Insufficient verification of data authenticity in Zcash - #VU138434
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to counterfeit funds within the Orchard pool, including double-spend notes under multiple nullifiers and authorize spends of other users' notes.
The vulnerability exists due to improper constraint enforcement in the Orchard Action circuit variable-base scalar-multiplication gadget in halo2_gadgets when generating Orchard proofs against an under-constrained base point. A remote attacker can produce a malformed proof with a freely chosen base value to counterfeit funds within the Orchard pool, including double-spend notes under multiple nullifiers and authorize spends of other users' notes.
The zero-knowledge property hides the malformed witness, leaving no distinguishing on-chain trace.