AI Is Rereading Cryptos Old Code, and Finding What Humans Missed

Abstract:Key TakeawaysZcash had a 4-year-old flaw hiding in its code until Claude Opus 4.8 helped a researcher finally uncover it.Coldcards 2021 firmware flaw

Key Takeaways

  • Zcash had a 4-year-old flaw hiding in its code until Claude Opus 4.8 helped a researcher finally uncover it.
  • Coldcards 2021 firmware flaw preceded more than $100 million in estimated bitcoin thefts across thousands of addresses.
  • Chainalysis says malicious onchain dead-drop activity jumped 440%, showing how quickly AI-assisted threats are picking up steam.

Things are certainly changing fast. An encrypted German Army transmission from July 1941 survived 85 years before an AI-assisted effort finally cracked it this month. The message was almost comically ordinary, essentially someone in Rosenow asking which way to march, but AI agents helped search archives, write code, simulate Enigma, and test possibilities until the old problem gave way. Crypto has spent 2026 discovering what happens when that ability to look again gets pointed at software containing actual money.

AI Goes Hunting Through Old Code

Zcash provided one of the cleanest examples in May. Researcher Taylor Hornby, working for Shielded Labs, used Claude Opus 4.8 in a custom audit agent and uncovered a flaw in the Orchard shielded-pool circuit dating to 2022. In testing, the vulnerability could create unlimited counterfeit ZEC without detection. No theft was established, and developers patched it within days, but a potentially catastrophic bug had survived roughly four years before AI-assisted review found it. Later, the Zcash team claimed to leverage Mythos to parse and audit the code and found no new bugs.

Coldcard was considerably messier. Beginning July 30, attackers swept bitcoin from wallets affected by a firmware weakness traced to 2021 that left some recovery seeds far less random than intended. Later estimates reached roughly 1,600 to more than 1,800 BTC and over $100 million across thousands of addresses. Coinkite, Coldcard‘s manufacturer, said it had to assume somebody used AI to inspect its public firmware, while many observers expressed high confidence unrestricted models were involved. The attribution isn’t settled, but the vulnerability itself had been sitting there for five years.

Sometimes the Machine Gets Tricked

Bankr flipped the equation around too, because the AI became part of the attack surface. On May 4, an attacker posted Morse-code text that Grok decoded into an instruction Bankr accepted, triggering the transfer of roughly 3 billion DRB worth around $150,000 to $200,000. Roughly two weeks later, the same general trust-layer problem hit 14 user wallets, with reported losses ranging from about $150,000 to $440,000. The attacker didnt crack cryptography. The machines trusted each other too much.

AI also appears to be making difficult smart-contract code cheaper to dissect. Chainalysis linked roughly $36.7 million in thefts to attacks against protocols with unverified contracts, where attackers first had to decompile the deployed bytecode. Ekubo and Trusted Volumes accounted for roughly $7 million of that cluster during the six-month period, although Chainalysis AI connection is a method claim rather than proof that a named model created each exploit.

Then there were the fake “Claude-built” arbitrage bots. Nine similar YouTube tutorials directed viewers to copy code into a bogus Remix-style compiler that secretly substituted a drainer. TRM counted 224 victims, 234 contracts, and roughly $517,000 lost. In this case, AI wasnt the weapon at all. It was the bait.

The 440% Number Changes the Story

None of this means every giant crypto hack in 2026 was AI-driven. Some exploits have no established AI connection, despite many suspecting involvement, along with numerous other DeFi attacks this year. Thats an important dividing line. A number of 2026 incidents have documented AI involvement, others carry credible suspicions, and plenty still come down to old-fashioned bugs, keys, permissions, and broken systems.

Chainalysis blockchain dead-drop data, however, suggests the broader economics are changing. Malicious onchain writes carrying malware instructions and command-and-control information climbed from roughly 2.06 per day to 11.1, a 440% increase. Powerful open-weight AI models can lower the expertise needed to build this infrastructure, while state-linked actors associated with North Korea and Iran accounted for roughly two-thirds of newly observed activity each quarter by the second quarter of 2026.

The Enigma lesson isn‘t that AI can suddenly crack Bitcoin’s cryptography. Its that machines make it cheaper to look again. Zcash found an old mistake before an attacker did, while the Coldcard fiasco shows what the opposite can look like. Crypto has years of public code waiting to be reread, and nobody knows how many Rosenows are still hiding inside it.

Disclaimer

The views in this article only represent the author's personal views, and do not constitute investment advice on this platform. This platform does not guarantee the accuracy, completeness and timeliness of the information in the article, and will not be liable for any loss caused by the use of or reliance on the information in the article.
Previous Post

VanEck flags Metaplanet as 'Bad' - Calls its executive pay a 'shareholder trap'

Next

Why Was Bitcoin Rejected at $82K? 3 Reasons Behind the Sunday Pullback