Zcash patch restores market after critical counterfeit‑token flaw
Security researcher Taylor Hornby disclosed a critical vulnerability in Zcash’s Orchard shielded pool that had existed since its launch in May 2022. Using the AI model Claude Opus 4.8, Hornby demonstrated how the flaw could allow unlimited creation of counterfeit ZEC tokens. The issue was reported privately on May 29 and publicly disclosed shortly thereafter, prompting an emergency network patch on June 2.
The market reaction was swift: ZEC fell more than 40 % in a day, erasing much of its recent rally, before recovering after the patch. Developers stated there is no evidence the bug was ever exploited, but the incident raised concerns about the credibility of privacy‑focused cryptocurrencies. Hornby plans to extend AI‑assisted audits to other privacy coins, notably Monero, highlighting the growing role of artificial intelligence in blockchain security.
The episode underscores the challenges of verifying supply in fully shielded pools and may influence future formal‑verification efforts and investor confidence in Zcash and similar assets.