Zcash Team Reveals It Fixed a Catastrophic Coin Counterfeiting Bug

The company behind the privacy-minded cryptocurrency zcash said Tuesday that it moved last year to fix a catastrophic bug that could have been used to print infinite coins.

AccessTimeIconFeb 5, 2019 at 8:06 p.m. UTC
Updated Sep 13, 2021 at 8:52 a.m. UTC

The company behind the privacy-minded cryptocurrency zcash has revealed that it fixed a catastrophic code bug last year that could have been used to print infinite coins.

According to a report published Tuesday, zcash cryptographer Ariel Gabizon discovered a "subtle" bug a little less than a year ago in zk-SNARKS, the bleeding-edge cryptography the cryptocurrency uses to shield balances and user identities, which are implemented so that outsiders can't see financial information users want kept to themselves.

Once the zcash team found out about the bug, they kept it quiet and pulled together a fix, which they then added to zcash's large Sapling upgrade, which was executed October last year. Today, though, is the first time the company has revealed it to the larger public.

If exploited, an attacker would have been able to print an infinite amount of zcash tokens.

The blog post, written by zcash marketing director Josh Swihart, director of product security Benjamin Winston, and engineer Sean Bowe, explained:

"Prior to its remediation, an attacker could have created fake Zcash without being detected. The counterfeiting vulnerability has been fully remediated in Zcash and no action is required by Zcash users."

Because zk-SNARKs are so bleeding-edge, some have criticized zcash for using the technology so early on. (It's so early stage that zcash is the largest implementation that uses the cryptography so far.) Plus, due to the nature of the privacy technology, which shields data, it's difficult to know for sure whether tokens have been counterfeited.

Still, the team added that they don't think zcash was at risk of the counterfeiting bug for a number of reasons, including "discovery of the vulnerability would have required a high level of technical and cryptographic sophistication that very few people possess."

And indeed, some have applauded the team's handling of the bug – including famed NSA whistleblower Edward Snowden.

"A lot of people wonder why I like #Zcash despite the Founder's Reward. Here's a reason: that tax funds a quality team that catches and kills serious bugs in-house, before they get exploited," he tweeted. "Some other projects learn about bugs like this only AFTER people have lost money."

Zcash image via Shutterstock


Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.

Learn more about Consensus 2024, CoinDesk’s longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.