A critical vulnerability in Zcash's Orchard privacy pool allowed attackers to bypass transaction input validation checks, enabling the generation of ZEC from nothing through fraudulent zero-knowledge proofs. The flaw originated from a check that failed to enforce its intended validation rules.
| Vendor | Product | Versions |
|---|---|---|
| zcash | orchard privacy pool | — |