The privacy-focused cryptocurrency project Zano has executed an extraordinary 30-day blockchain rollback after an attacker exploited a Gateway Address vulnerability to mint 36.9 million unauthorized ZANO tokens and 1.8 quadrillion fUSD stablecoins. Because Zano's privacy features made the counterfeit tokens indistinguishable from legitimate ones, the team nullified a month of ledger history to preserve supply integrity. Zano is working with exchanges to restore affected user balances using its development treasury and team donations.
Implementation of the blockchain rollback
- ▪The Zano team implemented the rollback because the privacy system's ring signatures mixed the counterfeit coins with legitimate outputs, making surgical separation of the funds technically impossible.
- ▪Zano executed a 30-day blockchain rollback to block 3,833,000, a point prior to the first exploit, which nullified all legitimate user transactions, staking rewards, and mined blocks from that period.
Restoration of affected user balances
- ▪Zano will restore affected user balances in full without changing the ZANO supply or emission schedule, using its development fund, team members' personal money, and outside contributions.
- ▪Cryptocurrency exchanges and payment services must manually replay reversed withdrawals and credit affected deposits in stages to restore user balances canceled by the rollback.
Details of the exploit
- ▪The attacker minted approximately 36.9 million unauthorized ZANO tokens across two separate transactions of 18.4 million ZANO each on August 29, 2026 and September 25, 2026.
- ▪The attacker paid a 100 ZANO registration fee on August 28, 2026 to set up a Gateway Address and tested the exploit with a fabricated asset before executing the first unauthorized mint.
- ▪An attacker exploited a missing verification in Zano's Gateway Addresses, a feature introduced in Hard Fork 6, to bypass transaction proofs and mint arbitrary token amounts into hidden outputs.
- ▪The attacker used the Gateway Address exploit on September 25, 2026 to mint approximately 1.8 quadrillion native Freedom Dollar (fUSD) stablecoin tokens.
Detection of the exploit
- ▪Zano's internal monitoring systems flagged the exploit on September 25, 2026, after the attacker executed the second minting event.
- ▪The initial August 29, 2026 exploit went undetected for nearly a month because the unauthorized outputs appeared identical to ordinary private outputs on the network.
Gateway Address vulnerability
- ▪Zano acknowledged that its pre-release security measures, including artificial intelligence-assisted testing, internal team audits, and bug bounty programs, failed to detect the Gateway Address vulnerability.
- ▪Zano disabled Gateway Addresses and restarted the blockchain under Hard Fork 7 from block 3,833,000.
Debatable claims
- ▪Zano's 30-day blockchain rollback is justified to preserve the network's long-term integrity
- ▪Blockchain developers should fully compensate users for losses caused by protocol-level exploits
- ▪Cryptocurrency exchanges bear an unfair operational burden in resolving blockchain rollbacks
- ▪Zano's absolute transaction privacy poses unacceptable risks by preventing surgical exploit recovery
Story comments
Loading comments…