The Orchard soundness bug, the five-day responsible disclosure that closed it, and why the “AI broke crypto” headline gets the story exactly backwards.
The headline that travelled fastest this week was the wrong one. “AI BREAKS ZCASH,” screamed half of crypto Twitter, complete with rocket emojis pointing the wrong direction. The truth is almost the opposite — and the difference matters, because it tells you something about where security is heading for every privacy coin you hold.
Here is what actually happened, what a “soundness bug” really is, the part of the story that is genuinely worrying, and the part that should reassure you.
The discovery (29 May 2026). Taylor Hornby, an independent security researcher contracted by the nonprofit Shielded Labs in April specifically to hunt for protocol flaws, found a critical bug in Orchard — Zcash’s newest shielded pool, the part of the chain that hides sender, receiver, and amount.
The flaw. An under-constrained elliptic-curve multiplication inside the
halo2_gadgetslibrary left a gap in the zero-knowledge circuit. In a working local test environment, that gap could be used to mint an unlimited, undetectable amount of counterfeit ZEC inside the shielded pool.The response. Hornby disclosed privately to the Zcash Open Development Lab the same evening. Within hours, core engineers Daira-Emma Hopwood, Kris Nuttycombe and Jack Grigg confirmed it and started a coordinated fix. A soft fork (Zebra 4.5.3) disabled Orchard to remove the risk; an emergency NU6.2 hard fork (Zebra 5.0.0) then shipped a corrected circuit on 3 June.
The window. The bug had been live since Orchard launched in May 2022. That’s roughly four years — through multiple expert audits — undetected.
No exploit was ever observed on mainnet. The proof-of-concept lived only in a regtest sandbox. The whole arc, from discovery to fixed mainnet, took five days.
A zero-knowledge proof is supposed to do one thing perfectly: let you prove a statement is true without revealing why. “I own these coins and I’m not double-spending them” — verified, with the amounts and addresses kept secret.
Soundness is the property that the system will reject anything false. A soundness bug means the circuit could be tricked into accepting a statement that isn’t true. In a transparent chain, a forged coin shows up — supply doesn’t add up. In a shielded pool, where balances are encrypted by design, a forged coin is invisible. That is the single worst failure mode a privacy coin can have, and it’s why the market reacted the way it did.
Let’s not spin this. Two things are real and uncomfortable:
Four years is a long time. The flaw survived since NU5 activation. Audits are not magic, and “it passed review” clearly isn’t the same as “it’s correct.”
You can’t prove the negative. Because Orchard hides everything, there is no way to cryptographically prove that no counterfeit ZEC was ever minted in that window. The Zcash Foundation found no evidence of exploitation, and supply-tracking mechanisms show nothing anomalous — but “no evidence” is not the same as “mathematically impossible.” Shielded Labs has already proposed a follow-up upgrade to let the network publicly attest total supply integrity.
That uncertainty — not the bug itself, which is patched — is what drove the price. ZEC fell roughly 30–40% in a day, back toward the mid-$400s (it had touched ~$736 in its 52-week range; for context, the 2016 all-time high was over $3,000). Arthur Hayes publicly dumped his entire position, declaring his “Holy Trinity” thesis dead. A coin that markets itself as sound money took a body blow to exactly that claim.
This is the honest bear case, and it deserves to be stated without flinching.
Now the reframe. The viral version of this story — “AI broke Zcash” — describes an attacker. There was no attacker.
The AI was on the defender’s side. Hornby used Anthropic’s newly released Claude Opus 4.8, paired with a custom auditing-agent framework, to do a deeply targeted review of the Orchard circuit — and found, in days, a soundness flaw that four years of human cryptographers and formal review had walked past.
Read that sequence again:
A frontier model, used by a defender, surfaced a latent flaw before anyone exploited it.
Responsible disclosure went to core devs the same night.
The network coordinated a hard fork and shipped a fix in five days.
That is not a privacy coin failing. That is privacy infrastructure working roughly the way it’s supposed to: a four-year-old, near-invisible bug found and closed before it ever touched a real balance. The frightening counterfactual isn’t “AI found it” — it’s the world where the next researcher to find it wasn’t being paid to disclose it.
The same capability that found this will be pointed at every other zk system in the space. That’s a feature.
The headline saidWhat actually happened”AI broke Zcash”AI (in a defender’s hands) found a 4-year-old bug before anyone abused it”Counterfeit ZEC is loose”Exploit existed only in a local test environment; none observed on mainnet”The chain is down”Block explorers mis-rendered during node upgrades; the chain kept producing blocks”Privacy is broken”The soundness of one pool was at risk; it’s patched. Privacy (confidentiality) was never compromised”Sell everything”The patched-in-five-days response is arguably a bull signal for the dev process — the supply-attestation question is the real open item
Two practical takeaways, beyond the price chart:
Privacy coins are software, and software has bugs. What separates a serious project from a meme is the response: disclosure discipline, a development lab that can ship a hard fork in days, and a willingness to follow up with a supply-integrity proof rather than hand-wave. Zcash, for all the pain this week, scored well on that test.
Holding ≠ moving. None of this touched your ability to transact privately. If anything, weeks like this are a reminder of why we list only hand-checked, non-custodial, no-KYC-where-possible tools in the NULL_ROUTE Directory — and why our own ZERO TRACE swap exists: so that when you move XMR, ZEC or anything else, you’re routing through infrastructure that doesn’t log you, doesn’t hold your funds, and doesn’t ask for your passport. Volatility you can’t control. Custody and surveillance you can.
The Orchard bug was real, serious, and uncomfortably old. The market’s fear about provable supply integrity is legitimate and not yet fully resolved. But the dominant headline — that AI broke a privacy coin — is exactly backwards. A frontier model in a defender’s hands caught a flaw that human review missed for four years, and the network closed it in five days with zero observed exploitation.
That’s not the story of crypto’s fragility. It’s a preview of how the next decade of cryptographic security is going to work: AI-assisted audits finding the holes faster than attackers can, and the resilient projects being the ones that disclose, patch, and prove. Watch which coins respond like Zcash did this week — and which ones go quiet.
Der Orchard-Soundness-Bug, die fünftägige verantwortungsvolle Offenlegung, die ihn schloss — und warum die Schlagzeile “KI bricht Krypto” die Geschichte genau verkehrt herum erzählt.
Die Schlagzeile, die sich diese Woche am schnellsten verbreitete, war die falsche. “KI BRICHT ZCASH” brüllte die halbe Krypto-Bubble, Raketen-Emojis in die falsche Richtung inklusive. Die Wahrheit ist fast das Gegenteil — und der Unterschied zählt, weil er zeigt, wohin sich die Sicherheit für jede Privacy-Coin entwickelt, die du hältst.
Hier ist, was wirklich geschah, was ein “Soundness-Bug” tatsächlich ist, welcher Teil der Geschichte ernsthaft beunruhigt — und welcher dich beruhigen sollte.
Die Entdeckung (29. Mai 2026). Taylor Hornby, ein unabhängiger Sicherheitsforscher, den die gemeinnützige Shielded Labs im April gezielt zur Suche nach Protokollfehlern engagierte, fand einen kritischen Bug in Orchard — Zcashs neuestem Shielded Pool, dem Teil der Chain, der Sender, Empfänger und Betrag verbirgt.
Der Fehler. Eine unzureichend eingeschränkte Elliptische-Kurven-Multiplikation in der Bibliothek
halo2_gadgetshinterließ eine Lücke im Zero-Knowledge-Circuit. In einer lokalen Testumgebung konnte diese Lücke genutzt werden, um eine unbegrenzte, nicht nachweisbare Menge gefälschter ZEC im Shielded Pool zu erzeugen.Die Reaktion. Hornby legte den Fund noch am selben Abend vertraulich gegenüber dem Zcash Open Development Lab offen. Innerhalb von Stunden bestätigten die Core-Entwickler Daira-Emma Hopwood, Kris Nuttycombe und Jack Grigg den Bug und begannen eine koordinierte Behebung. Ein Soft Fork (Zebra 4.5.3) deaktivierte Orchard, um das Risiko zu entfernen; ein Notfall-Hard Fork NU6.2 (Zebra 5.0.0) lieferte am 3. Juni einen korrigierten Circuit.
Das Zeitfenster. Der Bug war seit dem Start von Orchard im Mai 2022 aktiv. Das sind rund vier Jahre — durch mehrere Experten-Audits hindurch — unentdeckt.
Auf dem Mainnet wurde nie ein Exploit beobachtet. Der Proof-of-Concept existierte nur in einer Regtest-Sandbox. Der gesamte Bogen, von der Entdeckung bis zum gefixten Mainnet, dauerte fünf Tage.
Ein Zero-Knowledge-Beweis soll genau eine Sache perfekt können: eine Aussage als wahr beweisen, ohne das Warum preiszugeben. “Ich besitze diese Coins und gebe sie nicht doppelt aus” — verifiziert, mit geheim gehaltenen Beträgen und Adressen.
Soundness ist die Eigenschaft, dass das System alles Falsche ablehnt. Ein Soundness-Bug bedeutet, der Circuit ließe sich austricksen, eine unwahre Aussage zu akzeptieren. In einer transparenten Chain fällt eine gefälschte Münze auf — die Menge stimmt nicht. In einem Shielded Pool, in dem Salden bewusst verschlüsselt sind, ist eine gefälschte Münze unsichtbar. Das ist der schlimmste denkbare Fehlerfall für eine Privacy-Coin — und der Grund, warum der Markt so reagierte.
Schönreden bringt nichts. Zwei Dinge sind real und unbequem:
Vier Jahre sind lang. Der Fehler überlebte seit der NU5-Aktivierung. Audits sind keine Magie, und “hat das Review bestanden” ist offensichtlich nicht dasselbe wie “ist korrekt”.
Man kann das Negative nicht beweisen. Weil Orchard alles verbirgt, gibt es keine Möglichkeit, kryptografisch zu beweisen, dass in diesem Zeitfenster nie gefälschte ZEC erzeugt wurden. Die Zcash Foundation fand keine Hinweise auf einen Exploit, und Supply-Tracking zeigt nichts Auffälliges — aber “keine Hinweise” ist nicht “mathematisch ausgeschlossen”. Shielded Labs hat bereits ein Folge-Upgrade vorgeschlagen, mit dem das Netzwerk die Integrität der Gesamtmenge öffentlich attestieren kann.
Diese Unsicherheit — nicht der Bug selbst, der gepatcht ist — trieb den Kurs. ZEC fiel an einem Tag rund 30–40 %, zurück in die Mitte der 400-Dollar-Spanne (im 52-Wochen-Bereich hatte er ~736 $ berührt; zum Vergleich: das Allzeithoch von 2016 lag über 3.000 $). Arthur Hayes löste seine gesamte Position öffentlich auf und erklärte seine “Holy Trinity”-These für tot. Eine Coin, die sich als Sound Money vermarktet, kassierte einen Treffer auf genau diesen Anspruch.
Das ist der ehrliche Bär-Fall, und er gehört ohne Zögern ausgesprochen.
Jetzt die Neueinordnung. Die virale Version — “KI bricht Zcash” — beschreibt einen Angreifer. Es gab keinen Angreifer.
Die KI stand auf der Seite des Verteidigers. Hornby nutzte Anthropics neu veröffentlichtes Claude Opus 4.8, kombiniert mit einem eigenen Auditing-Agent-Framework, für ein hochgezieltes Review des Orchard-Circuits — und fand in Tagen einen Soundness-Fehler, an dem vier Jahre menschlicher Kryptografie und formaler Reviews vorbeigegangen waren.
Lies die Abfolge noch einmal:
Ein Frontier-Modell, eingesetzt von einem Verteidiger, brachte einen latenten Fehler ans Licht, bevor ihn jemand ausnutzte.
Verantwortungsvolle Offenlegung an die Core-Devs noch in derselben Nacht.
Das Netzwerk koordinierte einen Hard Fork und lieferte den Fix in fünf Tagen.
Das ist keine versagende Privacy-Coin. Das ist Privacy-Infrastruktur, die ungefähr so funktioniert, wie sie soll: ein vier Jahre alter, beinahe unsichtbarer Bug — gefunden und geschlossen, bevor er je einen echten Saldo berührte. Das beängstigende Gegenszenario ist nicht “KI fand ihn” — es ist die Welt, in der der nächste Forscher, der ihn findet, nicht fürs Offenlegen bezahlt wird.
Dieselbe Fähigkeit, die das hier fand, wird auf jedes andere zk-System der Branche gerichtet werden. Das ist ein Feature.
Die Schlagzeile sagteWas tatsächlich geschah”KI bricht Zcash”KI (in der Hand eines Verteidigers) fand einen 4 Jahre alten Bug, bevor ihn jemand missbrauchte”Gefälschte ZEC im Umlauf”Der Exploit existierte nur in einer lokalen Testumgebung; auf dem Mainnet keiner beobachtet”Die Chain ist down”Block-Explorer stellten während der Node-Upgrades falsch dar; die Chain produzierte weiter Blöcke”Privacy ist kaputt”Die Soundness eines Pools war gefährdet; gepatcht. Die Vertraulichkeit war nie kompromittiert”Alles verkaufen”Die Reaktion in fünf Tagen ist eher ein Bull-Signal für den Entwicklungsprozess — die offene Frage ist der Supply-Nachweis
Zwei praktische Lehren, jenseits des Kurscharts:
Privacy-Coins sind Software, und Software hat Bugs. Was ein ernsthaftes Projekt von einem Meme trennt, ist die Reaktion: Disziplin bei der Offenlegung, ein Dev-Lab, das in Tagen einen Hard Fork ausliefern kann, und die Bereitschaft, mit einem Supply-Integritätsnachweis nachzulegen statt abzuwiegeln. Zcash hat bei diesem Test — bei allem Schmerz dieser Woche — gut abgeschnitten.
Halten ≠ Bewegen. Nichts davon berührte deine Fähigkeit, privat zu transagieren. Wochen wie diese erinnern eher daran, warum wir im NULL_ROUTE Directory ausschließlich handgeprüfte, non-custodial, möglichst KYC-freie Tools listen — und warum unser eigener ZERO TRACE-Swap existiert: damit du, wenn du XMR, ZEC oder sonst etwas bewegst, über Infrastruktur routest, die dich nicht protokolliert, deine Mittel nicht hält und keinen Pass verlangt. Volatilität kannst du nicht kontrollieren. Verwahrung und Überwachung schon.
Der Orchard-Bug war real, ernst und unbequem alt. Die Marktangst um die beweisbare Supply-Integrität ist legitim und noch nicht vollständig ausgeräumt. Aber die dominante Schlagzeile — KI habe eine Privacy-Coin gebrochen — ist genau verkehrt herum. Ein Frontier-Modell in der Hand eines Verteidigers fand einen Fehler, den menschliches Review vier Jahre lang übersah, und das Netzwerk schloss ihn in fünf Tagen, ohne einen einzigen beobachteten Exploit.
Das ist nicht die Geschichte von Kryptos Zerbrechlichkeit. Es ist ein Vorgeschmack darauf, wie das nächste Jahrzehnt kryptografischer Sicherheit funktionieren wird: KI-gestützte Audits finden die Lücken schneller, als Angreifer es können — und die widerstandsfähigen Projekte sind jene, die offenlegen, patchen und beweisen. Beobachte, welche Coins so reagieren wie Zcash diese Woche — und welche still werden.
Keine Posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.