Security engineer Taylor Hornby, who used Anthropic's Opus 4.8 to uncover a critical flaw in Zcash's Orchard privacy pool, said on X that Monero and other privacy-focused cryptocurrencies are next on his audit list. Asked directly whether he would extend his review to Monero, Hornby replied: "Absolutely! I'll add Monero to my queue of things to audit."
The Zcash flaw, hidden in the network's Orchard pool since May 2022, was discovered on May 29 and disclosed on Thursday by nonprofit developer Shielded Labs. It could have allowed an attacker to mint unlimited, undetectable counterfeit ZEC, prompting an emergency fix by June 1. ZEC fell 38% in the 24 hours after disclosure as the market weighed the prospect of past silent exploitation of the shielded pool.
Why it matters
Hornby was hired by Shielded Labs in April specifically to find protocol bugs before attackers did, and he reported the vulnerability rather than exploit it — citing the closeness of the Zcash developer community. That disclosure-only model is now being stress-tested: it neutralised the immediate threat but handed the market a 38% drawdown anyway, and it sets a template for what a Monero audit could look like. Monero (XMR) is one of the largest privacy coins and hides transaction details by default, making any analogous flaw both harder to spot and harder to recover from once disclosed. The wider signal flagged after the disclosure is that AI-assisted auditing may systematically expose dormant vulnerabilities across crypto and traditional finance at the same time.
Market impact
The Zcash precedent is the read: a hidden flaw, surfaced by AI, disclosed responsibly, and still punished by a 38% single-day move. Privacy-coin liquidity is shallower than BTC or ETH, so the same playbook on Monero would likely produce a larger percentage reaction. Watch for Hornby to formalise a Zcash coinholder grant — funding the next round of audits — and for Shielded Labs to publish a post-mortem that quantifies how long the Orchard bug was live before discovery.
Frequently asked questions
-
What did Taylor Hornby actually find in Zcash?
A critical flaw in Zcash's Orchard privacy pool, hidden since May 2022, that could have allowed an attacker to mint unlimited, undetectable counterfeit ZEC. He discovered it on May 29 using Anthropic's Opus 4.8 AI model.
-
Why did Zcash drop 38% after the disclosure?
Shielded Labs disclosed the flaw on Thursday and pushed an emergency fix by June 1, prompting the market to price in the possibility that the shielded pool had been silently exploited for years without leaving a detectable trace.
-
Is Monero at risk of the same kind of bug?
Monero is on Hornby's audit queue, but no flaw has been disclosed yet. The concern is structural: Monero hides transaction details by default, so an analogous vulnerability would be harder to spot and harder to recover from once disclosed.
-
Why did Hornby report the Zcash bug instead of exploiting it?
He was hired by Shielded Labs in April specifically to find protocol bugs before attackers could. He has said the Zcash developers were "like family" and that he "could not live with that kind of betrayal."
-
How will Hornby fund the next round of audits?
He has said he plans to apply for a Zcash coinholder grant to fund further work on Zcash and other privacy-coin protocols on his queue.
CoinDesk