In a post-mortem published Thursday, Zano said the unauthorized coins were indistinguishable from legitimate ZANO, leaving the team unable to simply remove them without a more drastic measure. The decision was made to roll back the blockchain to a point before the exploit, effectively erasing the fraudulent transactions.
The vulnerability, termed a Gateway Address flaw, allowed the attacker to create tokens that the network treated as genuine. The scale of the exploit — 36.9 million ZANO created across two transactions — represents a significant portion of the total supply, though exact supply figures were not provided in the report. Zano also noted that the attacker minted Freedom Dollar tokens using the same method, though the quantity of fUSD was not specified in the post-mortem.
The rollback, which rewinds the blockchain by approximately one month, will invalidate all transactions after the revert point, potentially affecting legitimate users. Zano has not yet published details on how it plans to handle post-rollback transactions or compensate users.