Buy Crypto
Markets
Spot
Futures
Earn
Promotion
More
reward-centerNewcomer Zone
Feed HomeArticle details
Zcash Suffers Over 30% Plunge Amid Trust Crisis After AI Discovers Additional Issuance Vulnerability
  • OPUS0%
  • ZEC0%

Compiled by: Felix, PANews

On June 5, Zcash founder Zooko Wilcox disclosed on the X platform that security researcher Taylor Hornby discovered an extremely severe forging vulnerability in the Zcash Orchard privacy pool on May 29. This vulnerability theoretically allows attackers to bypass system restrictions and mint an unlimited amount of forged ZEC tokens. Due to the cryptographic properties of the privacy pool, such an attack is extremely difficult to detect through conventional means. Furthermore, the vulnerability has existed since the Orchard pool was enabled in May 2022.

The Zcash Open Development Lab (ZODL) was alerted and responded urgently, patching the vulnerability on June 1. The Zcash network has since resumed normal operations, and official and on-chain data indicate that user funds, privacy data, and the 21 million coin total supply cap have not been materially affected.

Although Zooko emphasized that the possibility of fraudulent behavior occurring before the vulnerability was fixed (over four years) was low, the market did not seem to alleviate its concerns. Coingecko data shows that after the news was announced, the price of ZEC tokens plummeted, falling by over 30% in 24 hours.

Using AI to Write Programs to Detect Vulnerabilities

The vulnerability was discovered using the latest AI-assisted security auditing techniques and traditional security research methods.

On May 28, shortly after Anthropic released the Opus 4.8 model, Taylor used it to conduct a highly targeted audit of Orchard circuits. Taylor leveraged Opus 4.8 to write a complete exploit. When tested in a local regtest environment, the program was able to generate an unlimited and undetectable supply of forged ZEC. If he were to run the same tool on the Zcash Mainnet, it would generate an unlimited and undetectable supply of forged ZEC in his Mainnet Zcash wallet.

The vulnerability is related to an under-constrained component in the Orchard circuit. Due to the under-constrained nature of this component, an attacker can input arbitrary error values into the elliptic curve multiplication, and the multiplication check will still pass.

What is particularly tricky is that due to Orchard's privacy features and the nature of the vulnerability itself, it is impossible to determine cryptographically whether such an exploit occurred before the vulnerability was discovered and patched.

Has ZEC been maliciously subjected to Additional Issuance?

Are users' funds safe? Has there been any malicious additional issuance? This is perhaps the question the market cares about most. Zooko believes that several factors can "prove" there has been no malicious additional issuance.

Firstly, the vulnerability evaded scrutiny from numerous cryptographers for many years. Secondly, this discovery was not accidental but the result of the team deliberately searching for such vulnerabilities, which attackers typically "would not" be aware of. Furthermore, Taylor utilized the latest AI tools available only to white-hat security researchers, along with a sophisticated custom AI framework and prompting system, completing the task ahead of potential attackers. After the vulnerability was discovered, the ZODL and Zcash ecosystem quickly patched it, shortening the exploitable time window.

Therefore, before the vulnerability was fixed, few people had the ability and opportunity to discover and exploit it. This conclusion is also agreed upon by some people.

Helius CEO mert believes that although it is impossible to directly prove whether the vulnerability has been exploited in the short term, if a turnstile is triggered or migration to a new verifiable privacy pool occurs in the future, it can prove the existence of forgery issues. In addition, the Zcash team's increasing use of advanced tools and hiring of external security companies to audit themselves has also improved security to some extent. Zcash's ability to discover and immediately fix the vulnerability is the result of continuous security efforts and even good news.

But BitMEX co-founder Arthur Hayes holds the opposite view, and published an article stating that he has cleared his ZEC position. Hayes stated, although the possibility of malicious minting is extremely low, it cannot be formally proven impossible through cryptographic methods. The claim of protecting privacy from AI, governments, and big tech companies requires perfection, not a very low probability . He also stated that if subsequent assumptions are proven false, he does not rule out buying back in at a lower price.

Network upgrade to be launched, "proof" of non-existence of forgery

The current market sentiment regarding the Zcash Orchard pool vulnerability is divided. However, to prove the integrity of Zcash supply, Shielded Labs, a non-profit core development organization focused on the Zcash ecosystem, stated that it is cooperating with other Zcash developers to explore a network upgrade proposal. This proposal aims to allow anyone to verify the integrity of Zcash supply and "prove" that no forged Zcash exists in the Orchard pool. The plan involves deploying a new shielded pool and enforcing a "turnstile accounting" mechanism for all tokens in the Orchard pool. Details of the proposal will be released next week.

In addition, Shielded Labs claims to be launching a project aimed at formally verifying the Orchard circuit, attempting to write mathematical proofs to "prove" that no undiscovered vulnerabilities exist within it.

Whether Zcash can successfully navigate this vulnerability crisis remains to be seen. However, the handling of this crisis will provide an important reference for security practices in the field of crypto privacy.

Related Reading: Variant: Bitcoin, Ethereum, and ZCash are highly likely to become major value storage methods

Source: PANews

Disclaimer: The current content is sourced from third-party perspectives or directly translated by AI from third-party perspectives. CoinEx does not guarantee the authenticity, accuracy, and originality of the content, and it does not constitute any investment advice from CoinEx. The prices of cryptocurrencies are highly volatile, please be aware of the potential risks.

Prev'47 Ronin' Director Gets 30 Months for Spending Netflix's $11M on Dogecoin
NextHere's the bottom.
Hot
  • Coins
    Price
    24H Change