Zcash coinholders approved $8.39 million in retroactive grants for work completed during this year's security crisis, according to OpenZcash data. The funding included $1.5 million specifically for Taylor Hornby, who discovered the critical Orchard vulnerability.
The Q3 2026 Coinholder-Directed Retroactive Grants round funded 17 of 37 submitted proposals, representing 93.1 percent of the $9.01 million requested. Voting involved a substantial portion of the Zcash supply, with the largest single vote accounting for approximately 2.18 million ZEC—10.4 percent of Zcash's maximum supply of 21 million ZEC.
Hornby received two separate $750,000 grants. One covered the original bug bounty for the Orchard flaw; the second was a community-nominated award. Shielded Labs disclosed in June that Hornby discovered the Orchard vulnerability on May 29 during a security review that combined traditional techniques with Anthropic's Opus 4.8 artificial intelligence model.
The vulnerability impacted Orchard's zero-knowledge proof circuit. If exploited, an attacker could have created counterfeit ZEC within the shielded pool without leaving a discernible onchain record. Hornby immediately reported the issue to engineers at Zcash Open Development Lab, triggering a coordinated emergency response involving developers, miners, exchanges and infrastructure providers.
The Zcash network temporarily disabled Orchard transactions, then activated NU6.2, which incorporated a corrected circuit to address the flaw. The Zcash Foundation confirmed no evidence of unauthorized value creation occurred. The network's total ZEC supply remained consistent under its turnstile accounting method, which tracks value flow.
The Q3 vote extended beyond Hornby's bounty. Coinholders approved $1.95 million for ZODL's core protocol development in Q1 and Q2, alongside $1.203 million for ValarGroup's Ironwood work. Additional allocations included $738,942 for formal verification of the Ironwood zk-SNARK circuit and $599,000 for external audit costs.
Other security-focused grants included $425,000 for addressing five critical Zebra consensus-divergence vulnerabilities, $400,000 for a temporary detectable unlimited-mint-and-sell exploit and $150,000 for a Zebra vulnerability bounty. The Ironwood upgrade followed the Orchard incident. In July, the Zcash Foundation released Zebra 6.0.0, which included support for the NU6.3 Ironwood upgrade.
Zcash co-founder Zooko Wilcox said on Oct. 1 that these grants rewarded individuals who contributed to the network during this year's security challenges. He characterized the vote as validation for Zcash's system of coinholder-directed funding and governance. All large grants—awards exceeding $50,000—undergo program administration including compliance checks before keyholders coordinate payouts.

