Zcash holders have voted to pay out 8.39 million USD in retroactive grants — including 1.5 million USD to the researcher who discovered a bug so severe it could have let an attacker counterfeit ZEC out of thin air. The vote, announced October 1, is the clearest demonstration yet of what happens when a crypto network lets its own coin holders decide, privately and directly, who gets rewarded.
By Jennifer Kim | October 1, 2026
The Hook: Paying for Work Already Done
According to OpenZcash’s public records, coinholders funded 17 of 37 proposals in the Q3 2026 Coinholder-Directed Retroactive Grants round, representing 93.1 percent of the 9.01 million USD requested. Unlike most crypto grant programs, which fund promises, this one pays after the fact: contributors complete the work first, and holders vote on whether it deserved payment. Zcash co-founder Zooko Wilcox wrote on October 1 that the grants rewarded people who “selflessly worked to protect all users” during this year’s security crisis — though his broader claim that the vote proves the governance model’s strength reflects his own view.
The largest single vote involved roughly 2.18 million ZEC, equal to 10.4 percent of Zcash’s fixed 21 million coin supply. Participation has grown sharply: the biggest Q3 vote dwarfs the roughly 500,608 ZEC recorded during Q1, after Q2 voting was postponed in the wake of the Orchard vulnerability and several proposals rolled into this round.
On-Chain Evidence: The 1.5 Million USD Bug
The headline grant went to Taylor Hornby, who received two 750,000 USD awards — one covering the original bug bounty, plus a second community nomination that doubled his total to 1.5 million USD. According to a disclosure by Shielded Labs, Hornby found the flaw on May 29 while reviewing Orchard’s zero-knowledge proof circuit using both traditional security techniques and Anthropic’s Opus 4.8 AI model.
The stakes were existential. The vulnerability sat in Orchard — Zcash’s shielded transaction system, the part that keeps amounts and senders private. Exploited, it could have allowed an attacker to create counterfeit ZEC inside the shielded pool without leaving an obvious on-chain trace. Hornby disclosed the issue immediately to Zcash Open Development Lab engineers, and developers, miners, exchanges, and infrastructure providers coordinated an emergency response. The network temporarily disabled Orchard transactions before activating the NU6.2 upgrade with a corrected circuit. The Zcash Foundation’s analysis found no evidence of unauthorized value creation — the total supply stayed intact.
Security dominated the rest of the round too. Coinholders approved 1.95 million USD for ZODL’s Q1 and Q2 core protocol development, 1.203 million USD for ValarGroup’s Ironwood work, 738,942 USD toward formal verification of the Ironwood zk-SNARK circuit, and 599,000 USD for external audit costs. Smaller awards covered five critical Zebra consensus-divergence vulnerabilities (425,000 USD), a temporary detectable unlimited-mint-and-sell exploit (400,000 USD), and a Zebra vulnerability bounty (150,000 USD). Twenty proposals were rejected or failed to receive funding.
The Core Conflict: Democracy With Guardrails
How does a network hand out millions without a board of directors? Under the current rules, at least 420,000 ZEC must participate for a proposal vote to qualify, and a simple majority — excluding abstentions — determines approval. Shielded Labs and the Zcash Foundation act as keyholders for the fund’s 2-of-3 multisignature arrangement, processing approved payments. They retain limited veto powers on defined legal grounds, but they cannot reverse a proposal coinholders have approved.
That design is the experiment: pure coinholder voting, with institutions reduced to administrators. Critics of token-voting governance argue it favors large holders; Zcash’s answer is private voting — participants cast ballots without revealing their holdings — which the round’s record participation suggests is drawing engagement rather than suppressing it. Large grants still pass through compliance checks for awards above 50,000 USD before keyholders coordinate payouts, a nod to regulatory reality.
Market Implications: What This Means for Your Altcoins
At the time of research, ZEC traded near 1,407 USD according to CoinGecko data cited by crypto.news, with a 24-hour range between roughly 1,382 and 1,458 USD. That is below the 1,600-to-1,700 USD area reached during September’s rally, but far above the levels seen before the month’s breakout. Momentum has cooled: the daily RSI sits at 55.45, below its moving average near 64.49, while the MACD histogram has turned negative at roughly -33.01 as the token consolidates.
- The governance signal — a security crisis was followed by record participation and full retroactive payment, not a funding freeze
- The supply signal — Zcash’s 21 million cap remained intact through the Orchard incident, verified under the network’s turnstile accounting
- The market signal — ZEC consolidating near 1,400 USD after a big September run; the grants vote has not derailed the structure
- The calendar — the next round accepts proposals from October 30 through November 13, with voting December 17-29
The Verdict
For altcoin investors, the Zcash round is a case study in what decentralized funding looks like when it works: a researcher finds a counterfeiting bug with AI assistance, reports it responsibly, the network patches without losses, and holders — not a foundation board — vote millions in rewards afterward. That does not guarantee ZEC’s price, and governance enthusiasm has cooled in many tokens before. But if you hold altcoins, ask the uncomfortable question this story raises: if your network’s equivalent of the Orchard bug surfaced tomorrow, is there a funded, functioning system to catch it — and to thank the people who did? On today’s evidence, Zcash’s answer is yes.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
1.5M for the counterfeiting bug guy is the cheapest insurance zcash ever bought. imagine that exploit actually hitting mainnet
1.5M against a counterfeiting bug on a chain this size is rounding error insurance. whoever originally priced that bounty should be sweating
2.18M ZEC voted, thats 10.4 percent of supply turning out. turnout alone is kinda wild for a governance vote
10.4 percent turnout beats most DAO votes that get decided by three wallets and a bribery forum. shielded voting actually gets people to show up
1.5M to the counterfeiting bug finder is the headline but 17 of 37 proposals funded is the real story. That is a brutal filter and honestly healthy for the pool.
Paying after the work is done, 17 of 37 proposals funded. Grant programs everywhere should copy this model.
copying the model requires shielded voting infra most chains dont have. a normal DAO would botch the sybil resistance in week one
Retroactive grants done by actual coinholder vote, privately. Try doing that with a DAO token where whales just farm their own proposals. Zcash keeps quietly outgrowing its memecoin-era reputation.
Piotr the privacy of the vote is the part other chains cannot copy easily. Shielded governance is genuinely novel and 8.39M allocated without a single governance attack is impressive.