
Security researcher Taylor Hornby has confirmed plans to add Monero to his audit queue after successfully using Anthropic's Claude Opus 4.8 to expose a critical counterfeiting flaw in Zcash. According to reports, Hornby confirmed the move when asked whether he could probe other privacy coins, following his discovery that erased roughly 38% from ZEC before developers shipped an emergency patch. The researcher was commissioned by nonprofit developer Shielded Labs in April and ran a custom auditing agent paired with Opus 4.8 on May 29, flagging the soundness flaw within a day of the model's release.
The discovered bug, an under-constrained elliptic curve check, had survived since Orchard launched in May 2022 and could have minted unlimited, undetectable ZEC counterfeits within the pool. As reported, engineers closed the hole on June 1, with Shielded Labs stating that prior exploitation looks unlikely but cannot be ruled out cryptographically. The find represents one of Opus 4.8's first high-profile security catches, demonstrating how AI tools can surface bugs that human reviewers missed for years. Unlike Zcash's transparent layer, where some transaction history is inspectable, Monero's mandatory privacy architecture means any inflation bug would be essentially invisible, making proactive audits especially critical.
Zcash's ZEC token crashed 38% in the 24 hours following the bug disclosure, with the price collapse reflecting real concerns about potential exploitation rather than purely rational panic. In contrast, Monero's XMR token has fallen by nearly 10% following Hornby's confirmation of Monero audit plans, trading for $298.76 as of this writing. Hornby plans to apply for a Zcash coinholder grant to fund his work on privacy-focused projects, stating that donations are appreciated but not necessary for his research efforts. The Zcash incident has accelerated conversations among protocol teams about integrating AI tools into security processes, with the barrier to entry dropping significantly as Anthropic's models become more accessible via API.
Hornby indicated that other privacy-focused projects also sit on his audit list, with Monero being the largest default-privacy cryptocurrency that hides every transaction by design. The Zcash experience demonstrates how AI-assisted protocol auditing can surface hidden flaws that traditional human reviewers miss, with Opus 4.8's pattern-matching capabilities across thousands of lines of code at speeds no human team can match. While formal verification efforts backed by the Winklevoss twins now aim to prevent similar flaws, Hornby's systematic approach using AI-assisted audits represents a significant shift in how privacy coin security is approached. The methodology combines human cryptographic expertise with AI assistance, creating a more effective approach than either component alone.