跳到主内容
@wquguru
精选75Coin Bureau(YouTube)加密货币

Zcash 经受 AI 破解考验后创历史新高

Zcash Just Proved AI Is NO MATCH For Private Money

原文
发到 X
推荐理由

加密从业者应关注 Zcash 应对 AI 漏洞的完整处置流程:快速分叉、旧池退役、新池形式化验证,展示了隐私币在极端压力下的韧性,对评估隐私赛道风险与应对机制有参考价值。

In May [music] 2026, a security researcher turned a frontier AI model loose on [music] Zcash. And in just under a day, it found a bug that 4 years of live operation and multiple cryptographic [music] audits had overlooked. Now, many assumed that was a death sentence [music] for Zec. The idea was that privacy coins were a pre-AI idea. Machines cannot break them, [music] and this is what the end of this trade actually looks like.

2026年5月[音乐],一名安全研究员将前沿AI模型释放到[音乐]Zcash上。不到一天时间,它就发现了一个经过4年实际运行和多次密码学[音乐]审计都未发现的漏洞。当时,许多人认为这对Zec来说是一纸死刑判决。他们的想法是,隐私币是AI之前的概念。机器无法破解它们,[音乐]而这正是这一行业终结的真实写照。

But 3 months later, Zcash is now trading at a new all-time high of $800 $888, [music] up 80 plus percent in a single month. And the bug that was supposed to kill Zcash ended up showing everybody why the protocol was built this way in [music] the first place. So, today, we're breaking down what the AI actually found, why the network survived something that should have been fatal, and why AI is now arguably the single biggest tailwind [music] this asset has.

但3个月后,Zcash现在交易价格创下历史新高,达到800美元888美元,[音乐]单月上涨超过80%。那个本应杀死Zcash的漏洞,最终却向所有人展示了该协议当初为何如此构建。所以,今天我们将剖析AI究竟发现了什么,为什么网络能挺过本应致命的事件,以及为什么AI现在可以说是这一资产最大的顺风。[音乐]

My name is DC, and this is The Coin Bureau. So, let's start with the bug that was supposed to spell the end of Zcash. This was not a sloppy smart contract, and it wasn't an exchange getting fished. The issue with Zcash was a matter of cryptography. Specifically, the bug was in the cryptographic code behind Zcash's Orchard shielded transactions, and it had been live on the main network since network upgrade five in May 2022.

我是DC,这里是Coin Bureau。那么,让我们从那个本应终结Zcash的漏洞说起。这不是一个草率的智能合约,也不是交易所被钓鱼。Zcash的问题在于密码学。具体来说,漏洞位于Zcash的Orchard屏蔽交易背后的密码学代码中,自2022年5月网络升级5以来,它一直在主网上运行。

That's 4 years in production. The researcher was Taylor Hornby, working on a contract with Shielded Labs, and the discovery was credited to an AI auditing harness built around Anthropic's Claude Opus 4.8. Roughly 6 hours of targeted analysis, and then a working local proof of concept. Now, what actually was it? In simple terms, it was possible to create a zero-knowledge proof that passed all of Zcash's checks, even though the transaction it was supposedly proving wasn't actually valid.

这已经运行了4年。研究员是Taylor Hornby,与Shielded Labs签订合同工作,这一发现归功于围绕Anthropic的Claude Opus 4.8构建的AI审计框架。大约6小时的定向分析,然后是一个可用的本地概念验证。那么,这到底是什么?简单来说,有可能创建一个通过Zcash所有检查的零知识证明,即使它声称证明的交易实际上并不有效。

It was a bit like a bouncer who inspects every single ID with perfect precision, checks the hologram, checks the font, checks the expiry date, but never actually checks whether the person on the card actually exists. And in a shielded pool where amounts and participants are hidden by design, that means conjuring notes that were never supposed to exist with no public trace at all. In a local test environment, it was confirmed capable of producing unlimited counterfeit Zec.

这有点像一位门卫,以完美精度检查每一张身份证,检查全息图、检查字体、检查有效期,但从未真正检查卡片上的人是否真实存在。而在一个金额和参与者都按设计隐藏的屏蔽池中,这意味着可以凭空捏造本不应存在的票据,且不留任何公开痕迹。在本地测试环境中,已确认能够生产无限量的伪造Zec。

Not a nice sentence to read if you're a holder. And the reason this was important well beyond crypto is that a single researcher with the right AI tooling did in about a day what a well-funded multi-audit human review process had not managed in four years. So, every bank and every code base out there started looking much more vulnerable to AI. Zcash just happened to be the first name on the list. So then, how the hell is this coin at new all-time highs rather than at zero?

如果你持有这种币,读到这句话可不好受。这件事之所以在加密领域之外也意义重大,是因为一位拥有合适AI工具的研究员在大约一天内就完成了资金充裕、经过多次人工审计的审查流程四年都没能完成的事情。因此,每家银行和每个代码库都开始看起来更容易受到AI的攻击。Zcash恰好是名单上的第一个名字。那么,这种币怎么反而创下历史新高而不是归零呢?

Well, there are three major reasons. The first is that Zcash was actually designed with this kind of failure in mind. Its developers assumed that one day even their own cryptography might break, so they built a safe guard called the turnstile. The turnstile basically keeps track of money moving between different parts of the Zcash system, such as from transparent transactions into shielded ones or from an older shielded pool into a newer one.

嗯,主要有三个原因。第一个是Zcash实际上在设计时就考虑到了这种失败的可能性。其开发者假设有一天连他们自己的密码学也可能被攻破,所以他们构建了一个名为“旋转门”的安全防护机制。旋转门基本上跟踪Zcash系统不同部分之间资金的流动,比如从透明交易转入屏蔽交易,或从旧屏蔽池转入新屏蔽池。

The rule is that more money can come out of a pool than has been verified going into it. Individual shielded transactions can remain private, but the total amount entering and leaving each pool is still publicly tracked. So, even if the privacy system itself were completely broken, an attacker secretly create extra Zcash beyond the 21 million cap and then withdraw it unnoticed. Any money leaving the pool still has to pass through this publicly counted checkpoint.

规则是,从池中流出的资金不能超过已验证流入的资金。单个屏蔽交易可以保持隐私,但每个池的进出总额仍然公开跟踪。因此,即使隐私系统本身被完全攻破,攻击者也无法秘密创造超出2100万上限的额外Zcash然后不被察觉地提取。任何离开池的资金仍然必须通过这个公开计数的检查点。

That is a system designed by people who assume something could eventually go wrong. And when you're designing money, that kind of paranoia is a feature. The second reason is the response, which was incredibly fast. Horbit disclosed privately the same evening he found the bug. Within roughly 72 hours an emergency soft fork shipped by a Zcash 4.5.3 disabling Orchard shielded transactions network wide to remove the attack surface before the vulnerability was public.

这是一个由假设事情最终可能出错的人设计的系统。当你设计货币时,这种偏执是一种特性。第二个原因是响应速度,快得令人难以置信。Horbit在发现漏洞的当晚就私下披露了。大约72小时内,Zcash 4.5.3紧急软分叉发布,全网禁用Orchard屏蔽交易,在漏洞公开前移除了攻击面。

On the 3rd of June an emergency hard fork with a corrected circuit restoring shielded functionality. That's only the second security driven protocol upgrade in Zcash's entire history. Engineers at the Zcash Open Development Lab, Daira Emma Hopwood, Chris Nuki Khum and Jack Krieg among them confirmed and patched within hours. Now compare that response to the industry norm and the difference is stark. And the third reason Zcash could recover from this stress test is well, a little strange.

6月3日,紧急硬分叉带着修正后的电路恢复了屏蔽功能。这是Zcash整个历史上第二次仅因安全驱动的协议升级。Zcash开放开发实验室的工程师们,其中包括Daira Emma Hopwood、Chris Nuki Khum和Jack Krieg,在数小时内确认并修补了问题。现在将这一响应与行业标准相比,差异显而易见。而Zcash能从这次压力测试中恢复的第三个原因,嗯,有点奇怪。

Nobody could prove the pool was clean. Because Orchard is quite literally private, there's no forensic method to demonstrate that the flaw was never exploited during those four years. Shielded Labs assessed prior exploitation is unlikely given the complexity involved and the pool's balance had grown steadily with no suspicious outflows, but they did acknowledge that you can't prove a negative here. That's quite the admission from a project while its price was collapsing and collapse it did.

没有人能证明这个池子是干净的。因为Orchard确实是私密的,没有法证方法能证明在这四年间该漏洞从未被利用。Shielded Labs评估认为,鉴于所涉复杂性以及池余额稳步增长且没有可疑流出,过去被利用的可能性不大,但他们确实承认,在这里你无法证明一个否定命题。对于一个价格正在暴跌的项目来说,这算是一个相当坦诚的承认,而它也确实暴跌了。

Zcash collapsed by 50% with over $5 million in market cap wiped out at the trough and several high profile holders liquidating publicly. Ouch. So, what did the developers do with an unprovable question hanging over $1.7 billion of shielded value? Well, they didn't patch and pray. On the 28th of July the Ironwood upgrade activated and rather than keep the repaired Orchard pool running, it retired Orchard permanently. The old pool was effectively locked into exit only mode behind the turnstile.

Zcash暴跌了50%,在最低点市值蒸发了超过500万美元,几位知名持有者公开清算。哎哟。那么,面对悬在17亿美元屏蔽价值之上的无法证明的问题,开发者们做了什么?他们没有打补丁然后祈祷。7月28日,Ironwood升级激活,与其继续运行修复后的Orchard池,不如永久退役Orchard。旧池实际上被锁定在仅限退出的模式,位于旋转门之后。

That means any fake Zcash that might have been created there during those four years is now trapped inside and can never all be withdrawn. It was replaced by a brand new shielded pool built with a clean code. According to one account, that new system was tested against more than 2,700 mathematical proofs using automated tools before it ever went live. So, in other words, the system was formally verified and users quickly moved over.

这意味着在那四年间可能在其中创建的任何假Zcash现在都被困在里面,永远无法全部提取。取而代之的是一个全新的屏蔽池,代码干净。据一个说法,这个新系统在上线前经过了自动化工具对2700多个数学证明的测试。换句话说,该系统经过了正式验证,用户迅速迁移了过去。

Around 176,000 Zec entered the new Iron Wood pool on day one and by mid-August it had already become the largest shielded pool on the network. So, Zcash never proved that the old bug was never exploited, but it did make sure that any exploit from the old system was no longer relevant.

大约176,000个ZEC在第一天就进入了新的Ironwood池,到8月中旬,它已经成为网络上最大的屏蔽池。所以,Zcash从未证明旧漏洞从未被利用,但它确实确保了旧系统的任何利用都不再相关。

What if you could trade real US stocks like Apple, Nvidia, or Tesla without leaving your crypto account? Well, that's the idea behind our tokens from Bitget. These are tokenized stocks backed one-to-one by real shares, but the key difference is they are actually usable. You can trade them, use them as margin, and even earn dividends instead of just letting them sit in your wallet. So, if you want to check them out for yourself, sign up for Bitget using the link in the description or by scanning this QR code.

如果你能在不离开加密货币账户的情况下交易像苹果、英伟达或特斯拉这样的真实美股,会怎么样?嗯,这就是我们来自Bitget的代币背后的想法。这些是代币化股票,由真实股票一对一支持,但关键区别在于它们实际上是可用的。你可以交易它们,将它们用作保证金,甚至赚取股息,而不是让它们闲置在钱包里。所以,如果你想亲自查看它们,请使用描述中的链接或扫描此二维码注册Bitget。

Which brings me to an interesting point, if I do say so myself, because plenty of protocols have survived a scare, but almost none of them survived an existential scare of this magnitude. I mean, let's be honest, most cryptos barely survive at all. Go back to the coins that were household names in 2017 and 2018 and look at where they trade as I make this video. EOS is 99% below its 2018 peak. NEO is down 99%. Dash, once a genuine top 10 asset, is down 97%.

这让我想到了一个有趣的观点,如果我可以这么说的话,因为许多协议都曾经历过恐慌,但几乎没有哪个能挺过如此规模的生存危机。我的意思是,说实话,大多数加密货币几乎都难以存活。回顾2017年和2018年家喻户晓的币种,看看在我制作这个视频时它们的交易价格。EOS比2018年的峰值下跌了99%。NEO下跌了99%。曾经真正排名前十的资产Dash,下跌了97%。

Litecoin is 87% below its December 2017 high. Ethereum Classic is down 83%. Cardano, 83%. Stellar, 79%. And XRP, the strongest survivor of the lot, is still 61% below where it traded in January 2018. Cycle after cycle and still nothing. So, why do old altcoins stay dead? Well, there four main reasons and none of them are about the tech. First, venture unlocks that simply never stop hitting the market. Second, perpetual emissions which create a class of eager sellers.

莱特币比2017年12月的高点下跌了87%。以太坊经典下跌了83%。卡尔达诺下跌了83%。恒星币下跌了79%。而XRP,作为其中最强的幸存者,仍比2018年1月的交易价格低61%。一个周期接一个周期,依然毫无起色。那么,为什么老牌山寨币一直沉寂呢?嗯,主要有四个原因,而且都与技术无关。第一,风险投资的解锁从未停止冲击市场。第二,永续发行创造了一类急于抛售的卖家。

Third, developers mindshare draining away toward whatever is newer. And fourth, the marginal buyer of this cycle is an institution with an ETF wrapper and a compliance depa

第三,开发者的关注度不断流向更新的项目。第四,这个周期的边际买家是拥有ETF包装和合规部门的机构。

原文超出正文长度上限,此处截断——上游还有内容,完整版见上方「原文 ↗」。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近