AI uncovers long-hidden flaw in Zcash privacy pool

Security engineer Taylor Hornby used an AI model to identify a critical vulnerability in the Zcash cryptocurrency that had remained undetected since 2022. The flaw could have permitted unlimited creation of counterfeit tokens. Hornby has now added Monero to his list of planned audits.

Hornby employed Anthropic’s Opus 4.8 AI model to locate the bug in Zcash’s Orchard privacy pool. The vulnerability dated back to May 2022 and could have allowed an attacker to mint undetectable counterfeit ZEC. He discovered the issue on May 29 while working for the nonprofit Shielded Labs. Shielded Labs disclosed the flaw on Thursday and implemented an emergency fix by June 1. Zcash fell 38 percent in the following 24 hours as concerns spread about possible undetected theft from the shielded pool. Hornby said he reported the bug rather than exploiting it because Zcash developers were “like family” and he could “not live with that kind of betrayal.” He plans to apply for a Zcash coinholder grant to continue his work. Asked on X about other privacy coins, Hornby replied that he will add Monero to his audit queue.

संबंधित लेख

Illustration of Zcash price drop after Orchard vulnerability disclosure showing cracked shield and falling chart
AI द्वारा उत्पन्न छवि

Zcash price falls after Orchard bug disclosure

AI द्वारा रिपोर्ट किया गया AI द्वारा उत्पन्न छवि

Zcash token ZEC dropped sharply after developers disclosed a vulnerability in the Orchard shielded pool that could have allowed undetected counterfeiting of tokens. The flaw, present since 2022, was found on May 29 using an AI model and patched by June 1. No evidence of exploitation was found, though privacy features prevent cryptographic proof.

Zcash has recovered about 45 percent from its recent low after developers proposed the Ironwood upgrade to address a supply verification issue. The privacy-focused cryptocurrency traded near $437 on Monday, though it remains down 22 percent for the week. The move comes after a patched bug in the Orchard pool triggered last week's sell-off.

AI द्वारा रिपोर्ट किया गया

Anthropic has released a new cyber-focused AI model called Mythos, capable of detecting software flaws faster than humans and generating exploits. The model has raised alarms among governments and companies for potentially turbocharging hacking by exposing vulnerabilities quicker than they can be patched. Officials worldwide are scrambling to assess the risks.

Anthropic has limited access to its Claude Mythos Preview AI model due to its superior ability to detect and exploit software vulnerabilities, while launching Project Glasswing—a consortium with over 45 tech firms including Apple, Google, and Microsoft—to collaboratively patch flaws and bolster defenses. The announcement follows recent data leaks at the firm.

AI द्वारा रिपोर्ट किया गया

Trezor has revealed a vulnerability in the TROPIC01 secure element chip used in its Safe 7 hardware wallet. The company said the issue does not put user funds at risk.

A private key compromise led to a drain of more than $520,000 from a Polymarket-linked wallet on the Polygon blockchain on May 22. The prediction market platform confirmed that user funds and core contracts remained unaffected.

AI द्वारा रिपोर्ट किया गया

LayerZero has acknowledged it made a mistake by allowing its own verifier network to secure high-value assets in a vulnerable setup. The admission comes weeks after a $292 million hack on Kelp DAO that the company had initially blamed on the developer. The firm says its core protocol remained unaffected.

 

 

 

यह वेबसाइट कुकीज़ का उपयोग करती है

हम अपनी साइट को बेहतर बनाने के लिए विश्लेषण के लिए कुकीज़ का उपयोग करते हैं। अधिक जानकारी के लिए हमारी गोपनीयता नीति पढ़ें।
अस्वीकार करें