Zcash fixes critical vulnerability: previously threatened the security of over 25,000 ZEC, worth approximately 6.5 million dollars
The privacy coin Zcash recently disclosed and fixed a critical security vulnerability that could have been exploited by malicious miners to transfer over 25,000 ZEC (approximately 6.5 million USD) from the deprecated Sprout privacy pool. Security researcher Alex "Scalar" Sol disclosed on March 23 that the vulnerability stemmed from the zcashd node skipping proof verification when processing transactions involving the Sprout pool.
The official statement indicated that the vulnerability had existed since July 2020 but had not been actively exploited, and user funds remained safe at all times. The development team has released version 6.12.0 to complete the fix, and mainstream mining pools have completed the upgrade deployment within a few days. Additionally, the unaffected Zebra full node implementation has the capability to trigger a chain fork, providing extra protection in the event of exploitation.
It was disclosed that although the Sprout pool closed to new deposits in November 2020, approximately 25,424 ZEC remained untransferred. Even if the vulnerability were exploited, Zcash's "turnstile" mechanism would prevent inflationary issuance, ensuring that the total supply would not be breached. This vulnerability was discovered with the assistance of AI, and the researcher will receive a total bounty of 200 ZEC (approximately 51,000 USD). It is worth noting that this is not the first time Zcash has encountered a significant vulnerability; as early as 2019, it had fixed a serious flaw that could lead to unlimited issuance.
You may also like

The Exit Signal is Pricier Than the Entry Signal | Rewire News Morning Brief

Claude Code 500K Lines Code Leak Fully Organized, What's the True Core of the AI Agent?

Bitcoin Enters Bond Market, Moody's Provides First-Ever Rating for Global Cryptocurrency-Backed Bond

A Country Wagering 9% of Its GDP on Bitcoin

Analyzing Claude Code Source Code: Why is It Better Than Other AI Programming Tools?

Is the "Quantum Threat" Imminent, and How Much Time Does Bitcoin Have Left?

Morning News | Nasdaq will eliminate the 10% minimum float requirement next month; OpenFX completes $94 million financing; Coinbase establishes "Next Bets" internal venture capital program

A Detailed Explanation of Hyperliquid HIP-4: Infiltrating Traditional Finance through Prediction Markets and Options Trading
WEEX Poker Party: The First-Ever Crypto Trading Card Game—Trade, Play, and Win Real Rewards
Join WEEX Poker Party, the first interactive crypto trading card game. Trade to earn cards, trigger lucky buffs, build winning poker hands, and claim daily rewards from April 1–30, 2026. Start playing now!

Hong Kong dollar stablecoin does not need to become USDC

Chain games are defeated by reality, Web3 does not believe in dreams

Interpreting Aave V4: A Transformation from Product to "Bank"

Report on the Current Status of AI Payment Agreement Research: A New Paradigm of Payment in the Agent Economy

Really Can't Be Too Optimistic? Two Quantum Computing Papers on the Same Day Lower Bitcoin's Breakeven Barrier by Two Orders of Magnitude

Event Update | 2026 Hong Kong Web3 Carnival Peripheral Events Overview

Pentagon's Broker | Rewire News Evening Brief
Global Crypto Tax Trends in 2026: From Bitcoin ETFs to DeFi Compliance
Bitcoin's 2025 peak of $126K is gone, but your tax bill isn't. New IRS Form 1099-DA means no hiding trades. Discover 3 legal strategies to reduce liabilities and use WEEX's free tax tool to automate reporting.

