i don’t like the attempt from some insiders to paint the zcash bug disclosure as “heroic”
it’s not heroic. it’s a systemic problem
yes they paid a smart researcher to find bugs and he did. that’s great
but the issue isn’t that the bug existed
the issue is that zcash, unlike almost any other cryptocurrency, enables a unique class of bugs, where if they’re exploited no one would know
this unique class still exists. the fact that they fixed this specific bug is immaterial. mythos could find 8 others. and then mythos 2
bugs can exist in all cryptocurrencies. they can exist in btc or eth or sol. but if someone exploits them we will IMMEDIATELY KNOW and limit the damage
with zcash, when someone secretly finds a bug and exploits it, WE WILL NOT KNOW
imagine if the kelpdao hack was exploited but it somehow magically wasn’t visible onchain. the attacker stole 300m but no one would know. and aave and other apps would assume everything is fine not knowing that they secretly have a hole in the balance sheet. how much wider would the damage have spread by the time we found out?
this is the real issue. not a specific bug. the systemic vulnerability: if a hack happens, we won’t know until much later
and a lot of zcashers have been trying to downplay the severity of this fundamental issue for years (including yesterday when this was first disclosed but played down)
regardless of this specific bug, i don’t think zcash is a safe place to store meaningful wealth long-term, until the design fundamentally changes
i wish zcashers were more open about that. that would’ve been heroic