< Back to all clusters
[TECHNOLOGY] · UN · 2 sources

started · updated

AI uncovers long-hidden vulnerabilities in Zcash and crypto code

Artificial intelligence is increasingly being used to identify long-standing vulnerabilities in cryptocurrency code that human researchers previously overlooked. In a recent audit, Shielded Labs utilized Anthropic’s Claude Opus 4.8 to uncover a four-year-old flaw in the Zcash Orchard shielded-pool circuit. This vulnerability, a soundness failure, could have allowed an attacker to generate unlimited counterfeit ZEC without detection. Developers patched the issue by early June, and no actual theft was confirmed.

AI-driven analysis has also highlighted older security gaps, such as a 2021 Coldcard firmware error involving insufficient randomness in seed generation. This flaw is linked to an estimated $112.7 million in Bitcoin thefts across more than 8,600 addresses. Additionally, Chainalysis reports a 440% increase in malicious on-chain dead-drop activity, suggesting that AI is lowering the barrier to entry for building attack infrastructure.

Beyond code analysis, AI has been involved in direct exploitation scenarios. In one instance, an attacker used Morse code on social media to manipulate an AI agent into transferring approximately 3 billion DRB. Experts note that while AI is not necessarily breaking cryptographic primitives, it is significantly accelerating the ability to find logical errors, reverse-engineer smart contracts, and automate the deployment of malicious instructions.

Entities

Anthropic · Chainalysis · Coldcard · Shielded Labs · Zcash