AUTO-UPDATED

Claude Opus Found a Four-Year-Old Hole in Zcash’s Privacy Layer. Nobody Knows If Someone Already Used It.

Security researcher Taylor Hornby utilized Anthropic’s Claude Opus 4.8 AI model to discover a critical, four-year-old vulnerability in the Zcash Orchard privacy pool that could have enabled counterfeit transactions.

Key Points

  • The vulnerability existed from the Orchard pool's launch in May 2022 until an emergency patch was deployed on June 1, 2026.
  • The flaw allowed for the potential creation of counterfeit ZEC that would appear legitimate due to the system's zero-knowledge proof architecture.
  • Because of the network's privacy features, it is impossible to cryptographically verify whether the exploit was utilized by bad actors prior to the fix.
  • Following the disclosure, the price of ZEC dropped 43%, reaching a low of $250.
  • Shielded Labs is proposing a "turnstile accounting" network upgrade to force all existing coins through a checkpoint to verify the integrity of the total supply.

Why it Matters

This incident demonstrates that advanced AI models can rapidly identify complex cryptographic flaws that have evaded human review for years. It raises significant concerns regarding the security of existing blockchain protocols and highlights the difficulty of auditing privacy-focused systems where exploitation may remain permanently undetectable.
Securityaffairs.com Published by Pierluigi Paganini
Read original