A month’s worth of history on Zano’s blockchain has been reversed, and the reason behind it is now known: an attacker took advantage of a Gateway Address weakness to produce 36.9 million unauthorized ZANO, alongside Freedom Dollar (fUSD) tokens, before the rollback was carried out.
Thursday’s post-mortem from Zano confirmed that the unauthorized coins could be spent normally, according to the team. This meant the unauthorized supply could not be distinguished from the legitimate coins, leaving a rollback as the sole available solution.
The attack unfolded in three steps
On Aug. 29, the attacker took advantage of the vulnerability and produced roughly 18.4 million ZANO through a single transaction. A second exploit occurred on Sept. 25, resulting in an additional 18.4 million ZANO being created. Both times, the attacker employed the same technique, and it was later used to generate fUSD, with some of it entering the Zano ecosystem.
According to the team, these coins operated as genuine ZANO and were spendable in regular transactions. This arrangement prevented the unauthorized supply from being distinguished from the real coins, leaving a rollback as the sole remedy.
The entry fee was tiny
To arrange the exploit, the attacker paid a fee of 100 ZANO, equivalent to roughly $553, at the time of publication. The payment secured entry into the Gateway Address vulnerability, which the attacker registered on Aug. 28.
On the day after the attack, the perpetrator tested a fabricated asset ahead of the very first unauthorized mint on Aug. 29. That initial 18.4 million ZANO mint went undetected for nearly a month, with the team stating that the unauthorized coins showed up as if they were normal outputs.
The internal team did not raise concerns until the second mint took place on Sept. 25.
How the exploit went undetected
The bug was not found by any of the three systems Zano named: AI-assisted testing, internal audits or bug bounties. Each one, according to Zano, failed to catch it.
The group admitted the rollback would damage trust but said it was needed to take out supply that had been put in without permission, since it could not be told apart from real coins. The numbers help explain why the Zano team asked for a rollback of roughly a month of blockchain history, covering genuine transactions along with it.
Recovery details
On Wednesday, Zano stated it is working to restore affected balances using its developer fund, personal funds from team members, and committed contributions. Recovery will mainly go through exchanges and payment services, where exchanges will replay withdrawals that were reversed by the rollback and credit the team for the affected deposits.
The recovery effort is still underway.
The stakes of a rollback
This reversal process treats valid transactions the same way it treats the unauthorized ones, which means honest users who believed their transactions were completed could end up losing the advantages of those dealings.
The trust cost is real, even though Zano’s team described the choice as a necessary evil. The post-mortem failed to explain whether the team intends to restore confidence after the recovery is finished.
What we know so far
- The attacker exploited a Gateway Address vulnerability
- The first unauthorized mint was 18.4 million ZANO on Aug. 29
- The second mint was another 18.4 million ZANO on Sept. 25
- The attacker also created fUSD, with some entering the ecosystem
- The attacker paid 100 ZANO to register the exploit, worth about $553
- AI-assisted testing, audits and bug bounties all failed to detect the bug
- Zano is restoring balances using a developer fund, personal funds and committed contributions
The path forward
A month of history has been undone at Zano, and the work of putting things right continues. Funds set aside for development, personal money from team members, and promised contributions are all being used to bring back balances that were harmed by the rollback.
The recovery effort will rely mainly on exchanges and payment services, which will handle the restoration of funds. Exchanges will replay withdrawals that were undone by the rollback, while the team credits any affected deposits.
The team admitted the price paid in trust but said the rollback was needed to get rid of the unauthorized supply, and whether it will actually win back confidence remains to be seen.
The broader security picture
The exploit exposed a serious weakness in Zano’s security architecture. The fact that AI-assisted testing, audits and bug bounties all failed to detect the bug is troubling, and it raises questions about the effectiveness of Zano’s existing security controls.
Right now, the focus is on getting things back to normal. People whose accounts were touched by the rollback will have to sit tight while exchanges work through their transactions again and the team puts their money back into their accounts.
Open questions
A complete tally of the losses has yet to surface, and Zano has offered no detailed account of how individual users were affected financially. Such information will probably come to light as the restoration effort moves forward.
It’s evident that Zano was presented with a tough decision: permit the unauthorized supply to keep circulating without end or undo a month of transactions. The team opted for the second course, and the results are now being seen.
The flaw has come to light, the tokens have appeared, and the ledger has been undone. The restoration will show whether Zano can win back confidence more quickly than it forfeited it.
Source material: “Zano exploiter created 36.9M unauthorized ZANO before blockchain rollback,” Cointelegraph.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

