A single vulnerability wiped $4.5 billion off Zcash's market cap. The trigger wasn't a sophisticated hack, but an audit: security researcher Taylor Hornby used Anthropic's Claude Opus 4.8 during a protocol review commissioned by Shielded Labs, uncovering a critical flaw in Zcash's Orchard privacy component.
Orchard Bug: Unlimited Token Minting
On May 29, Hornby found that attackers could exploit the bug to mint tokens out of thin air — unlimited inflation. Orchard is the core engine for Zcash's private transactions, relying on zero-knowledge proofs. The Zcash team pushed an emergency upgrade within days. On June 5, officials confirmed the vulnerability but could not determine if it had been actively exploited. The disclosure sent Zcash's price crashing 50%.
Notably, Claude Opus 4.8 had launched only a day earlier, on May 28. AI's role in security auditing had just been dramatically highlighted — and the industry shuddered.
From Mythos to Opus: Democratization of AI Security Power
Before Zcash, the real concern was Anthropic's Claude Mythos Preview. In April 2026, Anthropic released an evaluation showing Mythos Preview could identify zero-day vulnerabilities in mainstream operating systems and browsers — some lurking for over a decade, like a 27-year-old bug in OpenBSD. The evaluation stated that even engineers without a security background could have the model hunt for remote code execution bugs overnight and wake up to usable exploit code.
But the Zcash incident used Opus 4.8 — already released, already embedded in normal workflows — not the still-locked Mythos. This means a capability once reserved for elite experts is now a service anyone can call. The only difference lies in who uses it and for what purpose.
As AI lowers the cost of finding bugs, two things emerge: a flood of low-quality AI-generated reports that look plausible but are often false, and genuinely dangerous vulnerabilities that were previously too expensive to uncover. Both arrive simultaneously, overwhelming defenders.
Report Flood: Maintainers Under Attention DDoS
In February 2026, OpenSSF held discussions on "AI garbage reports." The curl project reported that by mid-2025, only about 5% of bounty submissions were real vulnerabilities; roughly 20% appeared AI-generated and low-quality. OpenSSF likened this to a DDoS attack on human attention. curl eventually shut down its bug bounty program, unable to cope.
Security traditionally followed a clean narrative: white-hat finds bug, discloses responsibly, vendor patches. But AI has lowered the bar for "finding," drawing in hoards chasing bounties or reputation — many just copy-paste prompts and let a model generate a report. Real or fake, maintainers must treat every report seriously. Many open-source maintainers work without pay, without a security team, yet their code underpins countless commercial systems.
Worse still, we truly live in a world where AI can find unfathomable numbers of bugs. Code is like a building constantly remodeled: old protocols and libraries at the base, patchwork fixes and "ship now" decisions above, and legacy code no one dares touch at the top. The sudo Baron Samedit vulnerability existed for nearly a decade before disclosure in 2021. Heartbleed lurked in OpenSSL for over two years, affecting more than 60% of active websites globally.
4.8 Million Talent Gap: Cheap to Find, Expensive to Fix
ISC2's 2024 cybersecurity workforce report estimated 5.5 million active professionals globally, with a gap of 4.8 million — up 19% YoY. 67% of respondents said their organization had a cybersecurity staff shortage; 58% considered it a significant risk. 31% of security teams had no entry-level employees; 15% had no junior staff with 1-3 years experience. A Chinese industry report found 56.5% of practitioners now focus more on analyzing complex threats thanks to AI, and 33% are shifting from execution to strategy.
AI makes discovery cheap, but it also makes attack cheap. Damage can be scripted infinitely; fixing costs the same as before. The truly scarce resource is no longer finding bugs — it's having enough people willing to fix them, one after another. The internet is not a self-sustaining natural order; it's a narrow corridor constantly defended by engineers pushing risk below our perception.

