Zano says exploiter minted 36.9 million unauthorized ZANO before one-month rollback

Zano says exploiter minted 36.9 million unauthorized ZANO before one-month rollback

N
News Editor
2026-10-02 05:02:23
Zano said an attacker exploited a Gateway Address vulnerability over the past month to create 36.9 million unauthorized ZANO and Freedom Dollar (fUSD) tokens before the project chose to roll back its blockchain by about one month. In a post-mortem published Thursday, the team said the attacker first used the bug on Aug. 29 to mint roughly 18.4 million ZANO in a single transaction, then repeated the exploit on Sept. 25 to mint another 18.4 million ZANO and later create fUSD through the same method. According to Zano, some of the unauthorized assets entered the ecosystem. The team said the coins were indistinguishable from legitimate ZANO and could be spent normally, which is why it concluded that a rollback was necessary even though it would also affect legitimate transactions and damage trust. Zano added that the attacker paid a 100 ZANO registration fee, worth about $553 at publication, to set up the exploit after registering a Gateway Address on Aug. 28. The project also said AI-assisted testing, internal audits and bug bounty efforts did not catch the flaw. On Wednesday, Zano said it was working to restore affected balances using its developer fund, personal funds from team members and committed contributions, with exchanges and payment services expected to handle much of the recovery process.

Zano said an attacker exploited its Gateway Address vulnerability over the past month to create 36.9 million unauthorized Zano (ZANO) and Freedom Dollar (fUSD) tokens before the project decided to roll back the blockchain by about one month.

In a post-mortem published Thursday, the team said the attacker first used the vulnerability on Aug. 29, creating about 18.4 million ZANO in a single transaction. The attacker used the same exploit again on Sept. 25, minting another 18.4 million ZANO, and then created fUSD through the same method. Zano said a portion of those assets entered the ecosystem.

「These coins functioned as authentic ZANO and could be spent normally,」 the team wrote in its post-mortem. Cointelegraph said it had reached out to Zano for comment.

The figures help explain why the Zano team called for a rollback covering roughly one month of blockchain history, including legitimate transactions. The team acknowledged that the rollback would hurt trust, but said it was necessary because the unauthorized supply could not be separated from legitimate coins.

Attacker paid 100 ZANO to set up the exploit

Zano said in the post-mortem that the attacker paid 100 ZANO as a registration fee to establish the exploit path, worth about $553 at the time of publication.

According to the team, the attacker registered a Gateway Address on Aug. 28, paid the fee, and tested a fabricated asset before carrying out the first unauthorized mint the next day.

The first 18.4 million ZANO mint went unnoticed for nearly a month. Zano said the unauthorized coins appeared onchain like ordinary outputs, and internal teams only flagged the activity after the second mint.

Zano also said AI-assisted testing, internal audits and bug bounty programs failed to detect the bug.

Zano says it is restoring affected balances

On Wednesday, Zano said it was working to restore affected balances using its developer fund, personal funds from team members and committed contributions. The recovery process will mainly run through exchanges and payment services: exchanges will replay withdrawals reversed by the rollback, while the team has credited affected deposits.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.