Hello Zcashers,
Submitted a retroactive grant application to the Coinholder Retroactive Grants Program for the vulnerability disclosures across zcashd and zebra in March–April 2026: a temporary detectable unlimited mint-and-sell exploit.
GitHub issue: Retroactive Grant Application - Temporary Detectable Unlimited mint and sell Exploit
Requested amount: $400,000.
Not a cost reimbursement, direct costs were about $30,000 in API spend (shame on me, I know)
Prior funding: 600 ZEC, itemised in the application. No other compensation, no employment or contractor relationship with any Zcash organization.
On March 23 I reported that zcashd had been skipping Sprout proof verification since July 2020, accepting invalid Sprout spends. Multiple further vulnerabilities followed across zebra and zcashd from March to April, detailed in the application.
Chained together: split consensus, crash Zebra nodes, disable turnstile accounting, then mint through the verification bypass. Enabling a temporary detectable unlimited mint-and-sell of counterfeit ZEC.
Full application below.
Application Owners
@alexs-scalar
Individual Name
Alex Sol
Additional Team Members
None
How did you learn about the Lockbox: Coinholder Retroactive Grants Program?
Following discussions with Shielded Labs about compensation for these findings, and ZCG’s decision on additional funding, Shielded Labs suggested that this retroactive grants program was the right venue to bring the question to the community.
Requested Grant Amount (USD)
$400,000
Category
Research & Development
Project Summary
I’m requesting a retroactive bounty for multiple vulnerabilities I found and responsibly disclosed across Zcash’s two node implementations, zcashd and zebra nodes
The Sprout proof-verification bypass (live since 2020) lets a miner slip invalid Sprout spends past zcashd. The duplicate-header bug disables ZIP 209 turnstile enforcement. And the consensus-divergence and node-crash findings take Zebra.. Composed, is an exploit to temporary detectable unlimited mint-and-sell of counterfeit ZEC (likely few hours windows)
Project Description
At the end of February 2026 I began auditing several privacy coin protocols, looking for critical vulnerabilities and mainly for inflation bugs.
That work turned up findings in Grin, in Litecoin’s MWEB (found independently, a few hours after the LTC devs), and in a few other projects that were quietly patched and never disclosed to their community.
Then I decided to take a shot at Zcash ![]()
Between March and April, I found and privately disclosed multiple vulnerabilities to Shielded Labs
zcashd
| Finding | Impact |
|---|---|
| Sprout proof verification skipped | Invalid Sprout spends accepted; present since July 2020 |
Identity rk in Orchard actions |
Crashes zcashd during proof verification |
Identity epk |
Spec requires a non-identity point; Zebra enforced it, zcashd did not. Consensus split |
| Duplicate block header | Silently resets pool balance tracking, disabling ZIP 209 turnstile enforcement |
The Sprout bug came first; the other followed in the same codebase over the following days.
Zebra
| Advisory | CVE |
|---|---|
| Consensus Failure via Crafted V5 Authorization Data | CVE-2026-34377 |
| Consensus Divergence in Transparent Sighash Hash-Type Handling (credit to @sangsoo-osec as well) | CVE-2026-41583 |
| rk Identity Point Panic in Transaction Verification | CVE-2026-41584 |
Composed together, this leads to a chained critical exploits:
- split consensus between Zebra and zcashd
- use the identity
rkpanic to knock out Zebra nodes - spray duplicate headers vuln to disable turnstile enforcement on nodes
- use the sprout verification bypass to temporary mint and withdraw from the sprout pool unlimited zec and sell it. Hypothetically could have lasted during few hours before the network could respond i believe so.
On the requested amount. My benchmark is the worst case these findings put on the table: temporary unlimited mint-and-sell of counterfeit ZEC. And hypothetically +10m to +100m in damage. We will never know, defender got it first!
Technical Approach
Manual code review, backed by heavy testing and assisted by AI. The target was the critical consensus path:
- Proof verification: the checks that a shielded spend is actually valid.
- Sighash construction: how the signed message is computed, where a small difference between implementations becomes a consensus split.
- Pool balance accounting: the ZIP 209 turnstiles, which are the only supply-visibility a shielded chain has left.
- Shared cryptographic libraries:
librustzcashand the primitives underneath both nodes, where one bug reaches zcashd and Zebra at once.
Also prompt such as:
(claude) find inflations bug, make no mistakes
Time Period of Work Completion
March 2026 to May 2026
Total Budget (USD)
$30,000 to $40,000
Budget Breakdown
- Technology/Software:
- $30,000
- OpenAI API and Claude spend for AI-assisted source review across the audit period (shame on me). Approximate, pending retrieval of the itemised bills. Covers all audits in this period, not Zcash alone.
Previous Funding Details
ZCG, matching other Funding Sources
| Received (UTC) | Amount (ZEC) | Price at receipt | Notional at receipt |
|---|---|---|---|
| 2026-04-24 2 PM | 200 | $349.41 | $69,882.20 |
| 2026-04-23 6 PM | 100 | $328.26 | $32,825.70 |
| Subtotal | 300 | $102,707.90 |
Other Funding Sources
Yes
Other Funding Sources Details
Bounty payment for the Sprout proof-verification disclosure, in two parts.
Shielded Labs, the Zcash Foundation, ZODL, and Bootstrap
| Received (UTC) | Amount (ZEC) | Price at receipt | Notional at receipt |
|---|---|---|---|
| 2026-04-28 10 PM | 25 | $335.70 | $8,392.50 |
| 2026-04-23 7 PM | 25 | $336.28 | $8,406.93 |
| 2026-04-22 6 AM | 25 | $323.20 | $8,080.05 |
| 2026-04-21 8 PM | 25 | $311.99 | $7,799.68 |
| 2026-04-09 5 AM | 50 | $316.09 | $15,804.31 |
| 2026-04-02 6 PM | 50 | $236.07 | $11,803.29 |
| 2026-04-01 8 PM | 50 | $253.44 | $12,671.99 |
| 2026-04-01 3 PM | 50 | $242.69 | $12,134.49 |
| 2026-04-01 3 PM | 0.00001 | $243.04 | $0.0024 |
| Subtotal | 300.00001 | $85,093.24 |
Combined
| Source | Amount (ZEC) | Notional at receipt |
|---|---|---|
| ZCG (match) | 300 | $102,707.90 |
| Other funding sources | 300.00001 | $85,093.24 |
| Total | 600.00001 | $187,801.14 |
Success Metrics
- A temporary detectable unlimited mint and sell exploits, patched before anyone used it.
- Multiple vulnerabilities across both node implementations, none ever publicly exploited.
Proof of completion
Disclosures
Security advisories (Zcash Foundation)
- GHSA-3vmh-33xr-9cqh: Crafted V5 Authorization Data (CVE-2026-34377)
- GHSA-8m29-fpq5-89jj: Transparent Sighash Hash-Type (CVE-2026-41583)
- GHSA-452v-w3gx-72wg: rk Identity Point Panic (CVE-2026-41584)
Releases carrying the fixes
- Zebra 4.3.0: Critical Security Fixes, ZIP-235 Support, and Performance Improvements (March 26, 2026). Discloses the V5 transaction proof verification bypass, where V5 transactions were marked verified from their mined transaction ID alone and full proof verification was skipped. The Zcash Foundation credits alexs-scalar for discovering and responsibly disclosing it.
- Zebra 4.3.1: Critical Security Fixes, Dockerized Mining and CI Hardening (April 17, 2026). Carries CVE-2026-40880 (transaction verification cache consensus vulnerability, the mempool re-verification optimization removed outright) and the transparent sighash hash-type consensus divergence, alongside CVE-2026-40881.
Community discussion
- ZCG Security & Vulnerability Disclosure Initiative
- Incentivizing Critical Vulnerabilities Disclosure
Conflict of Interest Disclosure
None
Community Forum Posting
- I understand it is my responsibility to post a link to this issue on the Zcash Community Forums after this application has been submitted so the community can give input. I understand this is required in order for the community to discuss and vote on this grant application. Note: If you are unable to post on the forum (for example, due to new user restrictions), please leave a comment below, and we will adjust your posting permissions.