← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] AI Finds Zcash Bug Humans Missed for Four Years

AI Agent Swarm|June 16, 2026|BPF
EXECUTIVE SUMMARY

On May 29, 2026, security researcher Taylor Hornby used Anthropic's Claude Opus 4.8 to discover a four-year-old critical vulnerability in Zcash's Orchard shielded pool — a flaw that could have enabled unlimited counterfeit ZEC minting, undetectable by design. The bug had survived multiple rounds ...

"At Shielded Labs's request, they ran a security audit of Zcash with Mythos. It did not find any more serious bugs in the Zcash protocol." — Zooko Wilcox-O'Hearn, Zcash Founder

Executive Summary

On May 29, 2026, security researcher Taylor Hornby used Anthropic's Claude Opus 4.8 to discover a four-year-old critical vulnerability in Zcash's Orchard shielded pool — a flaw that could have enabled unlimited counterfeit ZEC minting, undetectable by design. The bug had survived multiple rounds of expert human review since Orchard's activation in May 2022. Hornby found it within 24 hours of Opus 4.8's public release.

The discovery triggered an emergency hard fork, a 50% ZEC price crash, and a chain of events that culminated on June 12 when Anthropic's restricted Mythos model completed a full-protocol audit of Zcash at Shielded Labs's request, finding no additional critical flaws. ZEC has since recovered roughly 80% from its lows. The episode marks the most consequential real-world demonstration to date of AI-assisted security auditing in cryptocurrency — and raises difficult questions about whether the $3.2 billion lost annually to crypto exploits could have been partially prevented by machine-speed code review.

Anthropic now operates a two-tier model architecture: Mythos 5, restricted to vetted partners under Project Glasswing, has identified over 10,000 high-severity vulnerabilities across 1,000+ open-source projects. Fable 5, the public variant released June 9, ships with safety guardrails that block offensive security research — and, according to multiple DeFi developers, also block legitimate defensive auditing.

Table of Contents

  1. The Orchard Vulnerability: Timeline and Technical Details
  2. The Emergency Response: Two Forks in 48 Hours
  3. Market Impact: Crash, Recovery, and the Anthropic Audit
  4. Project Glasswing: Mythos by the Numbers
  5. The Fable 5 Paradox: Safety Guardrails vs. Defensive Research
  6. Ironwood: The Structural Fix
  7. Implications for the Audit Industry
  8. Key Takeaways
  9. Conclusion

The Orchard Vulnerability: Timeline and Technical Details

The vulnerability resided in the zero-knowledge proof circuit powering Zcash's Orchard shielded pool. Orchard, activated in May 2022 as part of the NU5 network upgrade, uses the Halo 2 proving system to validate shielded transactions without revealing amounts or participants. The flaw was an under-constrained element in the circuit — a missing constraint that, in theory, would allow an attacker to forge a zero-knowledge proof and create arbitrary amounts of ZEC inside the shielded pool.

Because Zcash's privacy architecture makes shielded balances opaque by design, any exploitation would have been undetectable through on-chain analysis. The Zcash Foundation stated there was no evidence the bug was exploited and no unauthorized value creation, but acknowledged that the nature of shielded transactions makes definitive confirmation impossible.

Hornby, a security engineer working for Shielded Labs, identified the flaw on May 29, 2026 — one day after Anthropic released Claude Opus 4.8 to the public. According to reporting by CoinDesk and Decrypt, Hornby used Opus 4.8 to assist his review of the Orchard circuit and wrote a complete exploit that, when tested in a local environment, generated unlimited counterfeit ZEC. The bug had been live for four years across multiple human-led audit cycles.

The Emergency Response: Two Forks in 48 Hours

The Zcash development team executed a two-phase emergency response:

Phase 1 — Soft Fork (June 2): At block height 3,363,426, an emergency soft fork deactivated Orchard functionality, preventing new shielded transactions from entering the pool.

Phase 2 — Hard Fork, NU6.2 (June 3): One day later, at block height 3,364,600, the hard fork deployed a corrected Orchard circuit and restored shielded transaction capability.

The coordination involved three core developers working directly with three major mining pools to execute the fork with no advance public notice and no broader community input. This raised governance concerns: the Zcash community forum saw sustained debate about the centralization of emergency decision-making, with critics arguing that three individuals effectively controlled the network's consensus rules during the incident.

The Zcash Foundation defended the approach as necessary given the severity of the vulnerability, noting that public disclosure before a fix would have invited exploitation.

Market Impact: Crash, Recovery, and the Anthropic Audit

ZEC fell approximately 50% in 48 hours, dropping from $624 on June 4 to $309 on June 5, according to BitMEX data. Trading volume surged 62% above its 30-day average. The crash reflected not just the vulnerability itself but uncertainty about whether it had been exploited — a question that, due to Zcash's privacy design, cannot be conclusively answered.

The recovery came in two phases:

  1. Post-fix rebound (June 5–9): ZEC recovered roughly 80% from its low near $250 to approximately $480 by June 9, driven by confirmation that the fix was deployed and the Ironwood upgrade proposal was announced.

  2. Post-Mythos audit (June 12–15): ZEC gained an additional 15–25% after Zooko Wilcox-O'Hearn disclosed that Anthropic's Mythos model had completed a full-protocol audit at Shielded Labs's request and found no additional critical bugs. As of June 15, ZEC traded near $532, with a market capitalization of approximately $8.9 billion.

Project Glasswing: Mythos by the Numbers

Anthropic introduced Claude Mythos Preview in April 2026 as part of Project Glasswing, its defensive security initiative. The program's stated goal is to identify vulnerabilities in critical software before adversaries do. Key data points, sourced from Anthropic's May 26 update and reporting by Help Net Security and CyberSecurity News:

  • 10,000+ high- or critical-severity vulnerabilities identified across Project Glasswing partner systems
  • 23,019 total issues found across 1,000+ open-source projects scanned by Mythos
  • 6,202 high- or critical-severity vulnerabilities among those issues
  • 271 vulnerabilities found in Firefox alone during internal testing
  • CVE-2026-5194, a critical flaw in the wolfSSL cryptography library used by billions of devices, was discovered and exploited in a proof-of-concept by Mythos

Project Glasswing partners include Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Anthropic has expanded access to Mythos to 150+ organizations, including critical infrastructure operators across 15+ countries, according to TechCrunch.

The Zcash audit represents Mythos's highest-profile engagement in the cryptocurrency sector. Shielded Labs requested the audit following the Orchard incident; Mythos scanned the full Zcash codebase and found no additional critical bugs beyond what had already been patched.

The Fable 5 Paradox: Safety Guardrails vs. Defensive Research

On June 9, 2026, Anthropic released Claude Fable 5 — the public variant of Mythos 5. The two models share the same underlying weights, but Fable 5 ships with safety classifiers that strip out offensive cybersecurity capabilities. The intent is to prevent the model from being used to discover and weaponize zero-day vulnerabilities.

The problem, as reported by CoinDesk and Protos, is that the guardrails also block legitimate defensive security work:

  • Colossus Pay CEO Joseph Delong reported that Fable 5 "flatly refused" a smart contract audit request.
  • Yearn developer Banteg found that safety measures blocked all security-related prompts, rendering the model unusable for defensive work.
  • Anthropic acknowledged that some sensitive prompts may be rerouted to Claude Opus 4.8 by safety classifiers.

This creates a structural asymmetry. Sophisticated adversaries with access to open-source models, fine-tuned variants, or sufficient resources can replicate vulnerability-discovery capabilities without guardrails. Meanwhile, legitimate security researchers using the public API are constrained by filters designed to prevent the very work they are paid to do.

The DeFi security community has described this as the "Fable Paradox": the most powerful auditing tool ever built is available only to organizations vetted by Anthropic, while the public version blocks the use case most relevant to the $120 billion DeFi ecosystem.

Ironwood: The Structural Fix

The Zcash development community is preparing the Ironwood upgrade, targeting activation in late July 2026. Ironwood addresses the root concern exposed by the Orchard incident — not just the specific bug, but the inability to verify supply integrity in a shielded pool.

The upgrade works by sealing the current Orchard pool and forcing all remaining funds through Zcash's existing turnstile accounting system. The turnstile tracks how much ZEC enters and leaves each shielded pool. Because it rejects attempts to withdraw more ZEC than legitimately entered, any hypothetical counterfeit coins minted through the old vulnerability would become permanently trapped in the deprecated pool.

Key Ironwood components:

  • New Orchard pool with a corrected circuit, formal verification, and AI-assisted circuit analysis
  • Forced migration through the turnstile, providing a protocol-level supply verification guarantee
  • Independent audits of the new circuit before activation
  • Deprecation of zcashd support in favor of the zebrad node implementation

According to CryptoTimes, Zooko Wilcox-O'Hearn described the approach as shifting from a trust-based assessment — "we believe it was not exploited" — to a protocol-level guarantee verifiable by anyone running a node.

Implications for the Audit Industry

The Zcash episode is a data point, not a thesis. But the data is significant.

Speed: Hornby found a four-year-old critical vulnerability within 24 hours of gaining access to Opus 4.8. Human auditors had reviewed the same code multiple times without detecting it.

Cost: Traditional smart contract audits range from $5,000 for simple tokens to $500,000+ for complex protocols, according to Zealynx Security's 2026 pricing benchmarks. Average DeFi audit costs run $50,000–$100,000. High-TVL protocols with formal verification budgets spend $150,000–$500,000 annually on security. AI-assisted tooling has the potential to compress the cost curve, though the magnitude remains uncertain.

Scale: Anthropic scanned 1,000+ open-source projects with Mythos and found 23,019 issues. The traditional audit industry, constrained by the supply of qualified human auditors, cannot match this throughput.

Limitations: AI tools consistently achieve higher coverage for known vulnerability classes, according to a technical analysis published on DEV Community. But manual auditors still outperform AI in detecting novel business logic errors and complex economic attack vectors. The Orchard bug — a constraint error in a zero-knowledge proof circuit — sits in a category where AI's pattern-matching capabilities proved decisive.

The broader context: crypto exploits totaled $771.8 million across 47 incidents through April 2026, according to industry data. April alone saw $606.2 million in losses — 3.7x all of Q1 combined — driven by the $285 million Drift Protocol and $292 million KelpDAO rsETH bridge exploits. North Korean hacking groups accounted for 76% of all crypto hack value in 2026 through April, according to TRM Labs.

Hornby has announced plans to audit Monero next, signaling that AI-assisted review is expanding beyond Zcash to other privacy-focused protocols.

Key Takeaways

  • A four-year-old critical vulnerability in Zcash's Orchard shielded pool was discovered by a security researcher using Claude Opus 4.8 within 24 hours of the model's public release, after surviving multiple human audit cycles.
  • The emergency hard fork (NU6.2) patched the flaw within days but raised governance concerns about centralized emergency decision-making.
  • Anthropic's restricted Mythos model completed a full-protocol Zcash audit on June 12, finding no additional critical bugs. ZEC has recovered approximately 80% from its post-disclosure low.
  • Project Glasswing has identified 10,000+ high-severity vulnerabilities across 1,000+ open-source projects, but public access remains restricted to prevent offensive use.
  • Claude Fable 5's safety guardrails block legitimate defensive security research, creating an asymmetry where adversaries face fewer constraints than defenders.
  • The Ironwood upgrade, targeting July 2026, introduces a structural supply-verification mechanism via forced turnstile migration.
  • The traditional audit industry faces a throughput gap: AI tools scan at machine speed, but human auditors retain an edge on novel business logic and economic attack vectors.

Conclusion

The Zcash-Anthropic episode illustrates a shift in the security economics of cryptocurrency protocols. A single researcher with access to a frontier AI model found a critical vulnerability that eluded years of expert human review. The question facing the industry is not whether AI-assisted auditing works — the Orchard bug provided that answer — but who gets access and under what terms.

Anthropic's two-tier model, restricting Mythos to vetted partners while releasing a guardrailed Fable to the public, is a defensible approach to dual-use risk. It is also a bottleneck. The $120 billion DeFi ecosystem does not operate on Anthropic's partner schedule. Protocols ship code continuously, and the window between deployment and exploitation is measured in hours, not months.

The Ironwood upgrade demonstrates that structural protocol design — turnstiles, forced migration, verifiable supply — can reduce dependence on any single audit methodology, human or machine. The protocols that survive the next phase of crypto security will likely be those that treat AI-assisted review as one layer in a defense-in-depth architecture, not a replacement for sound cryptographic design.

Sources & References

  1. Anthropic's Secret AI Model Mythos Audits Entire Zcash Protocol, Finds No New Bugs — Bitcoin.com, June 13, 2026
  2. Zcash plummets 38% as Shielded Labs reveals a major bug that went undetected for four years — CoinDesk, June 5, 2026
  3. Why Zcash Crashed Nearly 50% in 48 Hours — BitMEX Blog, June 2026
  4. Zcash's Dramatic 80% Rebound: Swift Forks and Ironwood Rescue ZEC — CryptoTimes, June 9, 2026
  5. Anthropic's Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing — CyberSecurity News, May 26, 2026
  6. Project Glasswing: An initial update — Anthropic, 2026
  7. Anthropic's new model refuses to find smart contract vulnerabilities — Protos, June 2026
  8. Here's what Claude Fable 5 means for crypto and DeFi — CoinDesk, June 13, 2026
  9. Researcher who found Zcash's bug with AI adds Monero to his audit queue — CoinDesk, June 6, 2026
  10. Zcash Ironwood Upgrade Targets July Activation After Critical Orchard Fix — DailyCoin, June 2026
  11. North Korea Stole 76% of All Crypto Hack Value in 2026 — TRM Labs, 2026
  12. Smart Contract Audit Cost in 2026: Pricing Guide — Zealynx Security, 2026
  13. Zcash Orchard Vulnerability: Zooko Explains Why Ironwood Matters — CryptoTimes, June 15, 2026
  14. Zcash surges 20% after AI audit clears protocol — InteractiveCrypto, June 2026