{"id":30579,"date":"2026-06-03T11:58:36","date_gmt":"2026-06-03T11:58:36","guid":{"rendered":"https:\/\/bitunikey.com\/news\/zcash-foundation-fixes-orchard-bug-with-zebra-emergency-upgrade\/"},"modified":"2026-06-03T11:58:40","modified_gmt":"2026-06-03T11:58:40","slug":"zcash-foundation-fixes-orchard-bug-with-zebra-emergency-upgrade","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/zcash-foundation-fixes-orchard-bug-with-zebra-emergency-upgrade\/","title":{"rendered":"Zcash Foundation fixes Orchard bug with Zebra emergency upgrade"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">Zcash Foundation released Zebra 4.5.3 and Zebra 5.0.0 after engineers found and fixed a critical soundness bug in the Orchard Action circuit.<\/p>\n<div id=\"cn-block-summary-block_1511e3cb870cc1c8a78f70071ab0af29\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Zcash Foundation fixed an Orchard circuit bug before known exploitation and urged urgent Zebra upgrades.<\/li>\n<li>Zebra 4.5.3 disabled Orchard actions, while 5.0.0 re-enabled them through NU6.2 at mainnet height 3,364,600.<\/li>\n<li>Zcash said no unauthorized value appeared, and Sapling plus transparent transactions kept working normally during incident.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>The foundation <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/zfnd.org\/zebra-4-5-3-and-5-0-0-emergency-soft-fork-and-nu6-2-activation\/\" target=\"_blank\" rel=\"nofollow\">said<\/a> Zebra 4.5.3 activated an emergency soft fork at mainnet block height 3,363,426. The release temporarily rejected transactions and blocks containing Orchard actions while engineers prepared a corrected circuit.<\/p>\n<p>The soft fork went live at about 02:00 UTC on June 2 after an earlier coordination attempt faced patch deployment issues. The foundation said private coordination with miners and exchanges started on May 31 to reduce the chance of exploitation before public disclosure.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\"><strong>NU6.2 restores shielded transactions<\/strong><\/h2>\n<p>Zebra 5.0.0 activated the NU6.2 hard fork at mainnet block height 3,364,600. The upgrade re-enabled Orchard actions with a corrected circuit and routed Orchard proofs to a new per-circuit verifying key. The release also marked the second security-driven protocol upgrade in Zcash history since 2016.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Zebra 4.5.3 and 5.0.0: Emergency Soft Fork and NU6.2 Activation <\/p>\n<p>\ud83d\udea8 Zebra 5.0.0 is out \u2013 all node operators should upgrade now.<\/p>\n<p>\u26a1 NU6.2 activated, re-enabling Orchard with a corrected circuit.<\/p>\n<p>\ud83d\udd12 Total ZEC supply confirmed intact throughout. <\/p>\n<p>Read the full update:\u2026<\/p>\n<p>\u2014 Zcash Foundation \ud83d\udee1\ufe0f (@ZcashFoundation) <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/ZcashFoundation\/status\/2062127221418991847?ref_src=twsrc%5Etfw\">June 3, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>A hard fork was needed because a zero-knowledge proof circuit fix requires a new pinned verifying key.\u00a0<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cWe strongly urge all node operators to upgrade to Zebra 5.0.0 as soon as possible,\u201d Zcash Foundation said.<\/p>\n<\/blockquote>\n<h2 class=\"wp-block-heading\"><strong>No known exploit found<\/strong><\/h2>\n<p>The bug was discovered on May 29 by independent security researcher Taylor Hornby during a protocol audit for Shielded Labs. ZODL engineers Daira-Emma Hopwood, Kris Nuttycombe and Jack Grigg confirmed the issue within hours and began work on a fix.<\/p>\n<p>The foundation said the flaw could have allowed invalid state changes inside Orchard and possible double spending within that pool. It also said Zcash\u2019s turnstile mechanism protected total ZEC supply, and \u201cThere is no evidence of unauthorized value creation.\u201d The affected code included older halo2_gadgets, orchard and zcash_primitives releases, plus zcashd versions 5.0.0 through 6.12.3.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Why Orchard remains important<\/strong><\/h2>\n<p>Orchard is Zcash\u2019s newest shielded pool and a core part of its privacy system. It launched with NU5 in 2022 and uses Halo 2, which removed the need for a trusted setup. That design made Orchard a key part of Zcash\u2019s current privacy roadmap.<\/p>\n<p>Related market coverage has recently focused on rising Zcash shielded use. A recent report said about 30% of ZEC supply had moved into shielded pools, with Orchard holding 4.2 million ZEC and most of the recent growth.<\/p>\n<p>The foundation said user privacy was not harmed during the incident. Sapling and transparent transactions also continued operating normally while Orchard actions remained paused.<\/p>\n<p>Node operators now face the main task of upgrading to Zebra 5.0.0, rather than relying on older releases. Operators that stayed on an incorrect fork after NU6.2 may need to resync from scratch or restore from a backup made before activation.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Zcash Foundation released Zebra 4.5.3 and Zebra 5.0.0 after engineers found and fixed a critical soundness bug in the Orchard Action circuit. Summary Zcash Foundation fixed an Orchard circuit bug&hellip;<\/p>\n","protected":false},"author":1,"featured_media":29602,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-30579","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/30579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=30579"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/30579\/revisions"}],"predecessor-version":[{"id":30580,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/30579\/revisions\/30580"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/29602"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=30579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=30579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=30579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}