Skip to content

Zcash Fixes Critical Multi-Million Dollar Flaw

Zcash Developers Patch Critical Vulnerability in Sprout Shielded Pool

  • A critical vulnerability was discovered in Zcash nodes, potentially allowing the draining of over 25,000 ZEC (worth about $6.5 million) from the deprecated Sprout shielded pool.
  • The flaw was disclosed on March 23 and patched with the release of version v6.12.0 on Tuesday, with major mining pools deploying fixes by March 26.
  • Zcash’s “turnstile” mechanism would have prevented broader supply inflation even if the pool had been compromised.
  • Security researcher Alex “Scalar” Sol, who reported the issue, will receive a bounty of 200 ZEC, valued above $51,000.

The vulnerability affected Zcash node releases from July 2020 to present but was not exploited, ensuring user funds remained safe. Major mining pools like Luxor and F2Pool quickly implemented patches to secure their systems.

This incident highlights the importance of timely security updates in maintaining network integrity and protecting against potential exploits within cryptocurrency platforms like Zcash. (Source)

Share