**David Canellis** (0:00)
It is Friday, June the 5th. I'm your host David Canellis, and this is The Breakdown. We're getting you ready for the weekend ahead with some quick stories. We're looking at this brutal Zcash crash around this orchid-related vulnerability that would have seen infinite supply be minted. Where we take a look at the aftermath and the disclosure of this particular bug, and if there is any risk moving forward. We're also going to be looking at, again, a Polymarket drama around a market for whether MicroStrategy was going to sell Bitcoin before the end of May, which it did, but apparently Polymarket says, no, it didn't. We're going to be taking a look at why that might be and what the crowd reaction is to such a ruling. And yeah, we're also going to be quick, briefly look at ETF flows to get an update on those amid an ongoing correction in the wider crypto space. So without further ado, this is The Breakdown. Let's get to it.
This podcast is for informational purposes only, and any views expressed by anyone on the show are opinions, not financial advice. Hosts and guests may hold positions in the company's funds or projects discussed. Alright, so first we're going to jump into this Zcash stuff. So I have the chart of Zcash against hype, Bitcoin, Ether and Sol over the past year. And as you can see, a huge drop in the price of Zcash very recently, over the past three days. Effectively, over the past year, Zcash was up 1,000%.
And after about a 50% retracement, over a few days, we're looking at Zcash only up around 500%. So still massively outperforming the other majors. But this gives you an indication of how serious the market response has been to this particular bug, which we're going to get into in a minute. But of course, there's also a big widespread correction happening across Bitcoin, Ether and so on. So, you know, it's all bundled together that there is this kind of crash in the price of Bitcoin and that's flowing on into alts. But clearly this bug has exacerbated the downturn for Zcash.
And actually, like I have some numbers here, like this is actually the seventh worst one day drop in Zcash's history, which spans back 10 years now, nearly 10 years. It dropped 30%, 29% in one day. Three day losses are almost 47%, which, I mean, this is the worst since, it's worse than COVID. It's worse than even the May 2021 wipeout around terror. So it's pretty bad for Zcash.
It's not quite as bad as the crashes when it was first listed in November 2016 But in terms of like, in terms of post price discovery since Zcash first launch, this is about the worst correction in Zcash's history. So why is it down? Let's take a look. So I'm piecing this timeline together because originally, the way that this bug was communicated was that there was a critical soundness vulnerability in the Orchid zero-knowledge proof circuit. And for those unfamiliar, what Orchid is, is the Zcash privacy pool that, that you can have shielded transactions and shielded balances within this Orchid pool. So there was a bug in this. And essentially what the bug entailed was that the circuit could be tricked into accepting invalid transactions as legitimate. And in the initial blog released by the Zcash Foundation on June the 3rd, so on Wednesday, it explained that in a protocol like Zcash, soundness means the system should only accept valid transactions and state transitions.
A soundness vulnerability is one that could allow the system to accept something it should reject. In this case, successful exploitation could have allowed the Orchid pool to accept invalid state transitions, potentially permitting double spending of funds within Orchid, though with no ability to inflate the total Zcash supply, which is protected by Zcash's turnstile mechanism. So it's essentially a double spending bug that an attacker, if they understood exactly how to exploit this vulnerability, they could have told the Zcash chain that they had access to more tokens than what they actually did. And considering how the bug works, the chain would just accept that as a normal transaction and process it and give the attacker whatever supply that they would say that they had. This wording in particular that there was no ability to inflate the total Zec supply is somewhat interesting. I'm just gonna pull up the chart here for Zcash and we can see that on the 3rd of June, there was no real market response to this bug being disclosed. It only began tanking at midnight on June the 4th, and then we saw a huge crash downward. And I just would point out that Bitcoin had already started its downward trajectory, its most recent connection, its most recent correction below 70K, days before this as well. So Bitcoin was already on its way down, but even with the disclosure of this bug as worded by the Zcash Foundation, Zcash had remained somewhat steady. It was only when a follow-up blog, a follow-up post in the Zcash community by Zcash founder Zuko Wilcox, that explained and elaborated on the seriousness of the vulnerability, that we saw a much bigger correction in Zcash start to occur, and with good reason. And as we can see here, this is what Zuko posted along with Jason McGee and Taylor Hornby. After reviewing Taylor's report and discussing the implications of the vulnerability internally, Shielded Labs believes it is important to provide additional context. The vulnerability could have been exploited to undetectably create an unlimited amount of counterfeit ZEC within Orchard. Because of the privacy properties of Orchard, there is no way to cryptographically prove whether the vulnerability was exploited before it was remediated. However, an upgrade can be deployed to protect users and prove the integrity of the Zcash supply. So this original wording here was not correct. The original wording that there was no ability to inflate the total ZEC supply, that turned out to be not true. And in the aftermath of the Zutro post on the Zcash forums, in the aftermath of that, we saw the massive correction really start to take shape in Zcash. I'm not too sure why the bug was initially framed as being not so damaging, and then it took 24 hours or whatever in order to correct the record. But it's clear that the market absolutely responded to the new information as framed by Zutro and Jason and Taylor. So I'm not too sure if there was just wires crossed or what have you, but it's clear that there was not outsized dumping. But it's here like seeing the strength of the price of Zcash in the lead up to the disclosure of exactly how bad this bug was. It's not like there was a bunch of people dumping their Zcash before the true impact of the vulnerability could be made public. That doesn't really appear to be the case, but the downward pressure from people seeing that it might have been possible that there was counterfeit ZEC minted, and we can't track that right now. That seems to be the impetus for the price of Zcash to go down. Now, I am inclined to give the Zcash team the benefit of the doubt, even though it might not be the most pragmatic way of going through investing in the crypto space to just trust what people tell you about things. And it's very difficult because, I mean, we've all faced this problem getting into crypto, is that it's part finance, it's part computer science. And if you're not a computer scientist or if you're not really attuned to finance lingo or finance concepts, it's very hard to navigate that yourself relying on your own research and your own intellect. And it does come down to listening to people with very highly specialized education and experience in order to understand what the implications are for any of this. So that said, this is from Craig Sam, Chief Legal Officer at Grayscale. He tweets, from a non-technical perspective, to believe this vulnerability was actually exploited before being patched, you'd have to believe someone, one, was looking at the Zcash code base more thoroughly than any of the ECC, Zottel, Shielded Labs, Zcash Foundation, and other core Zcash dev and security contributors combined, and two, resisted the urge to completely run out of the oracle pull turnstile to sell all its counterfeited Zcash during a historical 20X plus bull run seems unlikely to me. In my opinion, the real takeaway here is that the Zcash dev and security community is absolutely best in class and head of every other protocol in terms of AI risk and so on. He brings up the AI risk in that the security researcher that found the bug and disclosed it to the Zcash Foundation used AI tooling or used Opus to understand the bug and really like tested out it and kind of prove that it's real. But I mean, what is still worrying is that the bug existed since Orchard had been activated in May 2022, right up until the time of the emergency fix, which was on June 1, 2026 So about four years, this bug existed that we just don't know whether it was exploited or what the true supply of the Zcash currency is right now. I mean, they are touting that there is a network upgrade that will, a future network upgrade that will be able to be implemented, that we could effectively tally the, that we could gauge the integrity of the Zcash suppliers as Craig Sam puts it. So TBD on that until then, we basically have to trust that the exploit was not exploited.
13 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000771320375