In short
- Security researcher Taylor Hornby used Claude Opus 4.8 to discover a four-year-old flaw in Zcash’s Orchard privacy pool that could have allowed for unlimited creation of fake ZECs.
- Cybersecurity researchers say groundbreaking AI models are increasingly able to find cryptographic and logical flaws that previously required deep specialist expertise.
- Experts warn that capabilities approaching the most advanced vulnerability discovery systems could become widely available within months.
A security researcher using Anthropic’s Claude Opus 4.8 discovered a critical flaw in Zcash’s Orchard privacy pool within days, exposing a vulnerability that had survived four years of research by leading zero-knowledge cryptographers.
The revelation sent ZEC down about 38% on Thursday and raised broader concerns for the crypto industry around frontier AI models that are becoming increasingly adept at finding vulnerabilities than most humans.
“The meaning isn’t really that AI can find bugs,” says Ben Goertzel, founder and CEO of SingularityNETtold Declutter. “It’s that the kind of bug it can find now has changed.”
Rather than simply flagging obvious coding errors, boundary models are increasingly able to reason about whether software behaves as its designers intended, he said.
In May, Taylor Hornby, a security researcher hired by Shielded Labs, discovered a critical flaw in Zcash’s Orchard circuit with help from Anthropic’s Claude Opus 4.8. Hidden in two lines of code, the bug stemmed from a check that appeared to validate transaction input but did not actually enforce the intended rules, potentially allowing an attacker to create fake ZEC in the shielded pool without detection. Hornby built a working exploit to verify the vulnerability before reporting it to developers. An emergency solution was deployed on June 1.
Adding to the panic that hit Zcash and the broader crypto market on Thursday and Friday is the fact that the flaw had gone undiscovered for more than four years.
For Goertzel, the discovery is important not only because AI has found a vulnerability, but also because it points to a new model for security research.
“I think this is an early sign of a shift that will be hard to overestimate,” he said. “The model of security research, where a handful of respected human specialists conduct slow, artisanal, and highly skilled audits, is not going away, but it is no longer the whole game.”
Goertzel said the Orchard flaw belongs to a class of subtle logic bugs that groundbreaking AI models are increasingly finding, including smart-contract errors, access control errors and situations where software behaves differently than its designers intended. As these capabilities improve, he added that security research will shift to a model in which human specialists oversee ongoing AI-driven assessments that can analyze codebases much more comprehensively than traditional audits.
The Zcash answer itself could offer a taste of that future, Goertzel said.
“Shielded Labs specifically bringing in a researcher to find protocol-level errors with a boundary model before a malicious actor could do so is, I suspect, the template and not the exception,” Goertzel said. “Proactive, AI-enhanced adversarial assessment is becoming a commitment, and the protocols that don’t adopt this will increasingly be the ones that learn their vulnerabilities from the attacker rather than from a friendly attacker.”
According to Sean Ren, CEO of Sahara AI and professor of computer science at the University of Southern California, advances in AI are also changing the balance between attackers and defenders, as frontier models can quickly test attack strategies, learn from the results, and discover weaknesses.
“To build better defenses, we must use these groundbreaking AI models as potential attackers to test these systems,” Ren told us. Declutter.
Ren said blockchain networks are especially vulnerable because their open-source code can be directly analyzed by advanced AI models, which can quickly test attack strategies and identify vulnerabilities faster than traditional security assessments.
“If you think about frontier model labs like OpenAI, Anthropic and Google DeepMind, they are more likely to have access to the strongest unpublished models and can run a lot of experiments on public network systems like blockchains, so they have the power at their fingertips,” he said. “If someone with malicious intent had access to these capabilities, they could carry out attacks and create vulnerabilities.”
That window could close sooner than many expect, and according to Danny Jenkins, CEO and co-founder of cybersecurity firm ThreatLockerImproves AI-powered vulnerability detection faster than many organizations can secure the software they already rely on.
“We have a huge gap that will take years and years to overcome,” Jenkins told me Declutter. “All this software will have all these vulnerabilities, we won’t have any fixes or updates for them for a long time, and people will be able to find these vulnerabilities very quickly.”
Jenkins said that AI is not so much fundamentally changing vulnerability research as dramatically accelerating it. Tasks that once required security researchers to review code and manually reverse engineer software can now be accomplished in seconds by modern models.
“Pre-AI, cyber threats and exploits were increasing every year,” he said. “Post-AI has gotten even faster, and I think it’s gotten faster for two reasons. One is that you can now use AI to help find vulnerabilities and exploits, and the number of people who are able to do that has grown tremendously. You don’t have to be a script kiddie now.”
Despite these risks, Goertzel argued that crypto may also be better positioned than other industries to adapt because its code is open and its communities are highly security-oriented.
“Crypto is closest to the door, but it is also the part of the room that can see the door coming,” he said.
Daily debriefing Newsletter
Start every day with today’s top news stories, plus original articles, a podcast, videos and more.