News

Zano Exploit Minted 36.9 Million Unauthorized Coins Before Blockchain Rollback

Zano says an attacker exploited a Gateway Address vulnerability to create 36.9 million unauthorized ZANO before the network rolled back about one month of blockchain history. The incident also involved unauthorized Freedom Dollar (fUSD) tokens.

The disclosure shows that the attacker created roughly 18.4 million ZANO on Aug. 29 in a single transaction. On Sept. 25, the attacker repeated the exploit and created another 18.4 million ZANO. Some of the unauthorized assets entered the wider Zano ecosystem.

The coins created through the exploit posed a difficult problem because they behaved like legitimate ZANO. They could be transferred and spent normally, making it impossible for the team to identify and remove only the unauthorized supply.

How the Gateway Address exploit unfolded

The attacker first registered a Gateway Address on Aug. 28 and paid a 100 ZANO registration fee. The attacker then tested a fabricated asset before executing the first unauthorized mint.

The initial creation of 18.4 million ZANO remained undetected for almost a month. After the second mint, internal teams identified the activity and began investigating the vulnerability.

Zano said previous AI-assisted testing, internal audits and bug bounty efforts had not detected the flaw. The team ultimately concluded that removing the unauthorized supply required a blockchain rollback.

Rollback erased legitimate transactions

Zano restarted the blockchain from block 3,833,000, immediately before Hard Fork 6 introduced Gateway Addresses. The rollback removed both the unauthorized assets and legitimate transactions recorded during the affected period.

The team acknowledged that reversing legitimate blockchain history would affect users and services. However, it said the unauthorized coins could not otherwise be distinguished from genuine ZANO.

Zano is now working to restore affected balances. The recovery effort will use the developer fund, contributions from team members and committed outside support. Exchanges and payment services will play a central role in restoring legitimate deposits and withdrawals affected by the rollback.

The incident highlights the consequences of a supply vulnerability when unauthorized tokens retain the same spending properties as genuine assets. Zano has also disabled the affected functionality as it works to restore normal network operations.