AI discovers old vulnerability in Zcash; security experts warn of risks to banking software.
CoinDesk
4h ago
Ai Focus
After AI helped discover an old vulnerability in Zcash, industry insiders warned that similar flaws may exist in more crypto projects and banking systems, bringing formal verification back into focus.
Helpful
No.Help

After AI helped discover a four-year-old vulnerability in Zcash, concerns about the security of financial software quickly escalated. Several security researchers stated that as model capabilities continue to improve, similar hidden flaws could be exposed in more encrypted networks and traditional banking systems.

The vulnerability has been patched, but it exposes long-term risks.

The report states that the vulnerability was discovered by Shielded Labs, the Zcash ecosystem development organization, using Anthropic's recently released Opus 4.8 model. Zcash has stated that the issue has been fixed.

If the vulnerability had remained undiscovered for an extended period, attackers could theoretically have forged an unlimited number of tokens. Due to the severity of the issue, the price of Zcash plummeted after the incident was disclosed, prompting the market to re-examine the auditing methods for privacy coins and critical financial software.

Concerns are not limited to the crypto industry

Ben Goertzel, CEO of SingularityNET, told CoinDesk that this issue does not mean that other crypto assets have the same vulnerability, but other projects are likely to have different types of implementation flaws, and AI tools may continue to discover similar issues in the coming weeks and months.

He also stated that the software infrastructure of banks and other centralized institutions may contain serious flaws that could be identified by AI tools. In other words, this security stress test may not only be happening on-chain systems.

Formal verification has been brought back to the forefront.

Haseeb Qureshi, Managing Partner of Dragonfly, believes that AI's ability to discover vulnerabilities will drive upgrades in remediation methods. He sees "formal verification" as a key direction, believing that such methods can help reduce implementation errors from the development stage.

Ethereum co-founder Vitalik Buterin previously explained that formal verification is essentially writing program properties into mathematical proofs that can be automatically checked. As AI can more easily discover software weaknesses, this type of method may become an important tool in cybersecurity.

However, Goertzel also points out that developers haven't adopted this approach on a large scale because of the high amount of additional work involved, and the inherent difficulty in verifying some underlying libraries. Completely rewriting it to a safer implementation often results in performance penalties.

It is more difficult for the defending side to concentrate resources

CertiK co-founder and CEO Ronghui Gu stated that the current offense and defense are asymmetrical. For hackers, as long as the target is clear and the reward is high enough, they can concentrate a large amount of computing power and AI resources to continuously seek breakthroughs in a single project or smart contract.

However, security companies typically serve a large number of clients simultaneously, making it difficult to allocate the same amount of resources to a single objective in the long term; otherwise, costs would rise rapidly. According to him, defenders need to integrate automated scanning more deeply into their daily development processes and combine it with mathematical proof methods to improve the speed of vulnerability discovery and remediation.

Judging from the Zcash incident, the focus of industry discussions is no longer just "who discovers the vulnerability first," but rather whether developers and security teams can build a sustainable defense more quickly after AI improves the efficiency of vulnerability discovery.

Tip
$0
Like
0
Save
0
Views 676
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Zcash initiates emergency protocol upgrade due to Orchard vulnerability.
Zcash has initiated an emergency upgrade due to an Orchard vulnerability, temporarily suspending related transactions, while other network functions remain normal.
AMBCrypto
·2026-06-02 22:25:30
705
Zcash discloses Orchard vulnerability that could allow for the forgery of unlimited ZEC.
Zcash has disclosed a serious vulnerability in the Orchard shielding pool, which could theoretically allow for the creation of an unlimited number of ZECs. The team says there is currently no evidence that the vulnerability has been exploited.
AMBCrypto
·2026-06-06 00:29:22
906
Following the disclosure of the Zcash vulnerability, ZEC's price plummeted by as much as 35%.
After Zcash disclosed the Orchard privacy pool vulnerability, ZEC once plummeted by about 35%, with the market focusing on whether network trust can be restored after the fix.
CoinPedia
·2026-06-05 12:17:48
675
Zcash resumed operation after fixing the Orchard vulnerability, and ZEC rose by more than 10%.
Zcash completed the Orchard vulnerability fix and restored network functionality, and ZEC subsequently rose by more than 10%.
Coinpaper
·2026-06-04 02:37:06
121
Zcash vulnerability triggers a sharp drop, ZEC's market value evaporates by billions of dollars.
Zcash experienced a sell-off due to a vulnerability in its private trading pool, causing a sharp drop in the price of ZEC. The market is concerned about whether the vulnerability has been exploited.
Coinpaper
·2026-06-06 03:29:53
634