Only $3 for a DoS attack on Zcash

By Alfredo de Candia - 27 Aug 2019

DoS is a type of cyber attack that would cost only $3 a day to cause problems to the Zcash network. It was revealed by the mathematician Duke Leto who, in a recent tweet, reported the bug, criticising Zcash for not having solved it yet.


The Denial of Service (DoS) allows attacking any blockchain that uses the sapling protocol of Zcash 2.x. The severity of the attack depends on the blockchain values relative to the maximum size of the transactions and the maximum size of the block: a small number of machines is sufficient to block the entire network, as currently, the figure is 0.0576 ZEC per day.

The protocol has been listed with the name CVE-2019-11636 in the vulnerability database, explaining:

“Zcash 2.x allows an inexpensive approach to “fill all transactions of all blocks” and “prevent any real transaction from occurring” via “Sapling Wood-Chipper” attack.”

This protocol takes advantage of the fees of the Zcash blockchain, which by default are 0.0001 ZEC.

Leto hopes, as mentioned in the tweet, to have greater transparency on the fees and on the entire project so as to be able to intervene. This kind of DoS attack could be used to make unusable the blockchain which is already facing an uncertain period. The project could even be abandoned in the future, as declared by CEO Zooko Wilcox.


Android developer for over 8 years with a dozen of developed apps, Alfredo at age 21 has climbed Mount Fuji following the saying: "He who climbs Mount Fuji once in his life is a wise man, who climbs him twice is a Crazy". Among his app we find a Japanese database, a spam and virus database, the most complete database on Anime and Manga series birthdays and a shitcoin database. Sunday Miner, Alfredo has a passion for crypto and is a fan of EOS.

