https://forum.zcashcommunity.com/t/orchard-vulnerability-successfully-remediated/55976
Zcash's supply has now relied on trust in all private pools. This is Zcash's second hidden inflation vulnerability: the worst class of vulnerability possible. Monero has never had a hidden inflation vulnerability.
You now have to trust that no one printed more shielded Zcash in the Orchard pool while the vulnerability was live, the math in Zcash does not protect you. Orchard is now effectively a trusted pool, technically inferior to FCMP++.
The Zcash turnstile mechanism only mitigates damage. The turnstile would show that someone is unshielding a wholeeee lot of printed Zcash triggering the turnstile (the Orchard pool is almost 30% the total supply currently). There is no way of knowing if an attacker is currently sitting on infinite Zcash in the Orchard pool and already exploited the vulnerability.
It's reckless and irresponsible that the Zcash ecosystem downplays this vulnerability.
"ZCASH WAS NEVER DOWN. FUD"
This distracts from the MAJOR CRITICAL vulnerability that was just found (and YES, the Orchard pool was in fact down while they rolled out the patch).
