A security researcher used AI-assited auditing to uncover a major flaw in the Zcash protocol that could have allowed undetectable counterfeit ZEC inside the networkA security researcher used AI-assited auditing to uncover a major flaw in the Zcash protocol that could have allowed undetectable counterfeit ZEC inside the network

How One Guy Used Claude Code to Discover a Billion-Dollar Bug

2026/06/10 15:08
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Taylor Hornby, a security researcher who works with Shielded Labs, discovered a bug on May 29, 2026 – just one day after Anthropic released Opus 4.8- that resulted in billions of dollars removed from the project’s market capitalization.

The flaw affected a shielded pool within the protocol’s design that powered private Zcash transactions, and was serious enough to trigger an emergency response across the entire ecosystem. It resulted in a sudden sell-off that saw ZEC’s price crash by roughly 60%, thereby erasing more than $4 billion in market cap.

The short version of the story is relatively simple: a missing constraint in Zcash’s Orchard circuit could have allowed a malicious prover to spend the same shielded note many times over while producing different nullifiers. In practice, this means an attacker could have inflated ZEC within the Orchard pool without leaving an on-chain fingerprint.

The scary part is that this bug has existed since Orchard went live, and this happened in May 2022. Therefore, the total exposure window lasted for around four years, before it was ultimately patched shortly after Hornby discovered it.

AI Helped Find The Critical Vulnerability

This story isn’t just about the flaw, but the way it was found.

Hornby said he used a custom “zcash-full-stack-auditor” agent framework with Claude Opus 4.8. It was designed to work at maximum effort and was pointed at the halo2 implementation, including the Orchard circuit. The AI was searching for soundness and zero-knowledge security issues.

The researcher reported that around 6 p.m. on May 29, one of the audit agents flagged a vulnerability that it believed could be used to double-spend Orchard notes. Hornby then used Claude to help write proof-of-concept code against a similar circuit, before testing the issue against the real Orchard circuit.

Testing the Exploit with Claude

Hornby later built a full test in Zcash’s local regtest mode, where the exploit doubled the value of an Orchard note until the test wallet balance exceeded 10 million ZEC. These transactions were never broadcast to mainnet or testnet, of course, but the test itself was significant because regtest applies the exact same validation rules, meaning that it could have been done on mainnet with the same degree of success.

Per the official disclosure, the full PoC took roughly six hours to develop using Claude Code’s help. Hornby said the model needed relatively little guidance beyond a few hints.

Of course, it’s important to understand that this doesn’t mean that AI independently “hacked Zcash.”

Taylor Hornby is a renowned specialist security researcher. That audit was targeted, and the tools were custom-built.

Still, the case shows how some frontier AI models are beginning to significantly reduce the time required to investigate highly complex, technical systems.

The post How One Guy Used Claude Code to Discover a Billion-Dollar Bug appeared first on CryptoPotato.

Market Opportunity
Major Logo
Major Price(MAJOR)
$0.03795
$0.03795$0.03795
+0.44%
USD
Major (MAJOR) Live Price Chart

Predict & Trade to Win Rewards

Predict & Trade to Win RewardsPredict & Trade to Win Rewards

Guaranteed rewards with $500,000 prize pool

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Adoption Leads Traders to Snorter Token

Adoption Leads Traders to Snorter Token

The post Adoption Leads Traders to Snorter Token appeared on BitcoinEthereumNews.com. Largest Bank in Spain Launches Crypto Service: Adoption Leads Traders to Snorter Token Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Leah is a British journalist with a BA in Journalism, Media, and Communications and nearly a decade of content writing experience. Over the last four years, her focus has primarily been on Web3 technologies, driven by her genuine enthusiasm for decentralization and the latest technological advancements. She has contributed to leading crypto and NFT publications – Cointelegraph, Coinbound, Crypto News, NFT Plazas, Bitcolumnist, Techreport, and NFT Lately – which has elevated her to a senior role in crypto journalism. Whether crafting breaking news or in-depth reviews, she strives to engage her readers with the latest insights and information. Her articles often span the hottest cryptos, exchanges, and evolving regulations. As part of her ploy to attract crypto newbies into Web3, she explains even the most complex topics in an easily understandable and engaging way. Further underscoring her dynamic journalism background, she has written for various sectors, including software testing (TEST Magazine), travel (Travel Off Path), and music (Mixmag). When she’s not deep into a crypto rabbit hole, she’s probably island-hopping (with the Galapagos and Hainan being her go-to’s). Or perhaps sketching chalk pencil drawings while listening to the Pixies, her all-time favorite band. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/banco-santander-and-snorter-token-crypto-services/
Share
BitcoinEthereumNews2025/09/17 23:45
PAIR Finance accelerates in France and Appoints Thomas Duvacher as Managing Director

PAIR Finance accelerates in France and Appoints Thomas Duvacher as Managing Director

PAIR Finance, Europe’s leading AI-based digital debt collector, has announced the appointment of Thomas Duvacher as Managing Director of PAIR Finance France. This
Share
ffnews2026/06/10 17:00
Vinyl Equity Raises $20 Million Led by Jump Capital as Its Infrastructure Powers Modern Capital Markets and Corporate Transactions

Vinyl Equity Raises $20 Million Led by Jump Capital as Its Infrastructure Powers Modern Capital Markets and Corporate Transactions

Supports newly public companies like Neptune Insurance Holdings Inc. following its NYSE listing Vinyl Equity, a financial technology infrastructure company for
Share
Globalfintechseries2026/06/10 17:41

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage