Security Information

Electric Coin Company will announce any breaking security issues on this website’s Security Announcements page.

Security Announcements​

In order to keep the Zcash userbase up-to-date with all recent and historical security issues, we document all security related events on this page. We also publicly share when a new event has been added to this page.

Security Announcement 2021 03 01

The latest version of the ECC iOS SDK (Version 0.9.2) contains an important security update, and users are urged to update immediately. Unstoppable Wallet and Nighthawk Wallet have applied this fix and users of those apps should update to the latest versions immediately.

Security Announcement 2020 02 06

We have just released zcashd 2.1.1-1 to our Debian apt repository. It includes a soft-fork change to the consensus rules to address a security vulnerability that could be leveraged to cause consensus forks. We request miners and pools upgrade as soon as possible to ensure this soft-fork is activated. We also request all users to upgrade as soon as possible.

Please see the following for more information: https://electriccoin.co/blog/new-releases-2-1-1-and-hotfix-2-1-1-1/

Security Announcement 2019-11-08

Version 2.1.0-1 of Zcashd includes an important security fix in response to an issue that was published on November 8th 2019 on the bitcoin-dev mailing list and has the designation CVE-2017-18350.

Users should upgrade their nodes to this version immediately and discontinue use of older versions.

Security Announcement 2019-09-24

Version 2.0.7-3 of Zcashd includes an important security fix in response to an issue that was reported to us on Friday September 13th 2019 by Florian Tramèr, Dan Boneh, and Kenneth G. Paterson.

Users should upgrade their nodes to this version immediately and discontinue use of older versions.

Please note that the issue does not put funds at risk of theft or counterfeiting. More details of the issue will be released in coordination with the reporters of the issue at a future date.

Security Announcement 2019-03-27

Version 2.0.4 of Zcashd includes a fix for the bug described in the previous security announcement.

Users should install this update and then rescan the blockchain by invoking zcashd -rescan. Sprout address balances shown by the zcashd wallet should then be correct.

Thank you to Alexis Enston for bringing this to our attention.

Security Announcement 2019-03-19

Synopsis: A bug in the Zcashd wallet could result in Sprout z-addresses displaying an incorrect balance. Sapling z-addresses are not impacted by this issue. This would occur if someone sending funds to a Sprout z-address intentionally sent a different amount in the note commitment of a Sprout output than the value provided in the ciphertext (the encrypted message from the sender).

A code fix for the wallet has been written and the integration into an official Zcash release is targeted for our next release (version 2.0.4, expected March 25th).

Who is affected: Users that receive payments to their Sprout z-addresses using the Zcashd wallet are vulnerable. Users who do not receive payments to Sprout z-addresses are unaffected.

What can Sprout users do to protect themselves? Sprout users should suspend their trust in the receipt of funds to Sprout z-addresses until they upgrade to zcash v2.0.4, which is expected to be released on March 25th. If users need the fix earlier, they can manually build their own daemon with the code available now: https://github.com/zcash/zcash/pull/3897.

Once a fix has been applied, users are strongly advised to issue a rescan of the blockchain with “zcashd -rescan”.

Acknowledgements: Thank you to Alexis Enston for bringing this to our attention.