
One Researcher, One Model, One Four-Year-Old Bug
Zcash engineers shipped an emergency soft fork and activated the NU6.2 hard fork on June 3. One researcher, one custom framework, one model — and the same tool that saved the protocol could have gutted it. The outcome depended entirely on who ran the audit first.
The same engine, two very different drivers
Hornby's discovery is the optimistic case. The pessimistic one is sitting in Anthropic's restricted Mythos tier: a model class the company says can independently discover and exploit software vulnerabilities and run portions of agentic cyber operations. Access is granted only to vetted defenders. Zcash got the defender pass — Wilcox later announced that a Mythos audit of the protocol "did not find any more serious bugs." That reassurance holds only until the next model ships. A clean audit is a snapshot, not a permanent seal — a point AMBCrypto's recent headline about a reported $3.63 billion security crisis despite audited protocols makes uncomfortably plain.
The crime side is catching up. Chainalysis data cited by The420.in shows crypto scams generated at least $14 billion in on-chain inflows in 2025, and operations with on-chain links to AI vendors averaged roughly $3.2 million each — versus about $719,000 for those without. Correlation, not causation. But the gap is the kind of number an auditor does not file away. And while top financial institutions and crypto companies announced a new Bitcoin Security Consortium, the open question is whether that coordination reaches the trading desk before the threat model does.
Where your bot stack actually leaks
If you run algorithmic trading or automation, the model is no longer the only attack vector worth watching. Binance Research reports that roughly two-thirds of the approximately $621 million lost in DeFi exploits in April 2026 came from access-control failures — wallets, credentials, governance keys. Binance CSO Jimmy Su has framed it bluntly: as smart contract security improves, attackers move toward people, permissions, and process. Your backtest can be pristine and your API key can still hand the account to someone else by Monday.
Three things to verify this week: scope your exchange API keys to read-and-trade with withdrawal disabled; sandbox any agent executing on your behalf away from cold storage and treasury wallets; and review counterparty risk per integration, not per quarter. The Zcash bug sat in production for four years because nobody pointed a frontier model at it. Most operational blind spots behave the same way — invisible until someone, or something, finally looks.