AI Code Review Is Finding Bugs Humans Missed For Years AI just found a four-year-old Zcash bug in hours. That’s forcing a reprice across privacy coins. Claude Opus 4.8 flagged a flaw in the Orchard circuit dating back to May 2022. Emergency patch shipped June 3. No exploit found, but ZEC still dropped 30% to 410. Volume hit 1.355B tokens on June 4 with no bounce. Arthur Hayes confirmed a full exit. The market isn’t pricing the patch. It’s pricing doubt. In zero-knowledge systems you can’t independently verify supply. A small chance of stealth minting kills the premium people pay for "perfect privacy." Why this spreads: 1. *Speed.* AI compresses years of expert review into an afternoon. That means more bugs will surface across other zk codebases with old code. 2. *Capital rotation.* Money is moving from privacy assets to chains and tokens with verifiable supply. Audits aren’t enough anymore. 3. *Timeline.* Zcash leadership proposed formal verification, but implementation is months away and needs governance approval. Volatility stays until then. Interpretation split: Protocol handled it: Some bought the dip. Market ignored it. Trust won’t recover: Flow is going to transparent alternatives. Systemic risk: AI makes finding zk bugs cheaper, so expect more disclosures. Bottom line: Capital will only flow to privacy assets that build supply verification into the protocol. If you’re long privacy coins without that, you’re late. The advantage is with builders doing auditable shielded pools and funds rotating to transparent assets.
$BTC Cold Wallet Bug Drains 594 $BTC in 25 Minutes Security researchers say ∼594 BTC was drained from cold wallets in three Bitcoin blocks between 01:31 and 01:56 UTC. The attack wasn’t about phishing. It was about bad entropy from day one. A bug in Coldcard firmware caused some Mk4 and Mk5 devices to fall back from the hardware RNG to a weaker software generator. That generator was seeded by predictable values. According to Block's technical analysis, entropy dropped from 128-bit to around 72-bit on affected devices. About 500 wallets were hit. Median loss was 0.41 BTC. Worst hit was 29.9 BTC. The attacker filtered by balance, so this was targeted. Cold storage still protects against online theft, but it does not protect against a bad seed. If the randomness used to create your keys is weak, the wallet is compromised before it ever touches the internet. The mental model breaks at key generation. Trust in the device, not just the air gap. Seed entropy explained: 128-bit entropy means 2 to the 128 possible combinations. That is considered unbreakable. 72-bit drops the search space massively. With enough compute and on-chain addresses, attackers can brute force and reverse-engineer seeds. That is what happened here. Forensics show $38M still sitting unmoved at one address. We can see the flows, the timing, and the balance filtering. We cannot reverse it. Transparency tells us how it happened, not how to get it back. Three takeaways: 1. Verify how your seed was generated. If you used an affected Coldcard firmware, rotate funds to new keys generated with proper entropy. 2. Entropy matters more than marketing. Hardware RNG with verifiable output is not optional. 3. Cold does not mean immutable. Security is keygen plus storage plus process Investigation is still ongoing. This is security education, not FUD. If you self-custody, check your device firmware, check your seed generation method, and move to new keys if there is any doubt.
Cold Wallet Bug Drains 594 $BTC in 25 Minutes Security researchers say ∼594 BTC was drained from cold wallets in three Bitcoin blocks between 01:31 and 01:56 UTC. The attack wasn’t about phishing. It was about bad entropy from day one. A bug in Coldcard firmware caused some Mk4 and Mk5 devices to fall back from the hardware RNG to a weaker software generator. That generator was seeded by predictable values. According to Block's technical analysis, entropy dropped from 128-bit to around 72-bit on affected devices. About 500 wallets were hit. Median loss was 0.41 BTC. Worst hit was 29.9 BTC. The attacker filtered by balance, so this was targeted. Cold storage still protects against online theft, but it does not protect against a bad seed. If the randomness used to create your keys is weak, the wallet is compromised before it ever touches the internet. The mental model breaks at key generation. Trust in the device, not just the air gap. Seed entropy explained: 128-bit entropy means 2 to the 128 possible combinations. That is considered unbreakable. 72-bit drops the search space massively. With enough compute and on-chain addresses, attackers can brute force and reverse-engineer seeds. That is what happened here. On-chain transparency: Forensics show $38M still sitting unmoved at one address. We can see the flows, the timing, and the balance filtering. We cannot reverse it. Transparency tells us how it happened, not how to get it back. Three takeaways: 1. Verify how your seed was generated. If you used an affected Coldcard firmware, rotate funds to new keys generated with proper entropy. 2. Entropy matters more than marketing. Hardware RNG with verifiable output is not optional. 3. Cold does not mean immutable. Security is keygen plus storage plus process. Investigation is still ongoing. This is security education, not FUD. If you self-custody, check your device firmware, check your seed generation method, and move to new keys if there is any doubt.