LTC · Litecoin

What Litecoin can prove, and what Zcash cannot

What Litecoin can prove, and what Zcash cannot

Within six months, Litecoin and Zcash each shipped a critical bug in their privacy layer. That is the uncomfortable part, and it belongs at the top rather than buried, because the interesting question was never which chain writes flawless code. Neither does. Nobody does. The question is what each design let its community find out afterwards.

Start with ours, since that is the one we owe you straight.

On 19 March 2026, Litecoin developers found a missing validation in the MimbleWimble Extension Block code. When a block was connected to the chain, the metadata attached to an MWEB input was not fully re-checked, even though the mempool and block building paths checked it properly. A block producer could therefore mine a block containing an MWEB input whose stated commitment did not match the output it was actually spending.

It was not theoretical. It was exploited, once, at block 3,073,882, and it produced an inflated peg-out of 85,034.47285734 LTC.

Read that number again, specifically the decimal places. That is the entire argument of this article in one line.

Litecoin knew the exact quantity created, to eight decimals. It knew the block. It knew the transaction. It knew the input ID. Within a day, v0.21.5 stopped any further malformed inputs, and over the following weeks a short series of releases handled the exploit block, permitted a recovery transaction, and froze MWEB rebalancing permanently. The actor cooperated and returned the funds, keeping 850 LTC as a bounty. Charlie Lee purchased replacement coin. The full amount was pegged back into MWEB at block 3,078,098 as a single frozen output that anyone can point to today.

A bad day. Genuinely a bad one. But a closed one.

The reason it could close is not that Litecoin's developers are sharper than Zcash's. It is that MimbleWimble hides amounts using Pedersen commitments, and Pedersen commitments carry a property that matters enormously on the worst day: the network can verify that inputs and outputs balance without ever learning what they were. Supply arithmetic stays checkable. Privacy comes from hiding values from observers, not from making the total unverifiable. So when 85,034 LTC appeared that should not have existed, it appeared as a discrepancy, in public, measurable, with a receipt.

Now Zcash.

On 29 May 2026, independent security researcher Taylor Hornby, auditing for Shielded Labs, found a soundness bug in the Orchard proof circuit. An under-constrained element in the Orchard Action circuit permitted invalid state transitions, which in practice meant forging transactions and double spending inside the Orchard shielded pool. Hornby built a working proof of concept that minted counterfeit ZEC in local testing. The flaw had been live since Orchard launched in May 2022. Four years.

Zcash responded quickly and responsibly. A soft fork on 2 June, at block 3,363,426, disabled Orchard transactions outright. The NU6.2 hard fork the next day, at block 3,364,600, re-enabled the pool with corrected circuit code. As emergency response goes, that is fast and well executed, and the people who did it deserve credit.

Then everyone walked into the wall that no amount of competence gets you past.

Nobody can tell whether it was ever used.

Not "we checked the chain and found nothing". Zcash founder Zooko Wilcox said it plainly: because of Orchard's privacy properties, there is no way to cryptographically prove whether the vulnerability was exploited. The same mathematics that makes a shielded transaction private makes that question permanently unanswerable. There is no evidence of exploitation on mainnet. There is also no possible evidence of its absence. Those are very different statements, and four years is a long window to leave the difference hanging in.

It is worth being precise about scope here, because the loud versions of this story get it wrong in both directions. Zcash's 21 million cap was never at risk. The network runs a turnstile at each pool boundary that caps what can leave a pool at what verifiably entered it, and that check held. Counterfeit ZEC, if any exists, could not have escaped Orchard into the transparent supply.

But follow that through to the coins actually sitting in the pool. If counterfeits were created inside Orchard, they are indistinguishable from real notes inside Orchard, and the turnstile does not remove them. It only guarantees that no more value leaves than went in. So the shortfall, if there is one, does not land on the supply cap. It lands on whichever holders reach the exit last.

That is precisely what the Ironwood upgrade on 28 July, at block 3,428,143, formalised. Orchard is sealed. A fresh pool opens from zero. Roughly 3.66 million ZEC, more than a fifth of the circulating supply and around 1.7 billion dollars at the time, has to be moved out by hand through a one way turnstile into the new pool. Every holder migrates their own coins. Any counterfeits stay trapped behind them.

The turnstile caps exits at verified deposits. That protects the supply cap absolutely, and individual holders not at all.

The turnstile caps exits at verified deposits. That protects the supply cap absolutely, and individual holders not at all.

Sit with what that asks of an ordinary holder. Your funds are safe, provided you move them, and provided enough real value remains in the queue ahead of you when you do. That is not remediation. It is containment, and the cost of containment gets distributed across users in an order nobody chose and nobody can see.

ZEC fell more than thirty percent in a day on disclosure. Markets are not always wise, but they read this one correctly. The bug was never the problem. The permanent question mark is the problem.

Two privacy bugs, six months apart. Litecoin's was worse on the day and closed anyway.

Two privacy bugs, six months apart. Litecoin's was worse on the day and closed anyway.

Now the part where we should be fair, because a comparison that only flatters the home team is worth nothing to anybody.

Orchard's privacy is genuinely stronger than MWEB's, and it is not close. Zcash shielded transactions hide sender, receiver and amount behind zero knowledge proofs, with the whole pool as the anonymity set. MWEB hides amounts and breaks the direct link between inputs and outputs, but it leaks more to a determined analyst, and it is opt in, so its anonymity set is only the people who chose it. If your threat model demands the strongest on chain privacy available, Zcash offers something Litecoin does not.

The trade has a second half, though, and it is the half almost nobody prices until the morning after. Privacy built on a complex proving circuit means the integrity of your money rests on the soundness of that circuit. Not on whether it is sound today, but on whether it has been sound every single day since it shipped, which is a claim nobody can check retroactively. MimbleWimble buys weaker privacy and pays for it with arithmetic simple enough that the ledger stays auditable by anyone, permanently.

The trade stated plainly: Zcash wins on privacy, Litecoin wins on everything you need the morning after.

The trade stated plainly: Zcash wins on privacy, Litecoin wins on everything you need the morning after.

Litecoin made that trade deliberately, and March is the case study for why. A real exploit, real inflation, and a fully recovered ledger, because the design let us count.

The rest of Litecoin follows the same instinct. Privacy lives in an extension block rather than the base layer, so the main chain stays transparent and auditable by default and privacy is there for the people who want it. The chain has run close to fifteen years without a halt. Network hashrate sits at record levels, around 2.65 petahash per second at our latest snapshot, and that work does double duty: the same hashing can be submitted to Dogecoin, Pepecoin, Bellscoin, Dingocoin, Luckycoin and Junkcoin at no additional energy cost, which is why chains worth a fraction of Litecoin's market cap sit behind hashrate they could never buy alone. Institutional access arrived without drama through the Canary Litecoin ETF on Nasdaq. Blocks keep arriving every two and a half minutes, as they have since 2011.

None of that is thrilling. That is rather the point.

Litecoin is not the more private chain and has never claimed to be. What it is, is a chain where every coin in existence can be accounted for, including the ones that should never have existed, and where a bug in the privacy layer produced a number, an invoice and a fix rather than an open question that will outlive the people asking it.

Zcash will probably be fine. The migration will mostly work, the new pool will fill, the price will do whatever it does. But somewhere inside that sealed Orchard pool sits an unknown quantity of coins that may or may not have ever been real, and no cryptography that exists or is coming will ever tell anyone which. That is not a scandal. It is a design consequence, chosen years ago, arriving on schedule.

Offered the choice between a privacy system you can audit and one you have to trust, Litecoin picked the one you can check. Close to fifteen years in, that still looks like the right call.