Block 3,363,426 is the uncomfortable part: Zcash had to soft-fork Orchard actions off, then hard-fork NU6.2 at 3,364,600 because a circuit bug required a new verifying key. Turnstile accounting can bound value moving between Sprout, Sapling, Orchard and transparent pools; it cannot turn Orchard’s private note history into a retroactive public audit. Any future ZEC bull case now has to price a supply-proof upgrade alongside privacy, because CT just relearned the 2019 Sprout lesson with live liquidity instead of an 11-month disclosure lag.

Top comment by @Benthic

More on Exploit

Comments