Crypto news report · source clearly identified
AI Audits Uncover Old Crypto Vulnerabilities and Fuel New Attack Vectors in 2026
Artificial‑intelligence tools helped researchers expose a four‑year‑old Zcash bug and highlighted a Coldcard firmware flaw that preceded over $100 million in Bitcoin thefts, while on‑chain malicious instructions surged 440 % as AI became part of the attack surface.

In 2026, artificial‑intelligence (AI) systems proved both a diagnostic aid and a new weapon in the cryptocurrency security landscape. Researchers using AI‑driven audit agents uncovered long‑standing code flaws, while attackers leveraged AI‑enabled trust exploits to move millions of tokens.
AI‑assisted discovery of a dormant Zcash bug
Taylor Hornby of Shielded Labs employed the Claude Opus 4.8 model in a custom audit tool to examine Zcash’s Orchard shielded‑pool circuit. The analysis revealed a vulnerability dating back to 2022 that could generate unlimited counterfeit ZEC without detection. No theft was reported, and the Zcash team patched the issue within days.
Coldcard firmware weakness linked to massive Bitcoin losses
Attackers began sweeping Bitcoin from wallets affected by a Coldcard firmware flaw traced to 2021. The weakness reduced the randomness of recovery seeds, exposing roughly 1,600–1,800 BTC (over $100 million) across thousands of addresses. The manufacturer, Coinkite, suggested that AI may have been used to inspect the public firmware, though attribution remains unsettled.
AI becoming part of the attack surface
On May 4, an attacker posted Morse‑code text that an AI model (Grok) decoded into a command accepted by the Bankr platform, triggering a transfer of about 3 billion DRB (approximately $150 k–$200 k). Two weeks later, similar trust‑layer exploits affected 14 user wallets, causing losses between $150 k and $440 k.
Rise in AI‑facilitated on‑chain malicious activity
Chainalysis reported a 440 % increase in malicious on‑chain writes carrying malware instructions, rising from roughly 2.06 to 11.1 daily entries. State‑linked actors from North Korea and Iran accounted for about two‑thirds of the newly observed activity in Q2 2026.
Other AI‑related incidents
- DeFi protocol attacks linked to AI‑assisted decompilation of unverified contracts resulted in $36.7 million in thefts, with Ekubo and Trusted Volumes responsible for about $7 million.
- Fake “Claude‑built” arbitrage bot tutorials led to 224 victims, 234 compromised contracts, and roughly $517 k in losses, using AI as bait rather than a weapon.
These events illustrate that AI is reshaping both the detection and exploitation of vulnerabilities in cryptocurrency ecosystems.
Source & attribution
News Source
- Publisher
- Bitcoin.com News
- Original date
- September 20, 2026, 5:30 AM
- Original headline
- AI Is Rereading Crypto’s Old Code, and Finding What Humans Missed