Zcash Dodges $6.5M Threat as Critical Sprout Pool Bug Is Quietly Patched

A serious security flaw lurking inside Zcash infrastructure has been successfully neutralized after researchers revealed it could have enabled attackers to siphon off millions in dormant funds—without ever being detected.
The issue centered on the network’s outdated Sprout shielded pool, where more than 25,000 ZEC remained locked. Due to a verification oversight in zcashd nodes, certain transactions tied to this legacy pool were not properly validated. In theory, malicious miners could have exploited this gap to drain the funds, valued at roughly $6.5 million at the time of discovery.
The vulnerability was identified by security researcher Alex “Scalar” Sol, who used AI-assisted analysis to uncover the flaw and reported it on March 23. Despite the severity, no exploitation occurred, and all user funds remained secure.
Developers responded quickly. A patched release was rolled out, and major mining pools rapidly upgraded their systems within days, effectively closing the window for any potential attack. Notably, the Zebra node implementation remained unaffected and would have triggered a network fork if exploitation had been attempted—adding a crucial safety net.
Although the compromised component had been deprecated since late 2020, it still held a significant amount of unclaimed funds. This made it a lingering risk within the ecosystem, even years after being phased out.
Importantly, Zcash’s built-in “turnstile” mechanism ensured that even if attackers had exploited the flaw, they wouldn’t have been able to inflate the total supply. The safeguard enforces strict accounting between shielded pools, preventing unauthorized coin creation beyond the network’s circulating supply.
For responsibly disclosing the bug, Sol is set to receive a 200 ZEC reward, backed by multiple ecosystem contributors including the Zcash Foundation and development groups.
This isn’t the first time the network has faced a critical threat. A past vulnerability once raised concerns about infinite coin generation, but like this latest incident, it was resolved before causing damage.
Meanwhile, momentum around Zcash continues to build. The asset recently posted strong gains, climbing sharply over a 24-hour period and reflecting renewed investor interest—even as broader crypto markets remain volatile.
The incident serves as a reminder that even dormant features can pose real risks—but also highlights how coordinated disclosure and rapid response can prevent disaster before it begins.
