A security researcher used AI-assited auditing to uncover a major flaw in the Zcash protocol that could have allowed undetectable counterfeit ZEC inside the networkA security researcher used AI-assited auditing to uncover a major flaw in the Zcash protocol that could have allowed undetectable counterfeit ZEC inside the network

How One Guy Used Claude Code to Discover a Billion-Dollar Bug

2026/06/10 15:08
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Taylor Hornby, a security researcher who works with Shielded Labs, discovered a bug on May 29, 2026 – just one day after Anthropic released Opus 4.8- that resulted in billions of dollars removed from the project’s market capitalization.

The flaw affected a shielded pool within the protocol’s design that powered private Zcash transactions, and was serious enough to trigger an emergency response across the entire ecosystem. It resulted in a sudden sell-off that saw ZEC’s price crash by roughly 60%, thereby erasing more than $4 billion in market cap.

The short version of the story is relatively simple: a missing constraint in Zcash’s Orchard circuit could have allowed a malicious prover to spend the same shielded note many times over while producing different nullifiers. In practice, this means an attacker could have inflated ZEC within the Orchard pool without leaving an on-chain fingerprint.

The scary part is that this bug has existed since Orchard went live, and this happened in May 2022. Therefore, the total exposure window lasted for around four years, before it was ultimately patched shortly after Hornby discovered it.

AI Helped Find The Critical Vulnerability

This story isn’t just about the flaw, but the way it was found.

Hornby said he used a custom “zcash-full-stack-auditor” agent framework with Claude Opus 4.8. It was designed to work at maximum effort and was pointed at the halo2 implementation, including the Orchard circuit. The AI was searching for soundness and zero-knowledge security issues.

The researcher reported that around 6 p.m. on May 29, one of the audit agents flagged a vulnerability that it believed could be used to double-spend Orchard notes. Hornby then used Claude to help write proof-of-concept code against a similar circuit, before testing the issue against the real Orchard circuit.

Testing the Exploit with Claude

Hornby later built a full test in Zcash’s local regtest mode, where the exploit doubled the value of an Orchard note until the test wallet balance exceeded 10 million ZEC. These transactions were never broadcast to mainnet or testnet, of course, but the test itself was significant because regtest applies the exact same validation rules, meaning that it could have been done on mainnet with the same degree of success.

Per the official disclosure, the full PoC took roughly six hours to develop using Claude Code’s help. Hornby said the model needed relatively little guidance beyond a few hints.

Of course, it’s important to understand that this doesn’t mean that AI independently “hacked Zcash.”

Taylor Hornby is a renowned specialist security researcher. That audit was targeted, and the tools were custom-built.

Still, the case shows how some frontier AI models are beginning to significantly reduce the time required to investigate highly complex, technical systems.

The post How One Guy Used Claude Code to Discover a Billion-Dollar Bug appeared first on CryptoPotato.

시장 기회
Major 로고
Major 가격(MAJOR)
$0.03731
$0.03731$0.03731
-4.08%
USD
Major (MAJOR) 실시간 가격 차트

Predict & Trade to Win Rewards

Predict & Trade to Win RewardsPredict & Trade to Win Rewards

Guaranteed rewards with $500,000 prize pool

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage