Zcash 零知识证明漏洞:AI 发现 4 年未察觉的无限铸币漏洞
The ZEC Exploit That Changes EVERYTHING
这是加密隐私赛道里程碑级的安全事件:AI 发现人类审计 4 年未察觉的零知识证明漏洞,且漏洞影响 Zcash 供应量完整性。建议关注 Zcash 后续审计进展及隐私币赛道风险重估。
What do you know? It turns out for 4 years, anyone with the right knowledge could have printed unlimited and untraceable Zcash out of thin air. And nobody knew. The developers who built it had no idea. The auditors missed it entirely. And even the elite cryptographers who designed the privacy system were completely in the dark. The floor sat in just two lines of code buried inside the exact mechanism that was supposed to make Zcash perfectly private.
And then in late May 2026, an AI model that had been public for roughly 24 hours read that code and did in days what human experts couldn't do in years. It found the hole and then [music] helped build a working exploit. And what's more, because Zcash is so private, no one can ever prove that the bug was never used. So today, we'll take a look at exactly what broke, expose how a machine caught what cryptographers missed, and lay out why this might be the most unsettling crypto vulnerability of the [music] decade.
My name is Guy, and you're watching the Coin Bureau. Righty, before we get to the part where AI does something both brilliant and also slightly terrifying at the same time, let's look at what the issue actually was. So, Zcash has something called the Orchard Shielded Pool, which put simply is the core of Zcash's privacy. It hides the amounts, hides the participants, hides everything using zero knowledge proofs. And for those unfamiliar, a zero knowledge proof lets you prove something is true without revealing any of the underlying details.
By the way, and the entire system rests on one property called soundness, the guarantee that you cannot create a valid proof for a false statement. It's the mathematical bedrock. But that bedrock had a crack in it. The bug lived in a Rust library called Halo 2 gadgets. specifically inside the elliptic curve multiplication gadget. The circuit failed to properly constrain its inputs. Now, in plain English, mathematically invalid inputs could pass a check that should have rejected them outright.
Cryptographers call this under constrained. The circuit was accepting more valid proofs than it ever should have. And that made it possible for an attacker to mint unlimited counterfeit ZEC inside the shielded pool. And that fake ZEC would be completely undetectable on chain. A fake coin would look identical to a real one because well, the privacy hides everything. So the attacker could potentially double spend the same shielded Ze over and over.
And this bug was live since the orchard pool launched in May 2022, roughly 4 years, 1 day, and a few hours through multiple human audits by worldclass cryptographers. Two lines of code missed for 4 years. Which brings us directly to the part that should keep every privacy coin holder up at night. The identity of the auditor who finally caught it. Now, the man in question is Taylor Hornby, a security researcher hired by Shielded Labs in April 2026 to proactively audit Zcash's cryptographic infrastructure.
But Hornby didn't find this bug all on his own. He used Anthropic's Claude Opus 4.8. Now, Claude Opus 4.8 was released on the 28th of May 2026. Hornby discovered the bug on the 29th of May, i.e. within roughly 24 hours of the model going public. But let's be clear on the specifics of this though, because instead of simply pasting the code and asking the AI what was wrong, he built a custom auditing framework reportedly called Zcash full stack auditor with sophisticated purpose-built prompts designed specifically to hunt for constraint failures.
And the AI even went a step further, helping Hornby write a complete working proofofconcept exploit. When he ran it in a local test environment, it generated unlimited undetectable counterfeit Zeg. In Shielded Labs's own words, the exploit worked and they think Hornby probably found it before any attacker did. Probably. Right. If you're looking to trade these latest market moves, whether that's crypto or traditional assets like gold and commodities, then BitGet is definitely worth a look.
They've just rolled out their Tradfy trading platform, which lets you trade assets like gold and other commodities directly using USDT, so you don't need to jump between platforms. You also get deep liquidity, low slippage, and [music] access to up to 500x leverage. Now, if you sign up using the QR code on screen or the link in the description, you can get up to $50,000 in bonuses. And on top of that, if you complete your first net deposit of $5,000 and place your first trade, you'll unlock a VIP3 trial. [music] Now, that includes up to 38% fee discounts, exclusive [music] VIP perks, and free token airdrops.
So, scan the QR code, check the link below, and see what BitGet [music] has to offer. Now, you might assume that after the fix went live, the developers could simply check the books and confirm no fake Zeg was ever created. However, that assumption runs straight into the central paradox of the entire privacycoin model. The developers moved incredibly fast, and credit where it's due, they didn't hesitate to take action once the bug was discovered.
On the 1st and 2nd of June, they developed and deployed an emergency soft fork that temporarily disabled all Orchard transactions, closing the window. On the 3rd of June, the NU6.2 to hard fork activated with a corrected circuit. A hard fork was required by the way because changing even two lines of a zero knowledge circuit changes its cryptographic verifying key. So every node has to upgrade. The transition caused widespread block explorer synchronization failures that lasted over 4 hours, briefly creating the appearance of a network halt.
Though the Zcash mainet itself continued producing blocks, Orchard transactions remained suspended for approximately 24 hours across the full remediation window and officially they found no evidence of exploitation. But crucially, no evidence of exploitation cannot be cryptographically proven. Because Orchard is fully private, hiding all amounts and participants from everyone, including the developers themselves, it's impossible to prove that no counterfeit Ze was ever minted.
And the Zcash Foundation admitted this directly. If someone had minted, say, a million fake Ze 3 years ago and simply held it inside the shielded pool, there would be zero evidence. and no way to prove those coins don't exist. And this is the privacy coin paradox in one line. The exact feature that hides your transactions also makes supply integrity unverifiable. Now, the developers do have a defense. They point to a turnstyle mechanism that tracks value moving between pools.
So to actually profit, an attacker would have to move counterfeit coins out to a transparent address or an exchange where the turnstyle would register a surplus. But that defense has a hole of its own. If an attacker just sits on an invisible reserve and never moves it, the turn style shows absolutely nothing. So, the probably fine verdict rests entirely on the assumption that no one is patient enough to wait this out, which brings us to what this uncertainty did to the market because the price reaction was brutal.
Before disclosure, ZEC was trading in the $620 to $640 range. After the full vulnerability went public around the 5th of June, it cratered to intraday lows between $255 and $310. A drop of roughly 50 to 57% in a day or two. Around $5 billion in market cap vaporized. Now, for context, this wasn't a futures-driven leverage cascade like we're used to seeing these days. Analysts noted that the selling was primarily spot-driven and that indicates genuine holder capitulation alongside the usual liquidated dgens.
Although the liquidations were brutal, too, with some trackers reporting 9 figure totals in a single 24-hour window, though exact figures remain unconfirmed. The institutional damage, meanwhile, was just as stark. Cippherpunk Technologies, the Winklvossbacked NASDAQ listed Ze Treasury Company, watched its stock plummet approximately 37%, closing at 59. They were ho
原文超出正文长度上限,此处截断——上游还有内容,完整版见上方「原文 ↗」。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力