Security engineer Taylor Hornby said he has added Monero (XMR) to his audit queue and plans to conduct security reviews of additional privacy-coin projects.
According to ChainCatcher, Hornby previously identified a critical vulnerability in Zcash’s Orchard shielded pool on May 29. He said the issue had gone unnoticed since May 2022 and, in theory, could have allowed an attacker to mint unlimited counterfeit ZEC without detection.
Shielded Labs, the team responsible for development, completed an emergency fix before June 1 and later publicly disclosed details of the vulnerability. After the disclosure, ZEC at one point fell 38% within 24 hours, as the market worried the flaw might have been exploited to steal funds from the shielded pool without leaving on-chain traces.
Hornby said he was commissioned in April by the nonprofit Shielded Labs to identify protocol vulnerabilities before attackers could find them. He added that although he had the ability to profit from the vulnerability, he reported it to the development team instead.
Hornby also said he plans to apply for Zcash community funding to support further security research.