Taylor Hornby Adds Monero to Audit Queue After Exposing Four-Year Zcash Flaw

Taylor Hornby Adds Monero to Audit Queue After Exposing Four-Year Zcash Flaw

N
News Editor 01
2026-07-23 06:35:14
Security engineer Taylor Hornby, who uncovered Zcash’s Orchard vulnerability, says Monero is next on his audit list as he expands security reviews across privacy coin projects.
ZcashMoneroprivacy coinssecurity auditzero-knowledge proofs

Taylor Hornby, the security engineer who uncovered the critical Orchard shielded pool bug in Zcash, said Monero (XMR) is now in his next round of audit targets. He also plans to widen his security reviews across more privacy coin projects.

The announcement follows Hornby’s recent Zcash audit, which drew attention for both its speed and method. The day after Anthropic released Opus 4.8 in late May, he put the model to work on Zcash alongside his custom framework, “zcash-full-stack-auditor”. In less than 24 hours, he identified a key flaw that had remained hidden for four years. The weakness was in the Orchard circuit’s variable-base scalar multiplication gadget, where insufficient constraints could let an attacker forge inputs, bypass zero-knowledge proof verification, and mint undetectable fake ZEC with no limit.

Zcash pushed emergency fixes within days

Hornby is the founder of Defuse Security and also serves on the board of the Zcash Foundation. In April, nonprofit Shielded Labs hired him as a part-time security adviser under a three-month contract focused on finding protocol bugs before attackers did. He reported the issue to ZODL core engineers on the night of May 29. Shielded Labs then launched an emergency response. On June 2, Zebra 4.5.3 introduced a soft fork that halted all Orchard transactions, and on June 3, the NU6.2 hard fork fixed the flaw and closed it permanently.

Hornby said earlier audit attempts using Opus 4.7 with general prompts had failed to surface the bug. In his account, the difference was not just the model upgrade. His custom framework supplied highly targeted prompting strategies tailored to the protocol’s internals.

ZEC sold off sharply after disclosure

After the vulnerability became public, ZEC dropped as much as 48.51% within 24 hours, hitting a low of $250. Liquidations topped $116 million and affected more than 19,000 traders. Arthur Hayes exited his entire ZEC position, saying that privacy guarantees require certainty rather than possibility.

Hornby said he had the ability to profit from the exploit but chose disclosure instead, adding that he “could not accept that kind of betrayal.” Zcash founder Zooko Wilcox said the chance of real-world exploitation was very low. Still, because of Orchard’s privacy design, cryptography cannot prove whether fake coins had been minted at any point during the previous four years.

Monero joins the next audit round

Hornby has now placed Monero in his audit queue and said he intends to expand his security review work to other privacy coin projects. He is also preparing to apply for Zcash community funding to support continued security research.

On the Monero side, Trail of Bits has already been engaged to audit the FCMP++ integration, or Full-Chain Membership Proofs. Hornby’s move opens a separate line of review using the same AI-assisted methodology that exposed the Zcash issue, this time aimed at Monero’s cryptographic foundations.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.