I stumbled across this tweet claiming the recently found bug was known as early as 2016, months before Zcash was even launched.
Here’s the issue on GitHub:
opened 01:03AM - 23 Feb 16 UTC
closed 12:00AM - 01 Apr 16 UTC
C-bug
I-SECURITY
A-crypto
A-consensus
A-circuit
in 1.0
special to Daira
special to Nathan
protocol spec
Zerocash paper
I think I found an attack that would let an attacker create as much money as the… y want for themselves at the cost of finding 128-bit hash collisions.
**Background:** A coin is a tuple (a<sub>pk</sub>, v, ρ, r). The coin commitment CoinCommitment((a<sub>pk</sub>, v, ρ, r)) is computed as:
> InternalH = Leading128(CRH(a<sub>pk</sub> || ρ))
> k = CRH(r || InternalH)
> cm = CRH(v || k)
The truncation of InternalH is done to make the commitment statistically-hiding, i.e no matter how much computational resources I have, I can't find out what v or a<sub>pk</sub> are.
**Attack:** Because InternalH is only 128 bits, in 2^64 operations I can find some ρ != ρ' such that:
> Leading128(CRH(a<sub>pk</sub> || ρ)) = Leading128(CRH(a<sub>pk</sub> || ρ'))
And therefore:
> CoinCommitment((a<sub>pk</sub>, v, ρ, r)) = CoinCommitment((a<sub>pk</sub>, v, ρ', r))
To carry out a double-spend attack I first acquire some real Zcash (e.g. by buying it with USD), and then double spend it to myself as follows. Ignoring the faerie gold fix, I create a new coin for myself, but as I do so I make sure to find a collision (a<sub>pk</sub>, v, ρ, r) and (a<sub>pk</sub>, v, ρ', r) where ρ != ρ'. By completeness of the protocol, I'll be able to spend the (a<sub>pk</sub>, v, ρ, r) coin, and so that's what I do. This will reveal the serial number PRF<sup>sn</sup><sub>a<sub>sk</sub></sub>(ρ). After that first spend has made it on to the ledger, as far as I can see, nothing prevents me from spending that coin _again_, using ρ', because:
- I can still give a path from the root to CoinCommitment((a<sub>pk</sub>, v, ρ', r)), namely the same path as I gave in the first spend (and because of the zero-knowledge property nobody will know the path is the same).
- With high probability PRF<sup>sn</sup><sub>a<sub>sk</sub></sub>(ρ') is not equal to PRF<sup>sn</sup><sub>a<sub>sk</sub></sub>(ρ), and I can obviously still prove I computed PRF<sup>sn</sup><sub>a<sub>sk</sub></sub>(ρ') correctly inside the pour.
- I can still satisfy spend authority (I know a<sub>sk</sub> for the a<sub>pk</sub> I used).
- I have to use the same r (old) for both spends (otherwise the commitments won't collide), but again because of the zero-knowledge property I don't think anyone (except for me, the holder of a<sub>sk</sub>) can tell it's been reused.
After the faerie gold fix, I'm forced to find colliding ρ by altering h<sub>sig</sub>, and I'm forced to commit to either ρ or ρ' because h<sub>sig</sub> gets published. This doesn't prevent the attack, since when I go to spend for the second time it is not going to be noticed that ρ' doesn't match the old h<sub>sig</sub>, at least not according to the current protocol.
**Fix:** Maybe CoinCommitment needs to be collision-resistant? Or maybe we should re-use h<sub>sig</sub> as a commitment to ρ and check it when I try to spend with ρ?
Feel free to add more such coping clown claims to this thread for the sake of dispelling false rumours with evidence.
2 Likes
Can we attribute this to the double top pattern that was forming at the time, or is it too excessive?
Allium Labs reports Zcash futures volume surged 12-13x before a critical privacy bug disclosure, with five wallets shorting $72M and profiting $3.43M.
Est. reading time: 2 minutes
Shawn
September 11, 2026, 11:55pm
5
That kind of attack, as well as the Fairy Gold attack were all addressed before Zcashs mainnet launch.
Shawn:
Fairy Gold attack
What’s the fairy gold attack? And I was pretty much sarcastic.
Could you define “pretty much sarcastic” for me in this context?
It was sort of a version of reductio ad absurdum, as in “conspiracy theory? hell yeah, this is definitely a conspiracy theory, and this is why even if it was a conspiracy theory, it’d still be safe”
I would like to apologise if it didn’t sit right with anyone, autistic issues, I will remove it then.
Here’s my counter-conspiracy: It should be clear that antisemitism is like fertile soil to Zionism, not its enemy. Therefor, concerted efforts to spread the notion of some “Jewish plot” are most likely to originate from a Unit 8200 troll farm, while being directed at something that poses a threat to Zionism. You think it’s a coincidence that Memenero/Manuro and Mossad both start with mo ?
Maybe… may be.
Even though I may or may not agree with you (maybe I do?), I do not believe this forum is the appropriate place for posts like this, as it may make others feel excluded. You are entitled to your opinions, but please do not post charged opinions related to a specific religion here.
On the other hand, bashing Epstein is fine and encouraged.
I am not. Read it again.
…unless you think that Zionism is a religion.
You see, the people who will inevitably object to this… do not read.
That’s no reason to falsely accuse me.
Dude, you know the whole Zionism/Jewish/Torah thing is controversial from like 1800s. Just… don’t bring it up here. Try Quora or Re- nah, Quora is fine.
What’s that slash doing between Zionism and Judaism?
I was referring to the “Zionism is Judaism!” and “Zionism is not Judaism but a separate movement!” debate. Shorthand.
I’m not debating anything.