0x3ef202e63ef2…3ef202e3

ConfirmedSecurity469 vB44 sat/vB2 min decode

Zano Attacker Minted 36.9M ZANO in Two Transactions Before Rollback

Zano's post-mortem says an attacker minted 36.9M ZANO via a Gateway Address flaw, paying just 100 ZANO to set up the exploit that forced a month-long rollback.

Zano exploiter created 36.9M unauthorized ZANO before blockchain rollback
WitnessZano exploiter created 36.9M unauthorized ZANO before blockchain rollbackAI-generated

Outputs

  1. Attacker minted 36.9M unauthorized ZANO in two transactions (Aug. 29 and Sept. 25), plus fUSD tokens

  2. Exploit entry cost was a 100 ZANO Gateway Address registration fee (~$553)

  3. Unauthorized coins were indistinguishable from legitimate ZANO, forcing a one-month blockchain rollback; recovery runs via developer fund, team funds and committed contributions through exchanges

Zano has confirmed that the attacker behind last month's Gateway Address exploit created 36.9 million unauthorized ZANO tokens before the project rolled its blockchain back by roughly a month.

In a post-mortem published Thursday, the privacy-focused blockchain project said the attacker first exploited the vulnerability on Aug. 29, minting approximately 18.4 million ZANO in a single transaction. The attack went unnoticed for nearly a month. On Sept. 25, the same actor repeated the exploit, producing another 18.4 million ZANO, before using the same method to create Freedom Dollar (fUSD) tokens. A portion of the unauthorized supply entered the Zano ecosystem, the team said.

The counterfeit coins were functionally identical to legitimate ones. "These coins functioned as authentic ZANO and could be spent normally," the team wrote in the post-mortem. That indistinguishability is the core reason Zano opted for a rollback covering about a month of chain history, including legitimate transactions. The team acknowledged the move would damage trust but argued it was the only viable way to remove the unauthorized supply, since no technical marker separated forged coins from real ones.

The entry cost of the attack was minimal. The attacker registered a Gateway Address on Aug. 28 and paid a 100 ZANO registration fee — worth about $553 at the time of publication. Before the first unauthorized mint the next day, the attacker tested a fabricated asset through the same mechanism. The first 18.4 million ZANO mint escaped detection because the unauthorized coins appeared as ordinary outputs on the network, according to the post-mortem. Internal teams flagged the activity only after the second mint on Sept. 25.

The post-mortem also addressed why the bug survived pre-launch scrutiny. Zano said AI-assisted testing, internal audits and bug bounties all failed to surface the flaw in the Gateway Address system.

Recovery operations are now underway. In a Wednesday statement, Zano said it is restoring affected balances using its developer fund, personal contributions from team members and committed donations. The process will run primarily through exchanges and payment services: exchanges will replay withdrawals that the rollback reversed, while the Zano team compensates for affected deposits credited to those platforms.

The rollback itself carries operational consequences beyond reputational harm. By invalidating roughly a month of transactions, the project has forced exchanges, payment processors and users to reconcile balances against a rewritten chain state — a coordination burden that now defines its recovery timeline. Projects building on privacy chains with custom asset issuance systems, such as Zano's Gateway Addresses, will face sharper scrutiny of how forged supply can be detected and isolated without rewriting consensus history.

Zano has not disclosed a completion date for balance restoration, leaving the recovery window dependent on how quickly exchange partners replay reversed withdrawals and reconcile affected accounts.

via x.com (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles