via Decrypt · By Decrypt Editorial
Morning Minute: Massive ZCash Exploit Found by Claude, Extent Unknown
ZEC/USDT
$7,749,533,987.49
$553.71 / $250.12
Change: $303.59 (121.38%)
+0.0031%
Longs pay

Morning Minute is a daily newsletter written by Tyler Warner. The analysis and opinions expressed are his own and do not necessarily reflect those of Decrypt. And check out our new daily news show covering all of the top stories in 5 minutes, downloadable on Apple Pod or Spotify.
GM!
Today’s top news:
- Bitcoin holds steady while other majors dip; BTC at $62.5k
- BTC ETFs see net inflows for first day since May 14
- ZEC exploit vector confirmation sends the token down 43%
- First Fannie Mae-backed Bitcoin mortgage completed
- Pump Fun launches Pump Fun Go as new bounty marketplace
🚩 ZCash Exploit Found by Whitehat Using Claude Opus 4.8
On May 29, a security researcher named Taylor Hornby discovered a critical vulnerability in Zcash’s Orchard privacy pool that would have allowed an attacker to mint an unlimited amount of counterfeit ZEC.
Hornby, who was hired by the ZCash team for this exact reason, found it using Anthropic’s Claude Opus 4.8. By June 1, the Zcash ecosystem had deployed an emergency fix, solving the issue—tho it was exploitable for the past 4 years.
What the vulnerability was: The Orchard pool, Zcash’s most advanced shielded transaction layer, active since May 2022, uses zero-knowledge proofs to validate transactions without revealing amounts or participants. The bug in plain terms: a specific check that was supposed to validate transaction inputs wasn’t actually enforcing the rules it appeared to enforce. An attacker who discovered it could feed false inputs into that check and have it pass anyway—generating ZEC from nothing, with the ZK proof system blessing the fraudulent transaction as valid.
Hornby, with Opus 4.8’s assistance, wrote a complete working exploit. He tested it in a local environment and it worked: unlimited, undetectable counterfeit ZEC, indistinguishable from legitimate coins. He immediately disclosed it to ZODL, Zcash’s coordinating development body, rather than running it on mainnet.
What makes the exploit impact unknown: Because Orchard is a privacy pool, there is no way to cryptographically determine whether this vulnerability was exploited between May 2022 and June 2026. The privacy properties that make Orchard valuable are the same properties that make exploitation undetectable.
Now the team that hired Hornby says that prior exploitation is unlikely. The bug evaded years of scrutiny from world-class cryptographers, the discovery required cutting-edge AI tools available only to white-hat researchers, and the remediation window was narrow. But they were explicit: users should not rely on their assessment alone.
What happens next: Shielded Labs is proposing a Network Upgrade that would deploy a new shielded pool and enforce “turnstile accounting” on all coins from the Orchard pool. This would essentially force every existing Orchard coin to pass through a verifiable checkpoint that would expose any counterfeited supply. This requires broad community governance support and a standard Zcash network upgrade process. A detailed proposal is expected next week. Shielded Labs is also formally initiating a project to mathematically verify the entire Orchard circuit from scratch, and is hiring a Head of Security and a Cryptographer.
Why this matters beyond Zcash: This is the clearest real-world demonstration yet of what Anthropic’s most capable AI model can do in the hands of an expert security researcher. Hornby used Opus 4.8 released publicly on May 28, and within 24 hours of its release, he found a four-year-old critical bug that had survived multiple rounds of expert human review.
And this was just Opus 4.8. Mythos is coming soon. And there will be better models coming after that. Every crypto protocol has to be on notice—try to hack/exploit your own protocol with hired Whitehat hackers. Or roll the dice and wait for the Blackhats to do it for you.
The clock is ticking, and the near-term fate of the broader crypto space is likely hanging in the balance.
🌎 Macro Crypto and Markets
- Crypto majors are mostly red; BTC -3% at $61.9k; ETH -7% at $1,655; SOL -6% at $65.70; HYPE -8% at $61.80
- WLD (+9%), DEXE (+8%) and JST (+7%) led top movers
- ZEC fell 43% to $306 after the exploit was published, wicking as low as $250
- Oil -1% at $93; Gold -0.2% at $4,490
- Stock futures are mixed with the DOW green but Nasdaq down 1%
- Crypto longs saw $830M in liquidations over the past day, includng $336M in BTC longs, $277M in ETH and $117M in ZEC longs
- Coinbase and Better Home & Finance funded the first Fannie Mae-backed Bitcoin mortgage in US history, completed by a married couple in Ann Arbor who used their Bitcoin as collateral to purchase their first home without triggering a taxable sale
- Rep. Bryan Steil (R-WI) announced plans to add prediction market restrictions to the House’s stock ban bill, barring members of Congress from betting on elections and public policy on Kalshi and Polymarket
- Google DeepMind CEO Demis Hassabis said humanity is standing in the “foothills of the singularity” and predicted AGI will arrive around 2030, possibly as early as 2029
- The DOJ’s “Disruption Week” operation froze more than $3.8 million in stolen crypto with help from Coinbase, SpaceX, Meta, Apple, Google, and Microsoft
- A fast-growing gray market for peptides has become one of cryptocurrency’s newest high-volume markets, processing more than $100 million annually primarily through Bitcoin and stablecoin payments
Corporate Treasuries & ETFs
- The Bitcoin ETFs saw $3M in net inflows on Thursday, the first green day since May 14; the ETH ETFs saw $19M in inflows
- The HYPE ETFs saw $12M in net inflows on Thursday
Meme Coin Tracker
- Meme leaders were red again; DOGE -7%, SHIB -7%, PEPE -8%, PENGU -7%, TRUMP -9%, BONK -9%, SPX -11%, FARTCOIN -15%
- SV151 (+800%), Hunter (+200%) and LOA (+60%) led movers on Solana
- Base movers included chainspin (+200x), SERV (+30%) and Pitch (+30%)
📈 Myriad Market of the Day
💰 Token, Airdrop & Protocol Tracker
- Pump Fun launched Pump.fun GO, a global bounty marketplace letting anyone create and pay for any task to be completed by humans worldwide
🚚 What is happening in NFTs?
- NFT leaders were mostly flat; Punks even at 30.8 ETH, BAYC even at 7.78 ETH, Pudgy +1% at 4.14 ETH; Hypurr’s -9% at 259 HYPE
- VeeFriends (+27%) and Fidenzas (+15%) led notable top movers
Add COINOTAG as a Preferred Source
Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.
Add on GoogleJune 5, 2026 at 11:13 AM UTC
June 5, 2026 at 10:43 AM UTC
June 5, 2026 at 10:41 AM UTC
