Mert Mumtaz & Illia Polosukhin: What Happened to Zcash (Full Explanation) artwork

Mert Mumtaz & Illia Polosukhin: What Happened to Zcash (Full Explanation)

The Rollup

June 6, 2026

Illia and Mert break down why the Zcash situation is a known ZK circuit trade-off and not the infinite mint catastrophe the market priced in, why Project Tachyon's formal verification is the most bullish upgrade in Zcash history, and why NEAR Intents generated $150K in a single volatile day, buying...
Speakers: Robbie, Illia Polosukhin, Mert Mumtaz, Andy
**Robbie** (0:00)
Illia, Mert, guys, welcome back.

**Illia Polosukhin** (0:03)
Hello, hey, hey.

**Robbie** (0:05)
Hello, hello, all right, we're not gonna bury the lead here.
I mistakenly, idiotically, some could say utterly stupidly, tweeted that the Zcash exploit is terrifying. Mert, why is this not an exploit? Why am I retarded? What actually happened here? And talk to us about, just kind of give us the explanation as long as you need to go, what happened?

**Mert Mumtaz** (0:34)
Sure, well, fundamentally, there's two groups of people here. One are the people who were aware that this was a risk with ZK-based privacy protocols, and then everybody else, right? And so I think you would probably fall into the latter. But I had, like, the way to think about this is that with any privacy protocol that employs ZK-circuits, but not necessarily even ZK-circuits, just different types of math, for example, Monero has similar issues, although they're a different class, but counterfeiting all the same.
And Bitcoin actually has had a similar issue in the past as well. The main difference here is, of course, it's much harder to detect if you have a fully private pool, right? And so really the only way you can detect a supply issue is by having these things called turnstiles, which count the net difference between what goes in versus what goes out. So obviously, if there's structure in such a way that you can't have more than what went in, go out, right? So it's supply control in that sense.
Now, this is not new information to Zcash people and a fair amount of investors, I would say, especially ones who've been around for some time. Like even like four months ago, six months ago, eight months ago a year, I always have the same debate on Twitter with Bitcoin people about like, well, Bitcoin would never do this because they care about the audibility of the supply. I'm like, well, that is a soluble problem with things like formal verification and better audits and just making the arithmetic for ZK circuits simpler. So it's always this back and forth. So this is a pretty well-known trade-off on the risk spectrum. The problem, of course, is that a lot of the new people were not aware of this risk. And this was made worse by two things. One is that people tweeted that, well, actually somebody just vibe-coded an exploit with AI, which is, of course, not what happened. What happened is it was a highly technical and highly domain-knowledgeable auditor who knows Zcash better than almost anybody in the world.
And he was explicitly tasked to helping patch bugs if he found anything of this sort. So that's what happened. It wasn't like a, because like other people would have already found it by then, including other cryptographers who are world-class, who already work on Zcash, right? And then the other one, of course, is that the price went down a ton. Now there's a few reasons for this. One is that there was a network upgrade which made it such that some people actually, like Binance, for example, disabled deposits, which kind of delayed the price movement, right? When everything nuked like yesterday or the day before in the crypto markets, Zcash didn't because it literally couldn't.
But then now you combine that with the huge sell-off of the market today, right? Like QQQ, I believe, Nasdaq is down the most it's been since April 2025, right? So there's like a huge sell-off and panic everywhere. You combine all of them and then obviously it was the only coin that was still really up and it's just really fun to beat down in that case, right? And so you kind of have this mass hysteria and then it just keeps piling on and on and on. And so that's kind of where we are today.

**Robbie** (4:05)
Okay, so people were saying there's infinite supply in a shielded pool and somebody was tea whopping out every time this asset was trading around the $600, $700 mark that there was just like this supply that was just infinite, that was always hitting the market. From what I understand, do we even know if there was, if there is this double spend bug or do we need to wait for the next upgrade to know?

**Mert Mumtaz** (4:34)
Right, so it just depends on like your...
It really just depends on what kind of risk spectrum you're looking for, right? So if you want full verifiability and full trustlessness, like I want to know this for myself, I'm not going to trust anybody, then you would have to wait until the next upgrade, which I think actually they will release some communications on it in a few hours, so it should be pretty soon. In which case, basically what will happen is the funds from the old pool will go to the new pool as people withdraw and deposit, and then if there was an exploit, you would know because the turnstile would explicitly flag it. Now, some other people, including myself, make the game theoretical argument that, look, if you look at the trend of the shielded supply, so for example, somebody said that, well, somebody has been minting an infinite amount of notes in the shielded pool and then paying off all the KOLs who then do the marketing.

28 more minutes of transcript below

Feed this to your agent

Try it now โ€” copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000771407843