forge transactions and create unlimited counterfeit ZEC inside the shielded pool. The flaw was discovered on May 29, 2026 and patched through an emergency hard fork by June 3.
Why is THORChain still offline?
THORChain halted after a $10.7 million vault exploit on May 15, 2026. The team patched the original flaw but is running additional vault verification steps before restarting, with developer Chad Barraford stating the priority is correctness over speed.
Did anyone exploit the Zcash bug before it was fixed?
Shielded Labs said there is no evidence of exploitation on mainnet, but because Orchard's privacy features prevent full transaction tracing, it cannot be cryptographically proven that no counterfeit ZEC was created during the four-year window the bug existed.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
CRASH COURSE
- Which cryptocurrencies can make you money
- How to boost your security with a wallet (and which ones are actually worth using)
- Little-known investment strategies that the pros use
- How to get started investing in crypto (which exchanges to use, the best crypto to buy etc)















