Inside the Race to Fix Zcash's Shielded Pool Vulnerability | Markets Outlook artwork

Inside the Race to Fix Zcash's Shielded Pool Vulnerability | Markets Outlook

CoinDesk Podcast Network

June 11, 2026

The bug that tanked ZEC with Josh Swihart. On today's Markets Outlook, ZODL CEO Josh Swihart joins CoinDesk's Jennifer Sanasie to break down the Zcash vulnerability discovered with the help of AI, including how it was found, fixed, and what it means for the protocol's future.
Speakers: Josh Swihart, Jennifer Sanasie
**Josh Swihart** (0:00)
It was a master class in how to handle a security incident. And I think, and anybody that is working on a protocol or any software like this needs to have a very tight security process, needs to be auditing their code and hammering it with these AI tools.
Not just by like bug bounty programs where you have random people just looking to cash in, but people that really kind of understand the underlying protocol that can ask very targeted and specific questions.

**Jennifer Sanasie** (0:32)
Markets move fast, crypto moves faster. From the floor of the New York Stock Exchange, CoinDesk's Public Keys tracks the money, markets and moves shaping digital assets.
Josh Swihart, welcome to Markets Outlook.

**Josh Swihart** (1:06)
Good morning.

**Jennifer Sanasie** (1:07)
Good morning. I gotta say, I called you Josh Sweetheart at Consensus, and there was a pretty hilarious reaction to it online. So number one, I'm sorry for calling you Josh Sweetheart, but number two, I'm kind of happy I did, because we got an amazing meme out of it.

**Josh Swihart** (1:23)
Yeah, so I'll take that any day. People can call me Sweetheart any day.

**Jennifer Sanasie** (1:28)
I know, what a lovely thing for people to call you. All right, we're not here to talk about how much of a sweetheart you are. We're here to talk about Zcash.
Zcash has been in the headlines a lot over the past few weeks, over a bug that was found, a bug that had been there for about four years. AI was able to identify it. Take us back to when that happened and just lay a groundwork for us. What happened?

**Josh Swihart** (1:56)
Security researcher, Taylor Hornby, he was like the electric coin company, had a security for years, knows the protocol really well.
I would say it's like a combination of human and AI that found the bug. He's very good, he knows Zcash, he knows the underlying orchard circuit, and he was able to use tools where he had audited, lots of people had audited the code for years and years and years, had never noticed that this could be an issue. But with Opus 4.8, which had just come out that day or the day before, he was able to find an issue where theoretically, if an exploiter had found it or knew about it and knew how to exploit it, could have created additional Zcash in the Zcash Yield pool. So he notified my team. So I'm the CEO of Zcash Open Development Labs, ZODL, it's a former ECC team. It's the team that built Zcash to begin with, notified three members of our core team here. They remediated the issue, notified me, and then we went and coordinated a response, which included a soft fork about two days later, and then a hard fork another 24 hours after that to completely remediate the issue.

**Jennifer Sanasie** (3:26)
What's going through your head when you get this notification? Dear Lord.

**Josh Swihart** (3:33)
So I was sitting having a cup of coffee on my Saturday morning, and our head of research, Daria Emma, called me on Signal. Everything happens on Signal, right? So we have very tight security protocols in terms of who gets notified, when they get notified. So Daria read me in. But as per our protocol, I didn't need to know exactly where the bug was or what the bug was.
But I needed to know certain things about it in order to coordinate the response. So we limit again, who gets read in, who has information about it, how it works.
And so, yeah, it wasn't it, you just go into a mode of, okay, where do things sit today? What do we need to do? How do we get the proper response coordinated? In this case, we've got to work with minors and exchanges and people running nodes all around the world. So some folks in China, some people in New York in order to remediate it as quickly as we could. It was pretty amazing we remediated within the time that we did.

**Jennifer Sanasie** (4:48)
So the bug essentially could have allowed malicious actors to print Zcash in the shielded pool. Is there any way to know if that actually happened?

**Josh Swihart** (5:00)
No, there's no way to know if it actually happened. I think there's certain heuristics, there's certain patterns that you would see. So, generally, if somebody exploits a vulnerability, they'll sit on it quietly, they'll start to move money out in order because it's in their own best interest. They don't know who else may have exploited it or found an issue.
So we have something in Zcash called the turnstile, which limits the total supply. So it protects the total supply. And so, just gave theoretics, we would have seen a different kind of movement or different kind of activity, likely, if somebody had been able to exploit the vulnerability. But we haven't seen any such thing.

9 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000772256017