Zcash Team Reveals It Fixed a Catastrophic Coin Counterfeiting Bug

The company behind the privacy-minded cryptocurrency zcash said Tuesday that it moved last year to fix a catastrophic bug that could have been used to print infinite coins.

AccessTimeIconFeb 5, 2019 at 8:06 p.m. UTC
Updated Sep 13, 2021 at 8:52 a.m. UTC

The company behind the privacy-minded cryptocurrency zcash has revealed that it fixed a catastrophic code bug last year that could have been used to print infinite coins.

According to a report published Tuesday, zcash cryptographer Ariel Gabizon discovered a "subtle" bug a little less than a year ago in zk-SNARKS, the bleeding-edge cryptography the cryptocurrency uses to shield balances and user identities, which are implemented so that outsiders can't see financial information users want kept to themselves.

Once the zcash team found out about the bug, they kept it quiet and pulled together a fix, which they then added to zcash's large Sapling upgrade, which was executed October last year. Today, though, is the first time the company has revealed it to the larger public.

If exploited, an attacker would have been able to print an infinite amount of zcash tokens.

The blog post, written by zcash marketing director Josh Swihart, director of product security Benjamin Winston, and engineer Sean Bowe, explained:

"Prior to its remediation, an attacker could have created fake Zcash without being detected. The counterfeiting vulnerability has been fully remediated in Zcash and no action is required by Zcash users."

Because zk-SNARKs are so bleeding-edge, some have criticized zcash for using the technology so early on. (It's so early stage that zcash is the largest implementation that uses the cryptography so far.) Plus, due to the nature of the privacy technology, which shields data, it's difficult to know for sure whether tokens have been counterfeited.

Still, the team added that they don't think zcash was at risk of the counterfeiting bug for a number of reasons, including "discovery of the vulnerability would have required a high level of technical and cryptographic sophistication that very few people possess."

And indeed, some have applauded the team's handling of the bug – including famed NSA whistleblower Edward Snowden.

"A lot of people wonder why I like #Zcash despite the Founder's Reward. Here's a reason: that tax funds a quality team that catches and kills serious bugs in-house, before they get exploited," he tweeted. "Some other projects learn about bugs like this only AFTER people have lost money."

Zcash image via Shutterstock


Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.