Security researcher Taylor Hornby pointed Claude Opus 4.8 at Zcash's Orchard shielded pool code on May 29 and found a critical counterfeiting vulnerability within 24 hours of the model's release. The bug had survived years of review by world-class cryptographers. An emergency soft fork and the NU6.2 hard fork patched it by June 3.
The worst part: nobody knows if someone already exploited it. Because Orchard is a privacy pool, there is no cryptographic way to verify whether counterfeit ZEC was minted between May 2022 and today.
EXPLANATION (for interested people):
Zcash's Orchard pool uses zero-knowledge proofs to hide transaction details. A constraint in the circuit code was written too loosely, allowing an attacker to pass mathematically invalid inputs through an elliptic-curve check that should have rejected them. In practice this meant unlimited ZEC could be minted from nothing, completely indistinguishable from real coins. Hornby built a working exploit on testnet in a single day. The same privacy that makes Orchard valuable is also what makes past exploitation impossible to rule out.
🤖aluy.net the #1 VPS & RDP provider!
🔔 @Observer • 💬 Join community • 🌟 HighQuality OTC
