But we should make it clear that the vulnerability was not exploited. The vulnerability was found by zcash with the help of Taylor Hornby a security engineer.
How can anyone say that the vulnerability was not exploited. Is it possible for anyone to cryptographically prove that no one has exploited them. You cannot simply decrypt the Orchard pool to count the coins. As per the reports this critical flaw was unnoticed for 4 years.
~
But on the other hand this warns all projects in the crypto space, it would be great if all of them upgrade their flaws and in the future no project will be arbitrary so that security will definitely be improved from any aspect.
This case is not about upgrading the flaws. It was an issue of omission within the logic rules which is the most important part. Since the error did not produce a syntax errors, it took 4 years to identify.
