Crypto & Web3·Jun 6, 2026

Researcher who found Zcash's bug with AI adds Monero to his audit queue

Taylor Hornby, who uncovered the Orchard flaw that sent Zcash down 38%, says other privacy coins are on his list too.

CoinDesk2 min readVerified
Researcher who found Zcash's bug with AI adds Monero to his audit queue
Image · CoinDesk
The gist
3-point summary · 1 min

Taylor Hornby, who uncovered the Orchard flaw that sent Zcash down 38%, says other privacy coins are on his list too.

  • Taylor Hornby, who uncovered the Orchard flaw that sent Zcash down 38%, says other privacy coins are on his list too.
  • The bug, in the blockchain's Orchard privacy pool, had gone undetected since May 2022 and could have let an attacker mint unlimited, undetectable counterfeit ZEC.
  • Shielded Labs, a nonprofit developer on the network, disclosed it on Thursday and pushed through an emergency fix by June 1.
38%May 2022
BTC· Bitcoin
$01234567890123456789,012345678901234567890123456789.01234567890123456789 01234567890123456789.01234567890123456789 (0123456789.01234567890123456789%)
Last updated · 2:48:56 PM
Binance
Open$60,799.55
Range$59,130.91 – $62,000
Volume40.93K
24h$59,130.91 – $62,000

Taylor Hornby, who uncovered the Orchard flaw that sent Zcash down 38%, says other privacy coins are on his list too. Jun 6, 2026, 9:38 a.m. 1 min readMake preferred on Taylor Hornby, the security engineer who used Anthropic's Opus 4.8 AI model to find a critical bug in Zcash, says privacy coin Monero is among the tokens he intends to audit next.Asked on X whether he could look for flaws in Monero and other private cryptocurrencies, Hornby replied, "Absolutely! I'll add Monero to my queue of things to audit." Monero, which trades under the ticker XMR, is among the largest privacy-focused cryptocurrency and hides transaction details by default compared to Zcash, where users can either either transparent or shielded addressed.Hornby found the Zcash flaw on May 29. The bug, in the blockchain's Orchard privacy pool, had gone undetected since May 2022 and could have let an attacker mint unlimited, undetectable counterfeit ZEC. Shielded Labs, a nonprofit developer on the network, disclosed it on Thursday and pushed through an emergency fix by June 1. Zcash fell 38% over the following 24 hours amid fallout and concerns about a hacker possibly stealing money from the shielded pool - without leaving any detectable trace - over the past few years.Hornby, hired by Shielded Labs in April to find protocol bugs before attackers could, said he reported the flaw rather than exploit it because the Zcash developers were "like family" and he could "not live with that kind of betrayal."He plans to apply for a Zcash coinholder grant to fund further work.More For YouAfter an AI model helped uncover a four-year-old flaw in Zcash, security researchers warn that similar bugs may be hiding across crypto and traditional financial systems. What to know: An AI model uncovered a four-year-old bug in Zcash that could have enabled the issuance of unlimited tokens, triggering a steep selloff in the cryptocurrency.The incident has intensified fears that increasingly powerful AI systems will expose similar hidden vulnerabilities across both crypto networks and traditional banking software.Leading investors...Read full story

Integrity note  ·  Xela does not rewrite or paraphrase article content. The excerpt above is the source publication's own words, sanitized for display. For the full piece — including any quotes, charts, or images — read it at CoinDesk. Xela's rewritten version is off for this story, so there's no editorial angle attached — you're getting the source's reporting unfiltered. When the rewrite is on, we add a What this means block underneath with the operator/trader takeaway.

What people are saying

Discussion

Hot takes

0/280

Loading takes…

Comments

Discussion · 0

Sign in to comment, like, and save articles.

Sign in

Loading comments…

Newsletter

Track crypto & web3 every morning.

Daily digest tuned to this beat. The 5 stories most worth your time. Unsubscribe anytime.