cryptd.in

암호화폐 친화적인 인재를 위한 대체 링크드인

How One Guy Used Claude Code to Discover a Billion-Dollar Bug

Taylor Hornby, a security researcher who works with Shielded Labs, discovered a bug on May 29, 2026 – just one day after Anthropic released Opus 4.8- that resulted in billions of dollars removed from the project’s market capitalization.

The flaw affected a shielded pool within the protocol’s design that powered private Zcash transactions, and was serious enough to trigger an emergency response across the entire ecosystem. It resulted in a sudden sell-off that saw ZEC’s price crash by roughly 60%, thereby erasing more than $4 billion in market cap.

The short version of the story is relatively simple: a missing constraint in Zcash’s Orchard circuit could have allowed a malicious prover to spend the same shielded note many times over while producing different nullifiers. In practice, this means an attacker could have inflated ZEC within the Orchard pool without leaving an on-chain fingerprint.

The scary part is that this bug has existed since Orchard went live, and this happened in May 2022. Therefore, the total exposure window lasted for around four years, before it was ultimately patched shortly after Hornby discovered it.

AI Helped Find The Critical Vulnerability

This story isn’t just about the flaw, but the way it was found.

Hornby said he used a custom “zcash-full-stack-auditor” agent framework with Claude Opus 4.8. It was designed to work at maximum effort and was pointed at the halo2 implementation, including the Orchard circuit. The AI was searching for soundness and zero-knowledge security issues.

The researcher reported that around 6 p.m. on May 29, one of the audit agents flagged a vulnerability that it believed could be used to double-spend Orchard notes. Hornby then used Claude to help write proof-of-concept code against a similar circuit, before testing the issue against the real Orchard circuit.

Testing the Exploit with Claude

Hornby later built a full test in Zcash’s local regtest mode, where the exploit doubled the value of an Orchard note until the test wallet balance exceeded 10 million ZEC. These transactions were never broadcast to mainnet or testnet, of course, but the test itself was significant because regtest applies the exact same validation rules, meaning that it could have been done on mainnet with the same degree of success.

Per the official disclosure, the full PoC took roughly six hours to develop using Claude Code’s help. Hornby said the model needed relatively little guidance beyond a few hints.

Of course, it’s important to understand that this doesn’t mean that AI independently “hacked Zcash.”

Taylor Hornby is a renowned specialist security researcher. That audit was targeted, and the tools were custom-built.

Still, the case shows how some frontier AI models are beginning to significantly reduce the time required to investigate highly complex, technical systems.

게시물 How One Guy Used Claude Code to Discover a Billion-Dollar Bug 에 처음 등장 크립토포테이토.


댓글

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다

최신 피드

인기 카테고리

웹사이트 검색

인기 스토리

태그

#AlexeyPertsev (1) #BidenCryptoBan (1) #BidenElection (1) #BinanceVsCoinbase (1) #B비트코인 (447) #BitcoinETF (3) #B비트코인기초 (1) #B비트코인 취급 (1) #B비트코인가격 (5) #B비트코인가격수준 (1) #B비트코인펌프 (1) #B비트코인예치 (1) #B비트코인서지 (1) #BitcoinTop (1) #Bitfinex (1) #B비트 단위 (1) #브레이스브리지캐피털 (1) #BRC20토큰 (1) #BTC취득 (1) #B울리스틱 예측 (1) #BullishSentiment (1) #C중국광업 (1) #CPIP리뷰 (1) #CryptoAsset (2) #CryptoBattle (1) #CryptoBoom (1) #CryptoExpert (1) #CryptoInsights (1) #CryptoMania (1) #CryptoMarket (4) #CryptoPrediction (1) #CryptoPredictions (1) #CryptoRegulation (2) #CryptoTakeoff (1) #CryptoTiming (1) #CryptoTips (1) #CryptoTreasury (1) #CryptoUncertainty (1) #DerivativeJump (1) #Dogecoin (74) #DogecoinGains (1) #DogecoinVolume (1) #DutchCourt (2) #ECommerce (1) 1TP5테엘살바도르비트코인 (1) 1TP5테더리움 (73) 1TP5테더리움통증 (1) 1TP5테더리움가격 (1) 1TP5전문가 의견 (1) #FedRateCut (1) #FiatCurrency (1) #FinancialImpact (1) #FinancialPrivacy (1) #FirmShutdown (1) #FrozenAccounts (1) #IllicitFunds (1) #인플레이션데이터 (1) #투자 (1) #투자손실 (1) #일본기업 (1) #LegalAction (1) #LegalImpact (1) #법률 (1) #라이트닝 네트워크 (1) 1TP5시장분석 (3) 1TP5시장 모니터링 (1) 1TP5시장 예측 (1) 1TP5시장 예측 (1) #MarketProjection (1) 1TP5마켓지원 (1) 1TP5시장변동성 (1) #M결혼 (1) #MemeCoin (5) #MemeCoins (2) #M광부수익성 (1) #MoneyLaundering (2) #MtGox (4) 1TP5북한암호화 (1) 1TP5노보그라츠예측 (1) #P가격 마일스톤 (1) #P가격 예측 (2) #P가격 질문 (1) #PriceSurge (1) #P형량 (1) #QuantAnalysis (1) 1TP5규제압력 (1) #SEC안티크립토 (1) #ShibaInu (6) #SocialBuzz (1) 1TP5기술분석 (1) #Toncoin (3) #TornadoCash (3) #TornadoCashDev (1) 1TP5토네이도캐시개발자 (1) #UKCrypto (1) #업사이드 잠재력 (1) #USCongress (1) #와이오밍랜드 (1) #XRP가격 (1) #XRP업스윙 (1)

유용한 링크

유용하다고 생각되어 공유하고 싶은 링크.