HomeSecurityZcash: Developers discovered vulnerability that existed for years

Zcash: Developers discover vulnerability that existed for years

The developers behind Zcash encryption, with privacy in mind, recently discovered and created a very dangerous vulnerability in the most secret way that would allow an intruder to earn an infinite amount of Zcash (ZEC). Yes, clearly … like a continuous source of money.

Zcash

Launched in October 2016, Zcash is a privacy-focused cryptocurrency that claims to be more anonymous than Bitcoin, as the sender, recipient, and value of transactions remain hidden.

In a blog post released today, Zerocoin Electric Coin Company – the startup behind Zcash – revealed that one of its employees, Ariel Gabizon, discovered the vulnerability in its code on March 1, 2018, the evening before his talk at the Financial Cryptography conference almost a year ago.

Gabizon came into contact with Sean Bowe, a cryptographer at Zcash, immediately after the discovery of the forgery/impersonation vulnerability, as it was called by the team, and the team decided to keep it secret to avoid the risk of exploitation by intruders.

According to the company, only four Zcash employees knew the issue before a concealed fix was included in the Zcash network on October 28, 2018.

Aside from that, given that “the discovery of this vulnerability would require a high level of technical and cryptographic complexity that few people possess”, the company believes that no one else knew about this flaw and that there was no intrusion into Zcash.

Now, the Zcash team has thoroughly analyzed all the data regarding the vulnerability on its official website to inform the broader public, which, if exploited by an intruder, would allow them to print an infinite amount of Zcash tokens.

Details about the Catastrophic Zcash vulnerability

According to the team, the manipulation vulnerability resided in zk-SNARKs- a zero-knowledge encryption application used by Zcash for encrypting and protecting transactions – which was implemented independently of other projects.

Both the Komodo blockchains and Horizen (formerly known as ZenCash) suffered from the same issue and, according to information, they patched it on their platforms after being notified by the Zcash team in mid‑November 2018 via encrypted email.

Anyone who has access to multi-party computation (MPC), which is used to set Zcash's privacy features, could create false proofs, giving them the ability to generate an unlimited amount of coins.

Although the developers did not find evidence proving an intrusion into Zcash, they confirmed that the vulnerability has existed for years.

“The vulnerability existed for years but was not discovered by many expert cryptographers, scientists, third‑party auditors and third‑party engineering teams who started new projects based on the Zcash code”, the company writes.

Since Zcash is private, even if someone could have tampered with Zcash in the past, there is no way to find out. While, the Zcash Company disagreed “We studied the blockchain to find evidence of vulnerability: An attack can leave a certain kind of footprint. We did not detect any such footprint.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS