claude opus found a bug in crypto's ~$9B privacy token that could print money out of thin air - and it's fucking scary

zcash had a hidden flaw in its code. it let you create fake zec from nothing - and it was completely invisible. nobody could even tell it happened
and it sat there for 4 years. every top cryptographer looked at zcash, and none of them caught it
then a white hat used claude opus 4.8 + a custom setup and found it in about a day - just days after the model came out. he even built a working version that minted fake coins on a test network
the scary part is because zcash is private, there's no way to 100% prove nobody already used it before the fix
now think about how many other coins have a bug like this just sitting there waiting
how it actually worked: zcash hides every transaction behind a math proof that basically says "i own this coin and i'm spending it" - without revealing anything else
one step of that proof multiplies secret numbers on an elliptic curve to confirm your key matches the coin. the bug was that step never locked in which number you had to start with
so an attacker could quietly swap in a fake number, and the proof would still "check out" - even for a coin that was never theirs
once that check was fooled, they could spend the same coin again and again, each time stamping it with a fresh "spent" marker so the network saw a brand-new coin every time
zec conjured from nothing, fully encrypted, completely invisible. nobody watching the chain could even tell it happened
the fix was an emergency network upgrade. no evidence it was ever exploited - but no way to fully prove it wasn't
