TechFlow reports that on June 3, the Zcash Foundation released Zebra versions 4.5.3 and 5.0.0 to address a critical soundness vulnerability in the Orchard zero-knowledge proof circuit. Version 4.5.3 temporarily disables Orchard operations via an emergency soft fork, while version 5.0.0 activates NU 6.2, re-enables Orchard using the corrected circuit, and permanently closes the vulnerability.
The official statement indicates there is currently no evidence that the vulnerability has been exploited, no unauthorized ZEC inflation has occurred, user privacy remains unaffected, and Sapling and transparent transactions continue operating normally. Node operators are urged to upgrade to Zebra 5.0.0 as soon as possible.




