The Zcash community has approved a $1.5 million award for blockchain security researcher Taylor Hornby. The award recognizes his discovery of a security issue in the Zcash network that could lead to counterfeiting. This situation prompted developers to quickly implement an emergency upgrade to improve security.
The result of the award acknowledges Hornby’s contribution, which helped fix the issue, support testing, and encourage closer examination of the Zcash ecosystem.
Zcash Holders Approve $1.5M Security Award
Zcash decided to combine Hornby’s request for a $750,000 bug bounty with an additional $750,000 bonus for further recognition. Both requests were part of 37 applications submitted during the third round of Zcash’s Coinholder-Directed Retroactive Grants Program this month. Voting for these proposals took place from September 17 to September 29.
To be approved, each proposal needed at least 420,000 ZEC in participation and a simple majority of votes. The grant is important not just for its amount, but also because Zcash had previously delayed its second-quarter funding vote after a vulnerability disclosure in Orchard.
Organizers worried that using Orchard notes might affect voting power, which could undermine trust in ownership snapshots after the vulnerability was made public. This concern delayed the process into the third quarter, allowing coinholders to consider retroactive funding after emergency fixes and network stabilization were completed.
How the Orchard Bug Was Discovered
On May 29, 2026, Hornby discovered a serious security issue while conducting a security analysis for Shielded Labs. He promptly informed the engineers at the Zcash Open Development Lab about the critical problem in the Orchard proof circuit. The ZODL team confirmed the issue, developed a fix, and resolved the problem within five days.
The flaw involved a soundness issue in Orchard’s zero-knowledge proof circuit, which could potentially allow counterfeit value to enter the system and weaken the protections for the pool. As a result, Zcash activated an emergency soft fork and subsequently released a permanent fix, NU6.2, on June 3.
The updated implementation fixed the Orchard circuit issue. During this emergency, developers worked with exchanges, wallets, miners, and participants to ensure a smooth response. Project Tachyon later suggested using new turnstile mechanisms to help audit Orchard’s supply and protect users from potential counterfeit coins.












