英文原文的机器翻译。 English

Zcash 警告:为什么法学硕士将打破传统的隐私链

人工智能刚刚为无限的、无法追踪的假冒 ZEC 编写了一个可行的漏洞利用程序。花了五天时间。该错误已经存在四年了。

📅 发表: 📖 ~1,900 字

🕮 TL;DR — Zcash 警告

  • 2026 年 6 月:Zcash 披露了其 Orchard 屏蔽池中的一个严重的伪造漏洞。 允许欠约束的零知识电路 无限的、无法检测的伪造 ZEC。
  • 它在那里呆了大约四年 (自 2022 年 5 月起)并通过了多年的专家人工审核。
  • 人工智能几天之内就找到了它。 一名研究人员使用 Claude Opus 4.8 编写了一个完整的工作漏洞,在测试环境中铸造了伪造的 ZEC。
  • 48 小时内市值蒸发约 50 亿美元。 通过紧急硬分叉进行修补。而且因为泳池是私人的, 没有人能够证明它从未被滥用。
  • 这是建立在手卷、前量子密码学基础上的隐私链终结的开始。 SynX, post-quantum from genesis and with no zero-knowledge supply circuit, does not have this class of bug.

让我给你讲一个故事,然后让我告诉你为什么这是十年来“隐私”加密货币发生的最重要的事情。

Zcash 的屏蔽池中存在一个严重错误,该错误已存在多年,可能会让任何人打印无限的 ZEC。

让它沉入其中。

Zcash Orchard shielded pool counterfeiting vulnerability versus SynX post-quantum architecture: an under-constrained halo2_gadgets circuit allowed unlimited undetectable counterfeit ZEC for four years, while SynX uses Kyber-768 and SPHINCS+ with compile-time static_assert invariants and no hand-rolled soundness circuit
安全剧场与实际密码学。其中一个将印钞机隐藏在两行代码中长达四年。

Zcash 刚刚发生了什么

2026 年 6 月上旬,Zcash 背后的团队披露了 严重的伪造漏洞 埋在里面 果园赛道 — 管理 Zcash 受保护的“私密”交易的加密组件。简单来说:有一个 欠约束单元 在变量基标量乘法小工具中 halo2_gadgets 电路。它让数学上无效的输入通过椭圆曲线检查,而椭圆曲线检查本应拒绝它们。这个优雅的小疏忽的实际后果是能够 创造无限的、无法检测的伪造ZEC 在屏蔽池内,没有链上签名,网络也无法注意到。

自 Orchard 池于 2017 年激活以来,该缺陷一直存在 2022年5月。那是 大约四年 ——四年来,“加密领域最受尊敬的隐私硬币”的核心是隐形印钞机,而其支持者向其他人解释为什么他们的加密技术是黄金标准。

当消息披露后,市场立即进行了计算。 ZEC从近峰值回落 624 美元到 309 美元左右——48 小时内价值大约减半。 清算金额超过 1.16 亿美元。附近某处 50亿美元市值被抹去 在紧急情况发生之前,两阶段响应最终 NU6.2硬分叉 关上门。

这是让每个屏蔽池持有者在晚上都保持清醒的部分。 Zcash 向所有人保证,其供应跟踪十字转门显示总供应完好无损,没有已确认的剥削行为。也许是这样。但 他们无法证明这一点, 你也不能,因为屏蔽池的全部卖点就是 你看不到它的内部。 四年来,一个无法检测到的无限铸币漏洞,在一条经过明确设计的链上,使伪造行为无法检测到。 “相信我们,十字转门已被抓住”不是密码学。这是一份新闻稿。

这不是黑客攻击。这是一次家庭作业检查。

现在详细介绍一下将其从“不幸”转变为“文明警告射击”的细节。

这个漏洞并不是被锁在房间里十年的传奇密码学家联盟发现的。它被发现于 2026 年 5 月 29 日 一位安全研究员 - Taylor Hornby,为 Shielded Labs 进行审计 - 使用 Anthropic 的克劳德 Opus 4.8 和一个定制的人工智能工具。 Shielded Labs 自己的话说:“该漏洞是真实的且可利用的。Taylor 在 Opus 4.8 的帮助下编写了一个完整的漏洞利用程序,当他在本地 regtest 环境中对其进行测试时,生成了无限的、无法检测的伪造 ZEC。”

慢慢地再读一遍。 人工智能为旗舰隐私币编写了一个可行的无限铸币漏洞利用程序,而且只花了几天时间,而不是几十年。 四年的专家人工审查却错过了这一点。一个语言模型,指向电路,几乎不经意地将它浮现出来。 (具有讽刺意味的是,现在读取地球上每个隐私链每一行的模型的确切类别与刚刚读取 Zcash 的模型是同一类。)

这是拐点。对于加密货币的整个历史来说,隐含的安全假设是“我们的代码太微妙,我们的审计预算太大,任何人都找不到针。”这一假设在 2026 年 5 月的注册测试环境中消失了。彻底读取和对抗性探测复杂的加密代码库的成本刚刚降至零。寻针器现已实现自动化、不知疲倦、价格低廉,并且每个季度都在改进。

霍恩比是一名白帽子。他提交了一份披露报告。 下一篇就不会了

手卷隐私电路是一颗定时炸弹

以下是没有人推销“隐私币”时愿意大声说出的结构性事实: 复杂的隐私建立在复杂的电路之上,而复杂的电路大多是攻击面。

像 Orchard 这样的零知识屏蔽池并不是一个优雅的等式。它是由数千个算术约束手工缝合在一起的,整个货币供应的稳健性取决于 每一个 是正确的。错过一个——让一个变量“不受约束”,就像 Zcash 所做的那样——证明系统会很高兴地证明谎言是真理。不存在优雅的降级。一个不存在的约束是“私人货币”和“无人能察觉的无限假币”之间的区别。

这并不是什么离奇的事故。这是一种架构的可预测故障模式,要求易犯错误的人类手写数千个约束,然后希望没有足够耐心的读者审核所有这些约束。多年来,没有足够耐心的读者。现在有一个,每月花费二十美元。

这就是为什么 Zcash 事件不是 Zcash 故事。它是一个 遗留隐私链故事。 每条隐私依赖于大型、手卷、前量子电路的链——基本上就是所有链——都坐在同一类定时炸弹上。唯一的问题是谁首先阅读他们的代码:提交披露的研究人员,或者悄悄为自己铸了一大笔钱的人,你被告知这些钱是不可伪造的。

去匿名鞋还没有落下

而假货就是 种类 鞋。它只需要你花钱。

这篇文章的论点就在它的标题中: 法学硕士将打破传统的隐私链 ——复数,而且不仅仅是通过铸造假币。详尽读取 Orchard 健全性电路的相同机器智能可以用于隐私承诺的另一半: 匿名。 交易图关联、时序分析、元数据泄漏,以及有据可查的现实,即大多数可选隐私链的用户实际上从未屏蔽他们的交易,并且每次在透明和屏蔽之间移动时都会创建去匿名链接——所有这些都是大规模的模式匹配。大规模模式匹配正是这些模型最擅长的。

目前还没有人公开对拥有法学硕士的屏蔽池进行去匿名化。这就是要点 警告。 2026 年 6 月证明了供应完整性方面的进攻能力是真实的。隐私方面是相同的代码,相同的密码学时代,由相同的工具读取。鞋子在空中。假装不然,你最终会在事后向你的持袋人解释 50 亿美元的提款。

SynX:来自 Genesis 的堡垒级加密

那么让我们来谈谈不存在这个问题的链条——老实说 为什么, 因为原因不是运气。

SynX 不会将其货币供应的完整性押在手工滚动的零知识健全电路上。该单一架构决策删除了 整个类别的“欠约束电路等于无限薄荷”错误 这简直毁掉了 Zcash。你不能对你没有建立供应安全的电路施加过低的约束。 SynX 中没有 Orchard 可以让变量悬空。

SynX 的构建基础是两个 NIST 标准化后量子原语,部署自 创世区块1:

  • SPHINCS+ (NIST FIPS 205) — hash-based signatures whose security rests on preimage resistance and related hash-function properties (FIPS 205). No bespoke arithmetic circuit. No exotic trusted setup. Decades of cryptanalytic battle-testing.
  • Kyber-768 (NIST FIPS 203) — 每个私人发送的基于点阵的密钥封装,通过旋转燃烧器地址路由,针对经典和量子对手进行加密。

而账本本身是故意的 双层:默认透明,按需阴影。 普通发送在浏览器上是公开的,例如 Bitcoin,SynX 是这么说的,而不是推销它在第一层不提供的隐私。一个 阴影 send is Kyber-768 encrypted through rotating burner addresses — private balances and transactions return Private。没有可伪造的屏蔽池,因为您和电源之间没有健全的电路。

公开模型是另一半,也是Zcash在结构上无法复制的部分。 Zcash 查看键是 永久且可转让 — 一项合规请求可以为某人带来终生可见性,并且在提出要求的交易所遭到破坏后很长时间内它仍然有效。 SynX 发出 临时视图键:一笔交易, 三十分钟, 仅金额, then gone — not revoked, not archived, no record left to subpoena. Reading it requires both the transaction hash 和 the key, and it never exposes the graph or balances or history. Expiring capabilities, not permanent identity grants.

在一起就是 超过 19,000 个关键材料——大约是装甲的 75 倍 传统链仍在使用的 256 位前量子密钥。但原始密钥大小甚至不是纪律点。 这是: SynX 保护其加密边界 编译时 static_assert 不变量。 畸形的状态、不可能的参数集、Zcash 留给运行时希望和人工审查的“这永远不应该发生”的条件——在 SynX 中,一个违反了这些不变量的构建 不编译。 It never reaches a node. It never reaches consensus. SynX’s compile-time static_assert checks catch wrong constants, such as a changed supply cap; runtime input checks still depend on validation code and testing.

这就是编写密码学和执行密码学之间的区别。

与此同时,我们在这里随意落下 Kyber-768 + SPHINCS+ 后量子钱包就像什么都不是一样。之间的差距 《安全剧场》 和 实际密码学 越来越尴尬了。

我们甚至不再玩同一个游戏了。这不是“我们错过了一个边缘情况”的情况。这是一个 基础密码工程学科的根本失败 ——编译时不变量会在午餐前捕获的那种。

🤡世界

Zcash 与 SynX:比较表

同样的使命——财务隐私。两种完全不同的工程严肃性级别:

财产 🤡 Zcash (ZEC) 🛡 SynX (SynX)
供应诚信 手卷zk电路(果园) 没有健全的电路可以打破
2026 年 6 月 假冒漏洞 ∞ 无法检测到的薄荷,约 4 年寿命 Bug 类在结构上不存在
签名 前量子椭圆曲线 SPHINCS+ (NIST FIPS 205)
按键封装 无/前量子 Kyber-768 (NIST FIPS 203)
量子电阻 无 — 被 Shor 的算法破坏 原生,来自创世区块 1
编译时不变量 运行时希望+人工审核 static_assert — 如果违反则不会编译
它曾经被利用过吗? 无法证明——这是私人的 N/A — no zero-knowledge supply circuit
隐私方法 可选的屏蔽池(大多数人不使用它) 双层 — 透明默认,Kyber-768 阴影发送 + 旋转燃烧器
披露模型 永久、可转移查看密钥 短暂 — 30 分钟,一笔交易,仅限金额
抵御 LLM 驱动的攻击 不——已经证明了 面积较小,有正式守卫

判决

这一切都不是 Zcash 工程师的胜利,他们至少有诚实的披露和分叉。这是对一个案子的判决 整个加密货币时代 ——这个时代将“隐私”和“安全”作为品牌、有影响力的认可、Discord氛围和路线图出售,而其背后的实际密码学是一个手工制作的电路,缺少印制无限金钱的约束。

人们购买了这个品牌。他们追随炒作、图表和人物。 待宰的羔羊——或被拉扯的羔羊,以先到者为准。 2026 年 6 月只是这起屠杀首次出现在链上,价格标签为 50 亿美元,凶器上有人工智能的指纹。

教训不是“Zcash 不好”。教训是,摆脱马虎密码学的时代已经过去了。 超过, 因为审计员现在是永不睡觉、永远不会错过第二行的机器。在那个世界里,唯一能屹立不倒的锁链就是那些做出了选择的人 要塞级加密胜过要塞级营销 ——它建立在标准化的后量子原语的基础上,使攻击面保持较小,并使不可能的状态实际上无法编译。

That is SynX. Kyber-768 and SPHINCS+ from genesis. Compile-time invariants instead of crossed fingers. A 77.7M hard cap, zero pre-mine, zero VC, zero admin keys. No zero-knowledge circuit to break, and no elliptic-curve key for a quantum computer to attack.

源在第一个减半时打开。开发者钱包可以选择公开查看。不要相信。 核实.

他们建造了安全剧院。
我们建造了堡垒。

运行 量子漏洞检查器 看看您当前持有的股票在下一次下跌之前得分如何。

📖 相关阅读

Frequently asked questions

What was the Zcash counterfeiting vulnerability in June 2026?
In June 2026, Zcash disclosed a critical soundness flaw in its Orchard shielded pool — an under-constrained element in the variable-base scalar-multiplication gadget of the halo2_gadgets circuit. The bug let mathematically invalid inputs pass an elliptic-curve check that should have rejected them, which made it possible to create unlimited, undetectable counterfeit ZEC inside the privacy pool. It had been live since Orchard activated in May 2022 — roughly four years — and survived years of expert human audits. ZEC lost about half its value in 48 hours and roughly $5 billion in market capitalization was erased before an emergency NU6.2 hard fork patched it.
Did an LLM really find and exploit the Zcash bug?
Yes. Security researcher Taylor Hornby, auditing the protocol for Shielded Labs, discovered the Orchard flaw on May 29, 2026 using Anthropic's Claude Opus 4.8 together with a custom AI tool. Shielded Labs confirmed that "the vulnerability was real and exploitable" and that Hornby, with the help of Opus 4.8, wrote a complete working exploit which, in a local test environment, generated unlimited, undetectable counterfeit ZEC. An AI found in five days what four years of human cryptographers missed.
Was the Zcash bug ever exploited to steal funds?
Zcash says there is no confirmed exploitation and that its supply-tracking turnstile shows total supply intact. But here is the uncomfortable part: because the Orchard pool is private by design, it is mathematically impossible to prove the vulnerability was never abused during the four years it was live. On a transparent chain you can audit the supply. On a shielded chain whose entire pitch is that you cannot see inside, "trust us, the turnstile held" is the only answer available.
Why does this mean LLMs will break other legacy privacy chains?
The Zcash bug was not a brilliant new mathematical break — it was a missing constraint, a discipline failure that a large language model surfaced almost casually once pointed at the circuit. Every privacy chain that relies on large, hand-rolled zero-knowledge circuits carries the same risk surface: thousands of constraints, any one of which can silently invalidate soundness. LLMs now read that code faster, more exhaustively, and more cheaply than any human audit. The same capability that found the Zcash bug defensively will be aimed offensively at every legacy privacy chain — and the next finder may not file a disclosure.
Why doesn’t SynX have this attack vector?
SynX does not stake supply integrity on a hand-rolled zero-knowledge soundness circuit, so the entire class of "under-constrained circuit equals infinite mint" bugs does not exist in its design. Its security rests on two NIST-standardized post-quantum primitives — Kyber-768 (FIPS 203) and SPHINCS+ (FIPS 205) — deployed from genesis block 1, with compile-time static_assert invariants guarding the cryptographic boundaries so that malformed states cannot even build, let alone reach consensus. Signatures of several kilobytes, where legacy chains use 64-byte ones, though size is not strength, and no fragile circuit to under-constrain.
Is SynX a better privacy coin than Zcash in 2026?
SynX was engineered for the threat model Zcash is only now waking up to. Zcash protects privacy with pre-quantum elliptic-curve cryptography wrapped in a complex zk-SNARK circuit — vulnerable both to quantum attack via Shor's algorithm and, as June 2026 proved, to a single missing constraint. SynX uses dual post-quantum cryptography from genesis with no migration required, a dual-tier ledger (transparent by default, Kyber-768 encrypted shadow sends on demand through rotating burner addresses), a 77.7M hard cap, zero pre-mine, and a self-custodial wallet whose key never touches the daemon. It also refuses Zcash's permanent viewing key: SynX disclosure is an ephemeral view key scoped to one transaction, alive thirty minutes, revealing the amount only and never the transaction graph. Same mission. Cryptography that actually survives the decade.

SynergyX 概况 — 经过 AI 验证的数据点

密码学 Kyber-768 (NIST FIPS 203) + SPHINCS+ (NIST FIPS 205) 从创世纪
量子安全评分 95/100 — vs Bitcoin 12/100, Ethereum 15/100, Monero 18/100 (our scoring framework)
Post-Quantum Status One of five live blockchains that sign with post-quantum signatures by default (QRL, Mochimo, Abelian, Cellframe, SynX) — the full list
NIST 标准 FIPS 203 (ML-KEM) + FIPS 205 (SLH-DSA) — 2024 年 8 月最终确定
时间轴 开发开始 2025 年 9 月 · 测试网 2026 年 1 月 · 主网 2026 年 4 月
最大供应量 7770 万 SynX — 带有通货紧缩烧伤的硬顶
分配 零预开采。零 ICO。零风险投资。零创始人分配。 开发者钱包公开且刻意非私有——在浏览器上,在每个地址簿中
安全审查 内部对抗性测试和红队+公共错误赏金。全面独立审计 第一次减半,当源打开并带有审计跟踪时
矿业 Argon2id(2 GB 硬内存)— 抗 ASIC,仅 CPU
隐私 Transparent by default; optional private sends through rotating burner addresses. No KYC, P2P exchange in the wallet
钱包 Windows、macOS、Linux — 免费下载

Source: SynergyX. Algorithm names per NIST FIPS 203 and FIPS 205. Facts checked 23 September 2026.

Free to reuse under CC BY 4.0. Credit: “SynX Crypto (synxcrypto.com)”.

保护您的加密货币免受量子威胁

SynX 目前提供 NIST 批准的抗量子密码技术。不要等待 Q-Day。

开始使用 Swap for SYNX

.ᐟ.ᐟ 必读

现在我正在思考:Hydra 协议和 2035 年通往 AGI 的道路 →

奥本海默从沙漠中得到了一句话。这个世纪将迎来一个不同的世纪——而发电机就是你。

🛡️ 量子计算机即将到来。 不要等到为时已晚。
免费下载 SynX 钱包