Skip to content
October 21, 2025Cryptopolitan logoCryptopolitan

Blockchain investigator finds traceability issue in Zashi wallet cross-chain feature

Blockchain investigator ZachXBT has uncovered a privacy vulnerability in the Zashi wallet’s integration with cross-chain transaction protocol NEAR ￰0￱ independent researcher wrote an X thread on Tuesday saying he tested the system to find “design flaws he could abuse,” during his investigations for fraudulent ￰1￱ is a self-custody crypto wallet developed by Electric Coin Co. the team behind Zcash (ZEC) a privacy-oriented cryptocurrency launched in ￰2￱ wallet allows users to send receive

and spend ZEC while keeping their financial activity hidden from intermediaries corporations or government ￰3￱ wrote about how he tested Zashi’s integration with NEAR Intents because of the “recent hype,” wondering if it kept the same level of anonymity Zcash users expect from shielded ￰4￱ identifies privacy flaw in moving SOL to Zcash In his experiment ZachXBT bridged 1 SOL from Solana to Zcash using NEAR Intents to Zashi ￰5￱ then shielded the funds for privacy after confirming both the source and destination ￰6￱ blockchain security sleuth then used Zashi’s “CrossPay” feature

which lets users spend shielded ZEC and send equivalent value in another crypto to fund an Ethereum address with 0.005 ETH. 3/ Now let’s say I want to anonymously fund an ETH address from my Zashi wallet with my shielded ZEC so I use the “Crosspay” feature via Near Intents to receive 0.005 ETH to the following address: 0x6dda3649f19191a9df465f4010019f2f59c34bc4 ￰7￱ — ZachXBT (@zachxbt) October 21 2025 While the main transfer completed after several minutes ZachXBT discovered an unexpected refund transaction of 0.001598 ZEC sent to the same transparent address from which he had originally shielded the ￰8￱ to the well-followed crypto security investigator

the automatic refund created a visible link between his shielded and unshielded addresses undermining the privacy that Zcash’s shielded system is meant to ￰9￱ Wallet Near Intents transaction reveals shielded address.

Cryptopolitan logo
Cryptopolitan

Latest news and analysis from Cryptopolitan

October Crypto Hacks Decline 86% to $18M, Signaling Possible Security Gains

October Crypto Hacks Decline 86% to $18M, Signaling Possible Security Gains

October 2025 crypto hacks resulted in just $18.18 million stolen across 15 incidents, an 85.7% drop from September’s $127.06 million losses, according to PeckShield data. This decline highlights stren...

CoinOtag logoCoinOtag
1 min
US-China Trade Deal May Aid Bitcoin Recovery as Fear Index Shows Slight Uptick

US-China Trade Deal May Aid Bitcoin Recovery as Fear Index Shows Slight Uptick

The US-China trade deal announced in 2025 has sparked cautious optimism in the crypto market, with the Crypto Fear & Greed Index rising to 37 from 33, signaling a shift...

CoinOtag logoCoinOtag
1 min
China and South Korea Sign 400 Billion Yuan Swap to Potentially Boost Regional Ties

China and South Korea Sign 400 Billion Yuan Swap to Potentially Boost Regional Ties

China and South Korea’s new five-year bilateral currency swap agreement, valued at 70 trillion won ($49.24 billion), aims to reduce reliance on the US dollar in Asian trade, potentially boosting...

CoinOtag logoCoinOtag
1 min