Retroactive Grant Application - Temporary Detectable Unlimited mint and sell (Bug Bounty)

Hello Zcashers,

Submitted a retroactive grant application to the Coinholder Retroactive Grants Program for the vulnerability disclosures across zcashd and zebra in March–April 2026: a temporary detectable unlimited mint-and-sell exploit.

GitHub issue: Retroactive Grant Application - Temporary Detectable Unlimited mint and sell Exploit

Requested amount: $400,000.
Not a cost reimbursement, direct costs were about $30,000 in API spend (shame on me, I know)

Prior funding: 600 ZEC, itemised in the application. No other compensation, no employment or contractor relationship with any Zcash organization.

On March 23 I reported that zcashd had been skipping Sprout proof verification since July 2020, accepting invalid Sprout spends. Multiple further vulnerabilities followed across zebra and zcashd from March to April, detailed in the application.

Chained together: split consensus, crash Zebra nodes, disable turnstile accounting, then mint through the verification bypass. Enabling a temporary detectable unlimited mint-and-sell of counterfeit ZEC.

Full application below.


Application Owners

@alexs-scalar

Individual Name

Alex Sol

Additional Team Members

None

How did you learn about the Lockbox: Coinholder Retroactive Grants Program?

Following discussions with Shielded Labs about compensation for these findings, and ZCG’s decision on additional funding, Shielded Labs suggested that this retroactive grants program was the right venue to bring the question to the community.

Requested Grant Amount (USD)

$400,000

Category

Research & Development

Project Summary

I’m requesting a retroactive bounty for multiple vulnerabilities I found and responsibly disclosed across Zcash’s two node implementations, zcashd and zebra nodes

The Sprout proof-verification bypass (live since 2020) lets a miner slip invalid Sprout spends past zcashd. The duplicate-header bug disables ZIP 209 turnstile enforcement. And the consensus-divergence and node-crash findings take Zebra.. Composed, is an exploit to temporary detectable unlimited mint-and-sell of counterfeit ZEC (likely few hours windows)

Project Description

At the end of February 2026 I began auditing several privacy coin protocols, looking for critical vulnerabilities and mainly for inflation bugs.

That work turned up findings in Grin, in Litecoin’s MWEB (found independently, a few hours after the LTC devs), and in a few other projects that were quietly patched and never disclosed to their community.

Then I decided to take a shot at Zcash :shield:

Between March and April, I found and privately disclosed multiple vulnerabilities to Shielded Labs

zcashd

Finding Impact
Sprout proof verification skipped Invalid Sprout spends accepted; present since July 2020
Identity rk in Orchard actions Crashes zcashd during proof verification
Identity epk Spec requires a non-identity point; Zebra enforced it, zcashd did not. Consensus split
Duplicate block header Silently resets pool balance tracking, disabling ZIP 209 turnstile enforcement

The Sprout bug came first; the other followed in the same codebase over the following days.

Zebra

Composed together, this leads to a chained critical exploits:

  • split consensus between Zebra and zcashd
  • use the identity rk panic to knock out Zebra nodes
  • spray duplicate headers vuln to disable turnstile enforcement on nodes
  • use the sprout verification bypass to temporary mint and withdraw from the sprout pool unlimited zec and sell it. Hypothetically could have lasted during few hours before the network could respond i believe so.

On the requested amount. My benchmark is the worst case these findings put on the table: temporary unlimited mint-and-sell of counterfeit ZEC. And hypothetically +10m to +100m in damage. We will never know, defender got it first!

Technical Approach

Manual code review, backed by heavy testing and assisted by AI. The target was the critical consensus path:

  • Proof verification: the checks that a shielded spend is actually valid.
  • Sighash construction: how the signed message is computed, where a small difference between implementations becomes a consensus split.
  • Pool balance accounting: the ZIP 209 turnstiles, which are the only supply-visibility a shielded chain has left.
  • Shared cryptographic libraries: librustzcash and the primitives underneath both nodes, where one bug reaches zcashd and Zebra at once.

Also prompt such as:

(claude) find inflations bug, make no mistakes

Time Period of Work Completion

March 2026 to May 2026

Total Budget (USD)

$30,000 to $40,000

Budget Breakdown

  • Technology/Software:
    • $30,000
    • OpenAI API and Claude spend for AI-assisted source review across the audit period (shame on me). Approximate, pending retrieval of the itemised bills. Covers all audits in this period, not Zcash alone.

Previous Funding Details

ZCG, matching other Funding Sources

Received (UTC) Amount (ZEC) Price at receipt Notional at receipt
2026-04-24 2 PM 200 $349.41 $69,882.20
2026-04-23 6 PM 100 $328.26 $32,825.70
Subtotal 300 $102,707.90

Other Funding Sources

Yes

Other Funding Sources Details

Bounty payment for the Sprout proof-verification disclosure, in two parts.

Shielded Labs, the Zcash Foundation, ZODL, and Bootstrap

Received (UTC) Amount (ZEC) Price at receipt Notional at receipt
2026-04-28 10 PM 25 $335.70 $8,392.50
2026-04-23 7 PM 25 $336.28 $8,406.93
2026-04-22 6 AM 25 $323.20 $8,080.05
2026-04-21 8 PM 25 $311.99 $7,799.68
2026-04-09 5 AM 50 $316.09 $15,804.31
2026-04-02 6 PM 50 $236.07 $11,803.29
2026-04-01 8 PM 50 $253.44 $12,671.99
2026-04-01 3 PM 50 $242.69 $12,134.49
2026-04-01 3 PM 0.00001 $243.04 $0.0024
Subtotal 300.00001 $85,093.24

Combined

Source Amount (ZEC) Notional at receipt
ZCG (match) 300 $102,707.90
Other funding sources 300.00001 $85,093.24
Total 600.00001 $187,801.14

Success Metrics

  • A temporary detectable unlimited mint and sell exploits, patched before anyone used it.
  • Multiple vulnerabilities across both node implementations, none ever publicly exploited.

Proof of completion

Disclosures

Security advisories (Zcash Foundation)

Releases carrying the fixes

Community discussion

Conflict of Interest Disclosure

None

Community Forum Posting

  • I understand it is my responsibility to post a link to this issue on the Zcash Community Forums after this application has been submitted so the community can give input. I understand this is required in order for the community to discuss and vote on this grant application. Note: If you are unable to post on the forum (for example, due to new user restrictions), please leave a comment below, and we will adjust your posting permissions.
9 Likes

Alex’s finding is what got me started doing security research on Zcash. I beleive he deserves it

6 Likes

I strongly support this proposal.

Scalar is the researcher who set off the wave of security disclosures Zcash has seen this year. He disclosed a number of vulnerabilities in March and April. He was the inspiration for Shielded Labs hiring Taylor Hornby as a Security Consultant, which we said in our announcement at the time. Scalar’s findings convinced us that AI had changed the game for security research, that we were (as Zooko says) heading for an AIpocalypse, and that we needed to get ahead of it. If it weren’t for Scalar, we might never have engaged Taylor, and the Orchard vulnerability would have gone undiscovered, or worse, been found and exploited by an attacker. And as @sangsoo notes above, his work also inspired other researchers to start hunting for and reporting bugs in Zcash.

In March, a security engineer from another ecosystem put me in touch with Scalar. He had discovered that zcashd had been skipping Sprout proof verification since 2020, a critical bug that sat undetected for nearly six years and could have resulted in the counterfeiting of ZEC. Over the following weeks he reported a number of additional vulnerabilities in zcashd and Zebra, several of them high severity. I was his primary contact throughout, and worked closely with him. He handled everything professionally. He disclosed privately, reported promptly, and, at the time, had no expectation of being compensated.

Despite all that, his compensation to date has been modest. There was no bug bounty program in place when he made his disclosures, so Shielded Labs, ZODL, Bootstrap, and the Zcash Foundation put together a donation to thank him, and ZCG later contributed as well. In total he received 600 ZEC, worth less than $200K when he received it. ZCG tried to stand up a bounty program afterward, but it was shut down before Scalar could apply for anything more. The compensation he received is a fraction of what similar findings have paid out elsewhere in the industry.

There is a separate conversation happening right now about how Zcash should handle bug bounties in the AI era, and it’s worth having. ZCG’s program was a good-faith effort, but the flood of AI-generated reports overwhelmed the core engineers, and shutting it down was the right call. Whatever the community eventually lands on, the retroactive grants program is currently the only avenue a researcher has to be paid for protecting the network. Researchers like Scalar are rare, and how coinholders respond to applications like this one will determine whether the next one who finds a critical bug reports it, ignores it, or does something worse with it. Scalar did everything right, and his request is reasonable. I hope coinholders approve it.

8 Likes

Very deserved. I support!

4 Likes

This bug is actually what gave me the idea for applying for my own grant; I felt like @scalar didn’t get enough for the severity of this bug and recommended he apply for a retroactive grant at the time. I think it’s deserved.

4 Likes