AI is accelerating the discovery of vulnerabilities, and the Zcash incident has raised security concerns.
Coinpaper
4h ago
Ai Focus
The discovery of a critical vulnerability in Zcash with the assistance of AI demonstrates that cutting-edge models are accelerating their application in software and cryptographic security research.
Helpful
No.Help

A critical vulnerability disclosed by Zcash this week has once again brought the relationship between AI and cybersecurity to the forefront. The developers stated that this vulnerability exists in their privacy pool, Orchard, and could theoretically allow attackers to infinitely generate counterfeit ZECs. Due to the privacy-preserving nature of this mechanism, it is currently impossible to confirm whether the vulnerability has been actually exploited solely through cryptographic means.

This incident has garnered significant attention not only because of the severity of the vulnerability itself, but also because independent security researcher Taylor Hornby used Claude Opus 4.8 during his research. As more powerful AI models are incorporated into code auditing, vulnerability discovery, and security testing, the speed at which vulnerabilities are discovered may continue to accelerate.

The Zcash vulnerability has existed for many years.

According to Shielded Labs, this issue existed since Orchard was launched in May 2022 and was only patched on June 1, 2026. If exploited, the vulnerability allowed attackers to forge an unlimited number of ZECs, and it is currently impossible to confirm whether such counterfeit assets have already appeared on the blockchain.

This uncertainty quickly translated into market sentiment. The report noted that ZEC prices fell significantly later in the week, reflecting investor concerns about the difficulty of auditing privacy blockchains and the exposure of historical risks.

AI is shifting from writing code to finding vulnerabilities.

Early AI models were primarily used as programming assistants to complete code, explain logic, and troubleshoot errors. As their capabilities improved, researchers began using them for code review, software auditing, and vulnerability research. Industry experts believe that AI is significantly more efficient than most human processes in reading complex code, locating abnormal paths, and combining potential attack surfaces.

Danny Jenkins, co-founder and CEO of ThreatLocker, stated that current AI systems are already accelerating vulnerability discovery, and more powerful new models may further amplify this trend. He believes that AI is also lowering the barrier to vulnerability research, enabling more people to analyze code, find weaknesses, and devise exploits.

Tech companies have used AI for security research

This trend is not limited to the crypto industry. This week, Anthropic expanded the use of Project Glasswing, opening up Claude Mythos to 150 companies and institutions for identifying and fixing software vulnerabilities before models are released more widely.

Previously, Mozilla disclosed that Anthropic's model helped Firefox fix hundreds of vulnerabilities. Microsoft also launched MDASH, a proxy-based vulnerability discovery system, in May, claiming it helped identify previously unknown Windows vulnerabilities. Researchers also used Mythos Preview to help generate publicly available exploit samples targeting Apple's M5 chip.

Encryption protocols are facing more direct pressure.

For crypto and DeFi projects, the risks are more direct. The related code is often open source, and real funds are held on-chain, making them a long-term target for attackers and security researchers. As AI improves code analysis efficiency, the difficulty of quickly scanning open-source protocols, locating vulnerabilities, and constructing attack paths is decreasing.

The report cited data showing that in the first five months of 2026, DeFi projects suffered losses exceeding $840 million, with over $600 million stolen in April alone, involving projects such as KelpDAO and Drift Protocol. Meanwhile, the so-called "vibe hacking" is also drawing attention, referring to attackers using AI-powered coding agents to automate tasks such as reconnaissance, credential theft, and malware development.

However, security professionals also point out that AI won't just help attackers. Blockaid CTO Raz Niv stated that the more realistic change isn't AI replacing hackers, but rather amplifying their capabilities, allowing attackers to focus their efforts on more complex aspects while delegating repetitive tasks to models. For defenders, AI-assisted monitoring and simulation are also becoming essential tools for security teams to keep pace with attack speeds.

Tip
$0
Like
0
Save
0
Views 555
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Alphabet pulls back to key levels; buyback pause raises dilution concerns.
Alphabet's stock price has fallen back to the key range of $350 to $360, with the suspension of share buybacks and the risk of dilution from equity incentives becoming the focus of market attention.
Coinpaper
·2026-06-03 02:36:37
542
ENA faces pressure ahead of unlocking; exchange inflows trigger selling pressure concerns.
The Ethena team's linked wallet transferred ENA to Binance, and the market is focused on the upcoming token unlock and its impact on price.
AMBCrypto
·2026-06-01 01:22:44
531
AI discovers old vulnerability in Zcash; security experts warn of risks to banking software.
After AI helped discover an old vulnerability in Zcash, industry insiders warned that similar flaws may exist in more crypto projects and banking systems, bringing formal verification back into focus.
CoinDesk
·2026-06-06 02:08:56
684
The circuit board beneath the AI chip has become a focus of US security.
The United States is concerned about its reliance on Chinese suppliers for PCBs needed for AI chips, and Congress is pushing for subsidies and tax incentives to support domestic manufacturing.
CNBC
·2026-06-04 04:56:20
492
The expansion of AI data centers has led to an increase in physical security jobs.
The construction of AI data centers is gaining momentum, driving up demand for physical security and related technology jobs in the United States.
Business Insider
·2026-06-02 20:26:57
210