Zano exploiter minted 36.9 million unauthorized ZANO tokens before blockchain rollback

Attacker exploited Gateway Address vulnerability over two separate transactions spanning nearly one month

By LineZotpaper
Published
Read Time2 min
Zano, a privacy-focused cryptocurrency, has revealed that an attacker exploited a Gateway Address vulnerability to create 36.9 million unauthorized Zano (ZANO) tokens and Freedom Dollar (fUSD) tokens before the project opted to roll back its blockchain by roughly one month. The attacker first struck on Aug. 29, minting approximately 18.4 million ZANO, then repeated the exploit on Sept. 25 to create another 18.4 million ZANO and additional fUSD.

In a post-mortem published Thursday, Zano said the unauthorized coins were indistinguishable from legitimate ZANO, leaving the team unable to simply remove them without a more drastic measure. The decision was made to roll back the blockchain to a point before the exploit, effectively erasing the fraudulent transactions.

The vulnerability, termed a Gateway Address flaw, allowed the attacker to create tokens that the network treated as genuine. The scale of the exploit — 36.9 million ZANO created across two transactions — represents a significant portion of the total supply, though exact supply figures were not provided in the report. Zano also noted that the attacker minted Freedom Dollar tokens using the same method, though the quantity of fUSD was not specified in the post-mortem.

The rollback, which rewinds the blockchain by approximately one month, will invalidate all transactions after the revert point, potentially affecting legitimate users. Zano has not yet published details on how it plans to handle post-rollback transactions or compensate users.

§

Analysis

Why This Matters

  • The exploit undermines trust in Zano's security model, particularly its core value proposition as a privacy coin.
  • Users who transacted after the initial Aug. 29 exploit may see those transactions reversed by the rollback, raising questions about finality.
  • The incident highlights the difficulty of remediating blockchain vulnerabilities when forged tokens are cryptographically indistinguishable from legitimate ones.

Background

Zano is a cryptocurrency focused on privacy and anonymity, similar to Monero but with its own codebase. The Gateway Address vulnerability appears to have been a flaw in how the network handles incoming transactions or address resolution. Exploits that allow minting of unauthorized tokens are among the most severe blockchain bugs, as they directly inflate supply and can crash the token's value. Blockchains typically resort to hard forks or rollbacks in such cases, but each approach carries tradeoffs.

Key Perspectives

Zano team: They chose a rollback as the only way to remove the indistinguishable forged tokens, arguing it preserves the integrity of the supply. They published a post-mortem to explain the decision. Attacker: Unidentified; motivation unclear. By creating tokens that could be spent or traded, the attacker potentially profited if they managed to exchange the unauthorized tokens before the rollback. Users and traders: Those who held or transacted ZANO after Aug. 29 now face uncertainty. Legitimate transactions executed during the exploit window may be reverted, potentially causing losses or disputes.

What to Watch

  • Whether Zano releases a more detailed timeline or compensation plan for affected users.
  • If any exchange or service that accepted ZANO during the exploit period will honor or dispute pre-rollback balances.
  • How the Zano community reacts to the rollback — miners and node operators must coordinate to avoid a chain split.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.