Zcash’s ZEC token slumped more than 36% from recent highs after developers disclosed a critical flaw in the network’s Orchard shielded pool, pushing the cryptocurrency toward a significant long-term support near $367. The vulnerability was identified by security engineer Taylor Hornby on May 29 and reported to the Zcash Open Development Lab and Shielded Labs, prompting an emergency hard fork that was activated on June 3 to remove the risk.
Trading momentum reflected a sharp risk-off move. ZEC hovered around $390 on Thursday, after briefly trading above $611 earlier in the week, erasing more than $3 billion from its market capitalization. Shielded Labs and the Zcash Open Development Lab said the flaw affected the cryptographic circuit underpinning Orchard’s privacy pool. Hornby, aided by Anthropic’s Claude Opus 4.8 model, pinpointed a fault in an elliptic curve multiplication check and built a proof-of-concept exploit capable of generating counterfeit ZEC.
Researchers at Shielded Labs warned that, if the same exploit had been executed on the live network before the patch, it could have produced “unlimited, undetectable counterfeit ZEC” inside an Orchard wallet. The disclosure has nevertheless left investors wary, given the privacy design of Orchard makes it difficult to cryptographically prove whether the flaw was exploited prior to patching.
Traders focus on support levels after selloff
Although developers have fixed the vulnerability, uncertainty remains due to the privacy architecture of Orchard, which complicates retrospective verification of exploitation. Shielded Labs said it is “not overly concerned” about prior abuse, noting the bug had persisted for years under expert review and would have required targeted, sophisticated investigation to uncover.
From a technical standpoint, the selloff pushed ZEC through several key moving averages. Data shows ZEC breached its 20-day, 50-day and 100-day exponential moving averages in the wake of the disclosure. The next major technical milestone sits near the 200-day exponential moving average around $367, a zone that also coincides with a historically high-volume trading area on the volume profile.
Momentum indicators corroborate the softer tone. The daily relative strength index sits around 37, its lowest in weeks, indicating growing selling pressure though not yet in oversold territory. Bollinger Bands reveal the move is stretched, with price pressing near the lower band after breaking the middle band during the decline. The lower band sits in the high $300s, while the upper band remains far above current levels, underscoring the magnitude of the pullback.
Market‑data firm Coinglass shows liquidation activity reflecting a largely cleared-out chart of leveraged long positions, leaving a concentration of open liquidations above the current market price, notably in the $430–$500 area and extending toward the $550 region. In contrast, liquidity below the current level points to a historically active zone around $220–$260, where the token spent multiple months consolidating earlier this year.
Even with the patch in place, traders are watching whether the $367 level will hold. A failure there would shift attention to the lower-volume cluster just beneath, potentially drawing in sellers who view the new zone as the next test of fundamental support.
Not every observer sees the worst is over. Arthur Hayes, co-founder of BitMEX, wrote on social media that illegal minting of ZEC through the Orchard flaw was unlikely, though he cautioned that there is no cryptographic proof ruling out such an outcome entirely. Hayes also noted he had sold his ZEC holdings, signaling ongoing concerns about the chain’s risk profile. “The Holy Trinity is dead,” Hayes added, referring to Zcash, Hyperliquid and Near Protocol, which he said he had sold in the week.
Industry participants cautioned that privacy-focused systems face recurring risk. Mert Mumtaz, co-founder and chief executive of Solana infrastructure firm Helius, said variants of the same issue exist across many privacy protocols because complex zero-knowledge circuits are prone to undetected bugs. “This same FUD comes back every five months as new people learn how privacy pools work,” Mumtaz wrote.
Beyond the immediate incident, the episode is not the first counterfeiting-related concern for Zcash. In 2018, Electric Coin Company discovered a vulnerability in the cryptography underpinning zk‑proofs and remedied it without reported losses. Shielded Labs said it is working with Zcash developers on a network upgrade designed to help users verify the integrity of circulating ZEC and prove the absence of counterfeit coins in the Orchard pool.
The situation underscores the fragility of trust in privacy-focused assets and the sensitivity of their price to security disclosures. As investors weigh potential upside against continued uncertainty, the market’s attention remains squarely on the effectiveness of the planned network upgrades and the ability to provide verifiable assurances about supply integrity in Orchard.
The post Zcash crashes 36% on Orchard vulnerability, traders eye $367 support appeared first on Invezz.







