Executive brief
Zebra is a Rust-based implementation of a Zcash node. A vulnerability in how it handles specific transaction signatures (SIGHASH_SINGLE) allows it to accept transactions that other Zcash nodes (zcashd) would reject. This creates a 'consensus split' where the network disagrees on which transactions and blocks are valid, potentially leading to financial discrepancies, service disruptions, and a loss of trust in the network's integrity.
Technical details
A consensus divergence exists in Zebra's handling of ZIP-244 (V5+) transparent spends. When a transaction uses SIGHASH_SINGLE and the input index has no corresponding output, zcashd correctly fails validation. However, Zebra's transparent verification path computes a digest for the missing-output case instead of returning an error. An attacker can exploit this by crafting a V5 transaction with fewer outputs than inputs and signing the digest Zebra expects. This allows Zebra to accept, mempool, and mine blocks containing transactions that the rest of the Zcash network (running zcashd) will reject, resulting in a chain split. The issue is fixed in Zebra version 4.4.0.
Affected products
- ZcashFoundation zebrad < 4.4.0
Timeline
- 2026-05-02: disclosed: Advisory published by Zcash Foundation
- 2026-05-07: advisory: GitHub Advisory published
- 2026-05-07: patched: Fixed in version 4.4.0