What Actually Broke In ZCash.. - Tulip King
- The Orchard incident involved a potential double-spend vulnerability in its ZK circuit, not merely routine maintenance. A security engineer associated with Zcash found logic permitting what the disclosure called “invalid-state transactions”; Tulip King’s plain-English reading was that someone might exploit the circuit to spend the same amount twice after entering the shielded pool.
- The emergency response fixed the vulnerability while exposing a centralization tradeoff in Zcash’s design. Operators were asked to adopt a soft fork rejecting Orchard transactions for what Tulip estimated was roughly 24 hours, followed by a hard fork with corrected circuit logic. Tulip concedes that blocking exploitation was right, but finds it troubling that Zcash could “ping everybody” to suspend a privacy pool and quickly move everyone onto new rules.
- The turnstile limits how much ZEC can exit Orchard, but privacy prevents certainty about what might exist inside it. With 1 million ZEC deposited, an attacker might hypothetically create 17 million private units yet withdraw only the available 1 million—or avoid detection by taking “1,000 ZEC every day” and treating the pool as a permanent dividend.
- ZEC rallying on the news told Tulip more about positioning than technical safety. He thinks traders “hate Bitcoin right now” and interpreted the response as an ordinary upgrade, normalized by Ethereum, Solana, and Hyperliquid. His objection is that money should not depend on a founder being able to change the rules or freeze funds; he says he never wants to wake up to a Zuko blog announcing such a change.
- Tulip has moved from 150–160% Bitcoin exposure on margin to roughly one-third BTC, one-third HYPE, and one-third ZEC. Much of the initial reduction happened because gains elsewhere expanded his portfolio, but after closing his Bitcoin-backed margin he sold BTC for the first time. He framed ZEC as a hedge against Bitcoin’s approach to privacy, while also discussing Bitcoin’s quantum risk.
- His altcoin framework now demands both real revenue and credible alignment between cash flow and the token. HYPE must keep demonstrating that “revenue actually matters,” with revenue and buybacks on-chain rather than discretionary. He sees potential multiple expansion among $10 million–$50 million projects, but only if revenue persists and grows and leadership routes value to holders.
- Despite selling Bitcoin for the first time, Tulip’s long-run BTC thesis remains almost absolute. Even a hypothetical quantum theft could reinforce the principle if Bitcoin simply kept producing blocks without seizures or rule changes: “This currency is what it is, take it or leave it.” He still calls $1 million BTC “destiny” because it remains harder, more politically resistant, and more rule-bound than everything else he has considered.
1. Orchard’s private-state logic opened a potential double-spend path
Tulip King’s technical summary begins with a security engineer associated with Zcash finding a potential exploit in Orchard’s ZK circuit. Shielding transparent ZEC requires reimplementing familiar send-and-receive behavior under different private-state rules, creating room for a bug even when the intended economics remain unchanged.
The disclosure’s phrase was “invalid-state transactions.” Tulip openly admits the scalar-math explanation exceeded his understanding, but says the honest practical reading was a double-spend: an attacker might reuse the same amount within Orchard.
The immediate defense was a soft fork asking miners, exchanges, and wallet operators to reject Orchard transactions for what Tulip estimated was roughly 24 hours. Once corrected logic was ready, a hard fork moved the network onto a circuit without the identified exploit.
2. The turnstile revealed public totals but left private uncertainty
Tulip’s example: if two users each deposit 10 ZEC, the network knows Orchard contains 20, though their internal transfers remain hidden. The turnstile therefore prevents either user from transparently withdrawing 30.
That safeguard does not prove Orchard’s internal accounting was never corrupted. Against 1 million legitimate deposits, an attacker might create 17 million additional private units, withdraw only the available 1 million, or spend private ZEC through integrations that never require leaving the pool—Tulip’s examples were buying a Chipotle burrito or transacting through NEAR Intents.
Tulip says an immediate withdrawal would advertise the exploit and cause exchanges and others to shut down. “Why don’t I just withdraw 1,000 ZEC every day,” he asks, “and just pay myself a permanent dividend?” His comparison is that Monero’s total supply may be unknowable, while Zcash’s transparent totals and turnstile reduce—but do not eliminate—the uncertainty.
3. The repair sharpened the case for optional privacy
Tulip’s centralization objection survives his concession that developers did the right thing. Coordinating everyone to ignore Orchard and then accept a hard fork was preferable to leaving the bug open, but it also demonstrated “the value of Bitcoin not doing anything.”
Thread Guy’s pushback becomes a design alternative: perhaps existing currencies should support selectively shielded transactions rather than making the currency private by default. Tulip recognizes this as the NEAR and Railgun thesis—users “tap into privacy and then tap out,” while competing protocols compete on security, liquidity, and integrations—and says, “I don’t hate that conclusion.”
The episode marks a dramatic positioning change. Tulip went from 150–160% BTC on margin to about 30%; gains from other assets, including a trading hot streak in which he was turning profits into HYPE, diluted Bitcoin first, then he closed the remaining margin and trimmed BTC. His current shorthand is “a third Bitcoin, a third HYPE, and a third Zcash,” while describing himself as “kind of straddling.”
4. HYPE must prove that revenue-bearing tokens can rerate
Tulip’s near-term market condition is blunt: HYPE has to keep performing. Its signal is that revenue matters, but also that tokenholder treatment matters—“put the revenue on-chain, put the buybacks on-chain,” then keep swapping into the token “ad infinitum.”
He criticizes holder-hostile outcomes around the Helium Foundation and Axelar’s acquisition by Coinbase as examples of holders lacking rights. The investable model requires both continued revenue growth and teams willing to bind that revenue to the token.
His hunting ground is revenue-generating projects around $10 million–$50 million market caps. Some could achieve “10x” outcomes or at least rerate toward $80 million–$100 million if margins hold and teams show steady leadership, though he calls the field “an army of minefields.”
Collector Crypt Cards is his negative specimen: despite producing revenue, its official handle called the token a “valueless meme coin,” perhaps cheekily because of its stated concern about the SEC. Thread Guy adds the market-level risk: if HYPE falters while traders chase Worldcoin and other high-beta alts, “we have big problems on our hands.”
5. Bitcoin’s refusal to change remains the final bull case
Tulip no longer believes investors can buy the “guaranteed thing,” log off for four months, and expect effortless returns. Hyperliquid may now function as a broader crypto index because crypto tokens want to trade there, with exposure to volumes, fees, equity perps, RWAs, and HIP-4 options—but that does not replace Bitcoin’s monetary role.
His quantum scenario is explicitly conditional, not a forecast: a five-year threat is painful for a seven-year holder, yet less decisive across 70 years. Even if vulnerable coins were stolen and sold, Bitcoin could keep producing ten-minute blocks without forks or seizures—“we’re not changing the rules”—and remain secured by quantum compute and quantum-resistant hash.
Tulip closes by grounding money in human time and attention: society rewards work with a claim on other people’s effort, making fair, resistant money “deeply important to the species.” He trimmed BTC while on a trading hot streak and unwilling to sit through the price action, yet still calls Bitcoin’s path to $1 million “destiny”: “It is still better than everything else ever invented.”
Full transcript
How are you, man?
Good. I'm good. How are you?
Big day for you. UPS brand.
You're part of it, dude.
First guest with the new overlays.
The first guest with the new overlay.
I think we've got to test them out. We break it in a little bit. The market looks pretty good.
Yeah. If you hold the right coins. The market looks good if you hold the 3 good coins.
So, what do you like right now? You've been flip-flopping a little bit. Everybody wants to talk crypto. They wanted to hear from you. What do you like right now? What are you interested in? What are the good coins? How are you thinking about it?
Yeah. Well, I like hype just as much as everybody else. I was very, very in love with Zcash before kind of all of the [__] today. And I am so sick about Bitcoin I could puke.
[Laughter]
That's pretty much my mental state right now. And then I have opinions on, of course, all the rest of the coins, but as far as anything that everybody's talking about—
I was going to try to cover the Zcash thing myself, and then you were teaching me about it on our stand-up today. So I was like, “Maybe you just come on and talk about it for 20 minutes.” Can you give us the summary on what just happened as it relates to Zcash—the drama? You're fighting one of my biggest bags, one of my most beloved bags. And you're a Zcash—
One of my biggest bags.
Yeah, you're— I don't know. I'm reading it and I'm like, “What's going on?” Give us the rundown on what happened with Zcash.
Yeah. So, essentially, a security engineer at Zotl or associated with Zcash discovered a potential exploit in the ZK circuit that is used for the Orchard pool. So, essentially, when you take your Zcash and shield it into Orchard, you're putting it into a smart contract of sorts that enshrines the behavior of the privacy pools, right? Those have their own logic.
He found this bug, and he's like, “Oh, they're being pretty cheeky about the language of the bug, saying it would have been able to do invalid-state transactions.” I mean, it seems like the honest way to read that is like there was a double-spend bug, right? Somebody could have exploited it to essentially spend the same amount of—
They explained it as having some amount of scalar-math-type stuff, where I was like, “Okay, I mean, I don't really get it, to be honest with you.”
But it's basically like, when you transition from transparent Zcash to shielded Zcash, you're playing by a different set of rules, right? Because they have to implement essentially a new way for the coin to work for it to be private. You can't just copy-paste the same code over. It has to do all the ZK logic and stuff, right?
It's possible that as you want it to behave the same way—send, receive—but just all in private, you can introduce a bug when you do that, right? And it seems like that was the case here.
So, what they did is, first, they did a soft fork to censor Orchard transactions. Essentially, they just rejected them. I think it was about a 24-hour time window, but for however long, they basically said, “Hey, everybody run this soft-fork software: miners, exchanges, wallet operators.” It basically means if anybody went to do a transaction within the Orchard pool, we would just ignore it, right? Not include the transaction.
The point of that was essentially, while they're trying to fix the bug, if somebody else had discovered the bug—
It's not going to work.
They could exploit it. But by blocking all transactions, it can't be exploited.
So then they fixed the bug, and then they did a hard fork that essentially moved the ZK circuit to this new valid logic that doesn't have the exploit anymore.
There's a lot of different pieces. The first piece is, let's be clear, it's just not good. I don't see how it's good that Zcash can ping everybody and be like, “Just ignore that these privacy pools exist.” They can instantly get everybody to do that, and then they can hit the network with a hard fork, and we're all just on this new network now.
I understand the response where people are like, “Oh, it was easy to coordinate because the bug was so serious.” So if there was a hyper-serious Bitcoin bug, maybe they'd coordinate too. But there is a hyper-serious Bitcoin bug. Right? So, at the end of the day, you just have to admit that it's a concerning amount of centralization.
Even though they did the right thing—it would have been worse to leave the bug in there for sure—it exposes and reminds us of, candidly, the value of Bitcoin not doing anything. That's problem number one: centralization.
Problem number two is the privacy pools, because Orchard is a follow-up to some other Zcash privacy pools, right? It was one of the big upgrades that made it super dope. But they operate on what's called the turnstile.
Okay.
So, essentially, if I deposit 10 ZEC and you deposit 10 ZEC into the pool, the network knows that there's 10 ZEC in the private pool. You and I can swap back and forth all day and it will be hidden, but they know the total amount.
That way, when I go to withdraw, I can't withdraw 30 ZEC because I put in 10 and you put in 10. The network knows there's only 20 ZEC.
But imagine I used this exploit and I really have 10 ZEC, but I sent a bunch of other wallets I own 10 ZEC on double-spends. Then I could just drain the pool, classic DeFi style. I could pull out all the way up the turnstile.
What that essentially means is the Zcash network still has the same known amount of tokens. But in the privacy pool, it could have been the case where, say, there's a million deposits in there, and some guy just went and created 17 million private tokens that nobody knows about because it's a privacy pool. Nobody knows it was actually exploited.
Now, he could only pull out the 1 million, but what happens if other people start to integrate, like, “Oh, I can buy this thing with private tokens. I don't ever have to leave the pool to buy a Chipotle burrito, or I don't ever have to leave the pool to do a transaction with NEAR Intents,” and you never know.
The thing I always thought was funny about privacy coins—one of my favorite bits—was that no one actually knows what the supply of an arrow is because it's private. There's no way to ever really know if there was some sort of double-spend or double-mint function exploit that happened at some stage.
Yeah. And think of it this way, right? You could also have reason to believe you wouldn't drain it right away. If I had all that private ZEC and I instantly pulled it out into the public pool, everybody would know and the exchanges would shut down. Everybody would shut down.
But why don't I just withdraw 1,000 ZEC every day and pay myself a permanent dividend until that pool is slowly drained? The problem is it just creates this uncertainty, right? And that uncertainty is kind of inherent to these private projects.
I think the Zcash turnstile mechanism is actually pretty clever, because Monero—you could have God knows how many coins, right?—and never prove it. Zcash, you can at least prove there's this many transparent possible coins, which is good.
So, the exposure is less, but I don't think it should be underplayed: the centralization and the level of concern that this created, at least for me.
The funniest bit about the whole thing is that it pumped on this news. Everyone was blowing my phone up about it. I looked at the chart and was like, “Oh, it's green. Why is everyone asking me questions about this?”
I think it basically says 2 things. One, people [__] hate Bitcoin right now. They don't care. They're just like, “I'll do anything to get out of it, right? I'm an indiscriminate diversifier of my Bitcoin.” That's the first thing it says.
The second thing it says is people just don't really understand this ZEC dynamic. They see it as just a network upgrade, which has been very normalized by Ethereum, Solana, and Hyperliquid, which is fine. But the thing to remember is those projects aren't money, right?
You go to sleep at night holding Bitcoin like a baby because you know Satoshi isn't going to post a blog the next morning saying, “Hey, I froze all your funds overnight.” That's why I sleep like a baby holding Bitcoin before all this quantum [__].
But look, I don't want to wake up and see a blog from Zuko ever.
[Laughter]
I only want to see 1 more blog from him in the rest of my life, and it's like, “Hey, here's the quantum-resistant plan. We've done the thing. ZK is quantum-resistant. We're done now.” That's it. That's the only thing I ever want to read from Zuko.
It's a problem.
It's a good take. It was crazy. It was green. So, what did you do? Did you sell Zcash?
No, no. So, okay. Yesterday, I have to break the news to anybody who's actually a Tulip fan: yesterday, I trimmed some Bitcoin. I—
You did it?
I did it. I did it.
Ever sold Bitcoin before?
No. No. It was—I hope I sold the bottom.
Looks like I didn’t, unfortunately.
You’ve never sold Bitcoin ever.
Ever.
You know, one of the reasons I told Malcolm we had to hire you at the kind of price you came on the stream was that I asked you what percentage of your net worth was in Bitcoin. You said 150%. I said, “What does that mean?” You said, “I’m on margin.” I’ll never—
Basically, it’s been an interesting story for me. Before, during that bull run, I was at 150% to 160%, depending on the price and the margin. Then we got into stocks and all that other stuff, and it’s kind of funny. I’ve basically been on one of the greatest trading hot streaks of my life, and for the first time ever, I was turning profits into HYPE instead of into Bitcoin.
My Bitcoin exposure went from 160% to 140% to 110% to 90%, normally just by not selling any, but by making money on all of these other assets. After essentially closing the last of my Bitcoin-based margin and then trimming the position, it’s a third of my portfolio right now.
What?
It’s crazy. In the last year, I’ve gone from 150% Bitcoin to 30% Bitcoin. It’s nuts.
Whoa. What pushed you over the edge? I felt bad because I felt like I was responsible. I’m not going to lie. I felt like I was partially responsible, and I felt bad this morning. I’m going to be honest.
Well, I think, one, Zcash was the first time I was actually really hedging Bitcoin. I was holding some Zcash because either Bitcoin doesn’t fix privacy—which, based on the coin audit, I’m not even sure Bitcoin should try to be private. Maybe Air Mas is right, and we should all just hide our Bitcoin from the IRS in mixing pools, and then it’s functionally private. You didn’t hear that from me.
As far as quantum goes, I’m also starting to think, look, maybe we let the quantum get hacked. They full-port, full-stack all the coins, liquidate Sailor, take Bitcoin to $4K, one last holy distribution, and then we rip it back to $2 million.
Funnily enough, what Zcash is teaching you right now is that there is actually something to be said about the network doing nothing ever. Say quantum is happening in 5 years. If you have a 7-year time horizon, that’s a problem. If you have a 70-year time horizon, those coins will get stolen, but then they’ll get distributed and sold.
The quantum problem comes again, right? You’ve solved quantum, you’re still proof of work, there have been zero soft forks, there have been zero asset seizures, and even the quantum transactions were playing by the rules. So it still remains the fairest crypto ever made. Now it’s secured by quantum compute, and it’s basically secured by quantum hash—real hash.
Long story short, I hedge with Zcash, and we reached the point where it’s not so easy as just buying Bitcoin and doing nothing.
Which is probably for the better, by the way.
Yes. That’s why HYPE is going up, right?
The markets don’t work like this, is what I’ve learned. You can’t just buy the guaranteed thing, log off for 4 months, and guarantee you’ll make money forever. Otherwise, it would be too efficient, and there’d be no opportunity to make any money.
Exactly. I think it used to be as simple as Bitcoin being essentially the crypto ETF. If you wanted to get cute, you would buy some ETH or Solana. But we saw that you can’t blindly hold ETH. Obviously, you can’t blindly hold Solana. So why would it be the case that you could blindly hold Bitcoin either?
At this point, hyper liquid, which is where all of these crypto tokens want to trade anyway, is a better crypto index than Bitcoin. You have exposure to crypto market cap, and therefore to growing volumes, which generates more fees. You also have exposure to the growth areas of equity perps, RWAs, and HIP-4 creating options contracts. It’s an ETF on Bitcoin. It’s an ETF on everything, basically.
So, yeah, I’m a third Bitcoin, a third HYPE, and a third Zcash. That obviously changes based on—
I’m kind of straddling, right?
On the privacy thing, just put a pin in it. Part of me feels like, listening to you talk about it, you would rather have existing currencies with the ability to shield transactions rather than a default private currency. Like the Near type of process, where you can make individual transactions private. You can go private by choice if you want, but the currency doesn’t have to be private by default, because it comes with a plethora of problems if you start private.
Yeah. Well, this is the Near thesis, right? And this is the—yeah, I don’t know.
All right, here you go. Bring it back.
Right, right, right. I mean, this is the Nym thesis and the Railgun thesis, right? Make it so you tap into privacy and then tap out of privacy, and it can just exist at the protocol level. It doesn’t need to exist at the base layer.
Yeah.
Competing protocols could have competing implementations. People pick the most secure one with the best integrations and best liquidity, and we move on. I don’t hate that conclusion, honestly.
Yeah. Damn. Okay, give me a mini altseason take, if you have one. People want some bull porn. How do you think it plays out from here?
At this point, HYPE has to continue performing. What HYPE is telling the market is that revenue actually matters. The other thing it’s telling the market is that buybacks and caring about the token is better.
The Helium Foundation kind of rugged everybody. What was the one deal where Axelar was bought by Coinbase and kind of rugged everybody? No more of these toxic acquisitions where the holders have no rights. No more of this, “I’m going to turn buybacks on and off.” Put the revenue on-chain, put the buybacks on-chain, and just swap the token ad infinitum. That is becoming the winning tokenomics model, which is exactly what we’ve always wanted to happen.
First and foremost, HYPE just needs to keep going up. If it does, the real bull case for anybody who wants to get back to meme-coin-level returns is that there’s an army of crypto projects that actually make decent money, and make really decent money compared to their market caps.
To avoid shilling small tickers, go on DeFi Llama, look at the revenue tab, and see which of these projects actually make money. You have to be careful, because you’re making 2 bets: that they’re making money and will continue to grow, and that the team will make the right decisions to align that revenue with the token.
One example of it going the other direction is Collector Crypt Cards. You have their official handle tweeting that this is a valueless meme coin. I think they’re maybe being cheeky because they keep signaling some level of concern about the SEC and stuff. If they’re scared of being sued, whatever, I guess. But that’s a revenue-generating project that told you it’s a meme coin. I don’t know why anyone’s buying that thing. That’s the most toxic investor relations you can imagine.
It’s an army of minefields, but there’s a whole range of tokens in the $10 million to $50 million range that, honestly, if they just did the right things and showed steady leadership, could all re-rate 10x. They’re not going to be multi-tens-of-billions-of-dollar protocols like HYPE, but their margins are good. Why not trade at $100 million or $80 million? There are multiple after multiple to be found in these low-revenue-generating projects if the teams can just get their heads out of their asses.
That’s a good take. Also, Live Life TV, thank you for the five gifted. I’m not even going to say pump fun. I’m not going to say it. I like the way you think about it. I think HYPE has to perform. If HYPE stops performing, we have big problems on our hands. This is why I get scared every time there’s a mini-run and everyone’s like, “Okay, we’re buying Worldcoin. Okay, we’re buying everything.” We’re just ripping high-beta alts.
Thank you for coming on and giving us your Zcash thesis. Give me a Bitcoin thesis from here. I know you kind of talked about it, but you’re a decent amount of my conviction. Give me a little Bitcoin sauce before you leave. I’ll let you go after, but give me something, dude. And don’t say $4K again. Give me something before you go—a way to think about it. Give me something.
Yeah, I do. I don’t want to hit it with “the world is going to end, so you have to long Bitcoin,” but it remains the same. It is the hardest, most pure asset.
It is resistant to political forces. To screw with it, it might even just ignore quantum. It might just say, “Screw it. We don’t care about quantum. We’re just going to go straight through it. Hack the coins, market-sell them.” In the next 10 minutes, there’s going to be a block, and 10 minutes after that, there’s going to be another block. “Screw you, we’re not changing the rules,” right?
That is the most resolute symbol of this currency being what it is: take it or leave it. That has been the entire value proposition the whole time, right? Society—money is what you get for spending your time on things. You work on things, give them your attention, and put time and brainpower into them. Your reward from society is money, which is then your claim to other people’s time and attention.
It is deeply important to the species that we have fair and equitable money that is as hard, resistant, and true as possible, and that never changes the rules. We’re all playing the same game, no matter where you are in the world or who you are. You still have to believe that. It is so deeply important for society and humanity, and it’s going to make the world so much better. How could it not go to $1 million, then $10 million, then $100 million, and eventually—pick your line—where 1 BTC equals 1 BTC?
As bearish as I am, and as much as I didn’t want to sit through this price action because I’m on a trading hot streak, it’s destiny. It’s going to go to $1 million because it is still better than everything else ever invented. Thank God for Satoshi.
There he is.
There you go.
There he is. There’s a parallel universe somewhere where you are Michael Saylor, and you never did the weird dividends thing.
I’ll tell you what: if I were Michael Saylor, I would have fucking died before selling. I would not. They’d have to drag me out.
Ah, thank you, bro. 2Up King, you’re the GOAT. By the way, you want one for the chat as well. He is on a generational trading streak, I’m not going to lie. He’s on a Jenny trading streak, and—
Pharma next. We’re ripping Pharma next.
Yeah, we’re ripping Pharma. I like it. I like it a lot. Dude, you’re the GOAT. Anything final? Thank you for coming on for a quick one. I think it was time for a quick little banger. Anything else you want to add? You’re the GOAT.
No, that’s all I’ve got. It’s a pleasure. Let’s enjoy the new brand and the new overlays, everybody. Let’s have—
They want to know what that book is behind you.
This book? More Money Than God.
They can’t see that one. That one they want to know about.
This book, Daemon. It’s about an AI that takes over after some guy dies.
Oh, nice. Nice, man.
Yeah, very topical research.
Cool, dude.
Yeah, yeah, yeah. This one’s a tour book of Japan.
Ah, there you go. It’s beautiful. You’re the GOAT. Tulip King, you’re the fucking man, dude. Thanks for coming on. It’s always a pleasure.
Yeah, yeah.
All right, brother. See you on our call in a couple of hours.
Yeah, I’ll see you in 20 minutes.
I’ll see you in 30 minutes, yeah. All right, peace, brother.
Yeah, yeah.