Just for the record - ZODL, a for-profit entity funded by VC firms, secretly coordinated an entire soft and hard fork of a network, and now are using it for marketing purposes tell you NOT to use open source wallets who arenโt VC funded.
The full story:
1. As one of the largest ecosystem participants in Zcash (both as a wallet and a merchant via Cake Pay), we had to find out about the bug from an X post and were never contacted to start patching our nodes or wallets ahead of time.
2. Every question we sent on X and DMs to ZODL folks was ignored until after they had the opportunity to patch in secret before releasing code.
3. The fix was (understandably) obfuscated and commits were held back until the release was out, so we had no way to see what was necessary to resolve client-side until long after ZODL and who knows who else.
4. We were only able to get a response and talk to those in the know on the bug/fix as of 3h ago, despite repeated efforts on all platforms for two days, but they have been helpful since then.
I understand the need for doing things quietly when critical bugs are found in consensus code, but refusing to notify or communicate at all with your FOSS ecosystem partner (likely because they feel threatened by our competition) is absolutely insane and an abuse of the insider access that ZODL has, EVEN MORE SO now that theyโre a for-profit company that has to serve its VC interests.
This is not the way decentralized networks should be run, is not the way FOSS communities should coordinate responses to responsibly disclosed bugs, and is yet another frustrating saga in Zcash having good tech but an immensely frustrating social layer.
I suggest storing ZEC in wallets built by experienced teams committed to Zcash beyond collecting swap fees, with the engineering expertise to maintain and secure their own codebase.