# Vulnerability Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Vulnerability", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

Beosin: 36 Major Security Incidents in May Resulting in Over $76 Million in Losses

In May 2026, the Web3 ecosystem suffered over $76.15 million in losses across 36 major security incidents, according to Beosin Alert. The primary causes were contract vulnerabilities and private key leaks. The top loss involved the Verus-Ethereum Bridge, which lost $11.58 million due to a cross-chain message validation flaw—a vulnerability type historically responsible for massive losses at Wormhole and Nomad. The Echo Protocol attack, resulting from a private key leak, saw the minting of 1,000 eBTC (nominal value ~$76.7M), with the attacker netting ~$5.13 million due to liquidity constraints. Cross-chain bridges were the hardest-hit category, accounting for $27.995 million in losses. DeFi protocols were the most frequently targeted, with 14 attacks. Ethereum saw the highest chain-specific losses at over $48.76 million, followed by BNB Chain, Monad, and TON, indicating a multi-chain attack landscape. A detailed analysis highlighted three key incidents: 1. **Verus-Ethereum Bridge**: A flaw where the bridge contract verified proof from the Verus chain but failed to validate the underlying asset value, allowing fake outputs. 2. **Trusted Volumes**: A signature parameter defect in its RFQ system allowed an attacker to manipulate authorization checks and drain assets from the Resolver contract. 3. **Private Key Leaks (e.g., StablR)**: Operational failures, including inadequate multi-signature wallet thresholds and lack of timelocks, led to losses exceeding $25 million across multiple projects. The report concludes that the Web3 security threat landscape is expanding systemically. Risks now span code, infrastructure, interoperability, and human processes, moving beyond code audits alone. Projects are urged to enhance operational security, review old contracts, and users should regularly revoke unnecessary approvals.

marsbit06/10 09:26

Beosin: 36 Major Security Incidents in May Resulting in Over $76 Million in Losses

marsbit06/10 09:26

When AI Begins to Audit the World: From Claude Discovering the ZEC Vulnerability, Watching the Encryption Industry Enter the 'Recursive Security Era'

**When AI Audits the World: From Claude's Discovery of a ZEC Vulnerability, Viewing the Crypto Industry Entering a "Recursive Security Era"** This article examines a pivotal shift in the blockchain security landscape, triggered by the convergence of two events: Anthropic's research on AI's "Recursive Self-Improvement" and Claude Opus 4.8's discovery of a critical vulnerability in Zcash's code. Traditionally, crypto security has relied on human experts and automated tools for periodic audits. However, the article argues AI is transitioning from a mere tool to an active participant in understanding and analyzing complex systems. Claude's ability to identify a subtle flaw in Zcash's zero-knowledge proof system demonstrates AI's potential to dramatically lower the cost and time required for risk discovery. This goes beyond finding a single bug; it signals a change in the very mechanism of how vulnerabilities are found. The core thesis introduces the concept of "Recursive Security," drawing a parallel to Anthropic's "Recursive Self-Improvement." Just as AI can accelerate its own development through feedback loops, security systems are evolving towards a continuous cycle of analysis, risk identification, remediation, and re-analysis. Security is becoming a persistent, evolving capability integrated into a system's lifecycle, rather than a one-time pre-launch audit. This shift is particularly urgent for the crypto industry, where system complexity from Layer-2 networks, modular architectures, and ZK-proofs is growing faster than human analysis capacity. AI excels at the pattern recognition and contextual understanding needed to navigate this complexity. Importantly, the article cautions that AI augments both defenders and potential attackers, accelerating the entire threat landscape. The future competitive advantage may not lie in having zero vulnerabilities, but in having the fastest risk discovery, validation, and response capabilities. The Claude-Zcash incident is thus an early signal of an era where AI-driven, recursive security systems become essential for managing risk in an increasingly complex digital world.

marsbit06/08 13:20

When AI Begins to Audit the World: From Claude Discovering the ZEC Vulnerability, Watching the Encryption Industry Enter the 'Recursive Security Era'

marsbit06/08 13:20

Claude Opus 4.8 Finds a $4.5 Billion Bug: The AI Era is Mass-Producing Hackers

A researcher discovered a critical "infinite mint" vulnerability in the Zcash cryptocurrency's Orchard protocol using Claude Opus 4.8, leading to a swift fix but also a 50% market drop, erasing billions in value. This incident highlights a new era where powerful, accessible AI models are dramatically lowering the barrier to finding software vulnerabilities. Previously, the security community feared specialized models like Claude Mythos Preview, capable of finding decades-old zero-day exploits. The Zcash case, however, involved a publicly available, general-purpose model. This shift makes advanced security auditing—and attack capabilities—accessible to far more people, not just experts. The mass democratization of vulnerability discovery brings a dual challenge: a flood of low-quality, AI-generated false reports that overwhelm maintainers, and the real, rapid uncovering of deep, dangerous bugs. Open-source projects, often understaffed and unfunded, are particularly vulnerable to this "attention DDoS." The article cites examples like curl shutting down its bug bounty program due to the unsustainable workload. Our perceived digital safety has often been luck, relying on the high cost and effort required to find deeply hidden flaws in complex systems, as seen with historical vulnerabilities like Heartbleed or Baron Samedit. AI changes this cost structure, effectively "mass-producing flashlights" to illuminate every corner of our codebase. While large companies operate extensive security chains involving external white-hat hackers and massive defensive operations, the global cybersecurity workforce faces a severe shortage, especially of experienced personnel capable of analyzing complex threats and coordinating fixes. The core dilemma emerges: AI makes *finding* bugs cheap and scalable, but *fixing* them remains a slow, expensive, and human-intensive process. The article concludes that AI won't destroy the internet but acts as a bright light, revealing that our digital existence is not inherently secure but is precariously maintained by ongoing human effort. The true cost in the AI era may not be discovery, but whether there will be enough people left willing and able to do the hard work of repair.

marsbit06/06 09:22

Claude Opus 4.8 Finds a $4.5 Billion Bug: The AI Era is Mass-Producing Hackers

marsbit06/06 09:22

Privacy Coin Crisis of Confidence! ZEC Plunges Over 56% in a Single Day

Zcash (ZEC), a leading privacy-focused cryptocurrency, experienced a severe crash on June 5th, plummeting over 56% in a single day and erasing nearly two months of gains. The flash crash was triggered by the disclosure of a critical zero-knowledge proof vulnerability within Zcash's Orchard privacy pool, which had existed since the pool's launch in May 2022. The flaw theoretically allowed an attacker to forge unlimited ZEC undetectably due to the pool's privacy features. The vulnerability was discovered on May 29th by independent security researcher Taylor Hornby during a proactive audit commissioned by Shielded Labs, utilizing AI-assisted analysis. The Zcash development team responded swiftly, implementing an emergency soft fork to disable Orchard transactions on June 2nd and executing a permanent hard fork fix (NU6.2) on June 3rd. Despite the technical fix, a major crisis of confidence emerged. The core issue is that Orchard's privacy design makes it cryptographically impossible to prove whether the vulnerability was exploited over the past four years, casting permanent doubt on the historical supply integrity of ZEC. While Shielded Labs argues exploitation was unlikely, the inability to provide definitive proof has severely damaged market trust. This sentiment was exacerbated when BitMEX co-founder Arthur Hayes, a prominent ZEC supporter, announced he was selling his entire position. He stated that privacy assets require "perfect security" rather than "probable safety." The combined effect of the disclosure and Hayes's exit ignited widespread panic selling, leading to massive liquidations and significant price decline. Analysts note the event highlights a fundamental tension within privacy coins: the conflict between verifiable supply and cryptographic privacy.

链捕手06/05 10:15

Privacy Coin Crisis of Confidence! ZEC Plunges Over 56% in a Single Day

链捕手06/05 10:15

Behind ZEC's Over 30% Plunge: An 'Unlimited Minting' Vulnerability with No Way to Prove if It Was Ever Exploited

A critical vulnerability was discovered in Zcash's Orchard privacy pool, allowing for the theoretical creation of undetectable counterfeit ZEC. Researcher Taylor Hornby found the flaw on May 29th, 2024, within the Orchard circuit's cryptographic constraints, which could let an attacker bypass asset conservation rules. Although a rapid emergency fix was deployed within days via a coordinated soft and hard fork, a core uncertainty remains: due to Orchard's privacy features, it is impossible to cryptographically prove whether this "unlimited mint" flaw was exploited in the nearly four years since the pool's 2022 launch. This uncertainty, rather than the patched flaw itself, triggered a market panic, causing ZEC's price to drop over 30%. While the Zcash Foundation stated no evidence of exploitation was found, independent entity Shielded Labs emphasized the impossibility of definitively proving no counterfeit ZEC was ever created. The incident highlights the unique trust challenge in privacy systems. To address this, developers are proposing a new network upgrade with enhanced auditing to allow verifiable proof of supply integrity. Notably, the researcher utilized the newly released AI model Claude Opus 4.8 as a tool during the security review, signaling the growing role of advanced AI in uncovering complex cryptographic vulnerabilities.

marsbit06/05 06:51

Behind ZEC's Over 30% Plunge: An 'Unlimited Minting' Vulnerability with No Way to Prove if It Was Ever Exploited

marsbit06/05 06:51

Single-Day Plunge of 30%, Arthur Hayes Suddenly Liquidates: Why Did ZEC Get Exploded by Security Issues?

On June 5th, Zcash founder Zooko Wilcox disclosed a critical soundness vulnerability in the project's latest Orchard privacy pool. This flaw, found in the elliptic curve multiplication constraints, could allow an attacker to create unlimited counterfeit ZEC within the shielded pool, with transactions appearing valid. The vulnerability was discovered in late May by security researcher Taylor Hornby, who utilized Anthropic's new Opus 4.8 AI model for a targeted audit. The Zcash ecosystem had already performed an emergency network upgrade to patch the issue. However, the detailed disclosure triggered severe market panic, causing ZEC's price to plummet over 30% in a single day. Notably, prominent investor Arthur Hayes announced he had sold his entire ZEC position following the news. The incident starkly challenges the "technological trust" narrative central to privacy coins. Despite years of top-tier cryptographic audits, the bug persisted until uncovered with advanced AI-assisted research. This highlights the growing gap between theoretical perfection and practical implementation in privacy technology. The event serves as a industry-wide warning: in an AI-driven security landscape, the assumption that "undiscovered equals safe" is obsolete. It underscores the urgent need for continuous, proactive security practices combining AI audits, formal verification, and rapid response mechanisms.

foresightnews_api06/05 04:34

Single-Day Plunge of 30%, Arthur Hayes Suddenly Liquidates: Why Did ZEC Get Exploded by Security Issues?

foresightnews_api06/05 04:34

Kelp DAO Vulnerability Triggers Exodus of Hundreds of Billions; Two Major DeFi Lending Pathologies Clash Head-On

Title: Kelp DAO Exploit Triggers $15 Billion Exodus, Exposing a Clash Between Two DeFi Lending Models. In April 2026, a hacker exploited a LayerZero bridge vulnerability in the Kelp DAO project, minting $292 million in fake rsETH tokens. These were deposited into Aave as collateral to borrow real Ethereum, draining the protocol's liquidity. Within three and a half days, Aave saw $15 billion in deposits flee, forcing a costly $160 million bailout. The root cause was identified as Aave's governance, which had previously voted to set rsETH's loan-to-value ratio to a risky 93%, leaving minimal safety margin. This incident starkly contrasts with the experience of Morpho, the second-largest DeFi lending protocol. Some fake rsETH also flowed into Morpho, but the exposure was limited to $1 million across isolated, pre-configured markets, preventing systemic contagion. The event highlights a fundamental divergence in DeFi lending architectures. Aave employs a shared liquidity pool model, where all deposits back all approved collateral assets, governed by DAO vote. This creates systemic risk, as seen when even users who never interacted with rsETH faced frozen funds. Furthermore, Aave's governance, influenced by leveraged borrowers, prioritized their interests during the crisis, even lowering borrowing rates for frozen markets at the expense of safer depositors. Its supplemental insurance mechanism, Umbrella, also failed as providers withdrew capital when needed. Morpho operates on an isolated market model. Anyone can create a separate lending market with fixed parameters (collateral, loan asset, oracle, rates). Independent risk managers (curators) allocate capital to these markets, bearing losses within their own vaults if they occur. This structure prevents risk from spreading and removes governance conflicts, as curators' decisions are not subject to community override. Beyond crisis management, the shared pool model carries a hidden cost: idle capital. In Aave's core markets, the spread between borrowing and deposit rates represents unusable funds, costing an estimated $52 million annually in lost value. Morpho's model targets a higher utilization rate (90% vs. Aave's 60-80%) because it eliminates rehypothecation risk, dynamically adjusting rates to balance supply and demand without governance delays. Consequently, Morpho often offers higher net yields to depositors. Institutional adoption underscores this difference. Major players like Coinbase (powering its lending for over 100M users), Apollo Global Management, Anchorage Digital, and SG-FORGE (Societe Generale) have chosen to build on Morpho. They require compliant, self-controlled risk parameters that Aave's community-governed model cannot provide. This trend is amplified by regulations like the proposed US GENIUS Act, which will push stablecoin issuers to seek neutral, controllable infrastructure like Morpho to manage trillions in reserve assets.

marsbit05/29 01:44

Kelp DAO Vulnerability Triggers Exodus of Hundreds of Billions; Two Major DeFi Lending Pathologies Clash Head-On

marsbit05/29 01:44

活动图片