An AI model discovered a critical vulnerability that had lain hidden in privacy-focused cryptocurrency Zcash for four years — and a subsequent AI audit found no new flaws in the protocol.
Security researcher Taylor Hornby, who works for Zcash's research and development organization, used Anthropic's AI model Claude Opus 4.8 on May 29 to identify a vulnerability in a zero-knowledge proof circuit within the Zcash blockchain, according to Bloomberg and other international media reports on Sunday.
The flaw had gone undetected through expert reviews since May 2022.
The potential impact was serious: a malicious actor who had found it first could have forged an unlimited supply of Zcash tokens.
The Zcash Foundation said it found no evidence the vulnerability had been exploited, but the token's price tumbled 38 to 50 percent within 48 hours of the disclosure.
Developers moved quickly to contain the damage. They halted all transactions on June 2 and patched parts of the system, then pushed a full update the following day that addressed the flaw entirely.
After the emergency patch, Zcash asked Anthropic to conduct an additional security review. Anthropic deployed its unreleased AI model "Mythos" to re-examine the entire Zcash protocol.
Zcash founder Zooko Wilcox said Saturday on X, formerly Twitter, that "Mythos conducted a security audit of Zcash and found no additional serious bugs in the protocol."
Eli Ben-Sasson, who was involved in Zcash's early development, warned Bloomberg that malicious hackers will sometimes find and exploit bugs before they are disclosed. "More exploitation cases will occur," he said.
dbsdn1110@heraldcorp.com
