Zano Attacker Minted 36.9M ZANO, 1.8 Quadrillion fUSD Before Rollback

Zano reveals an attacker minted 36.9 million ZANO and 1.8 quadrillion fUSD before the network rolled back roughly one month of history.
Table of Contents

TL;DR

  • Zano says an attacker exploited Gateway Addresses to mint 36.9 million unauthorized ZANO and roughly 1.8 quadrillion fUSD before the network rolled back about one month.
  • The attacker first minted roughly 18.4 million ZANO on August 29, repeated the exploit on September 25, and created the enormous fUSD supply afterward.
  • Only a small fraction reportedly reached markets, while Zano is restoring balances through development funds, team contributions and exchange coordination.

Zano has disclosed the scale of the Gateway Address exploit that forced the project to erase roughly one month of blockchain history. In an official update, the team said the attacker created 36.9 million unauthorized ZANO and approximately 1.8 quadrillion fUSD, a Freedom Dollar asset issued on the privacy focused network. The newly minted assets behaved like legitimate coins, making selective removal impossible once they entered the ledger. The disclosure clarifies why developers considered a disruptive rollback necessary despite the damage to legitimate transaction history.

Gateway Address Exploit Went Undetected for Nearly a Month

The exploit began on August 29, one day after the attacker registered a Gateway Address and paid the required 100 ZANO fee. A first transaction created roughly 18.4 million ZANO, followed by another 18.4 million on September 25 and the massive fUSD mint. The first unauthorized issuance remained undetected for nearly a month, explaining why the eventual Zano rollback reached back to the period immediately before Hard Fork 6.

Zano says an attacker exploited Gateway Addresses to mint 36.9 million

Zano said the forged outputs were indistinguishable from ordinary ZANO and could be spent normally. That prevented the team from invalidating only the attacker’s coins without changing valid chain history. According to the information released, only a small fraction reached the market because exchange liquidity limited how much could be sold. The gap between the amount minted and the amount actually monetized is crucial, because unauthorized supply was enormous even though realized market impact was far smaller.

The team chose to restart the blockchain from block 3,833,000, removing both the unauthorized assets and legitimate transactions recorded during the affected period. Transfers already settled on other blockchains cannot be reversed, leaving recovery work for exchanges and users. The rollback prioritized restoring the intended supply at the cost of transaction finality, a trade-off also seen in debates around unauthorized token minting and emergency chain recovery.

Zano said AI-assisted testing, internal audits and bug bounties failed to detect the Gateway Address vulnerability before exploitation. The project is working to restore affected balances using its developer fund, personal funds from team members and committed contributions, while exchanges are expected to replay withdrawals reversed by the rollback. The incident shows that patching the technical flaw is only part of recovery, because projects must also reconcile balances and restore user confidence after ledger-level intervention, a challenge explored in post-exploit recovery.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews