Home Cybersecurity SKN | Zano Exploiter Created 36.9M Unauthorized ZANO Before Blockchain Rollback
Cybersecurity

SKN | Zano Exploiter Created 36.9M Unauthorized ZANO Before Blockchain Rollback

Share
Share

Key Points

  • The attacker exploited Zano’s Gateway Address vulnerability twice, creating approximately 36.9 million unauthorized ZANO.
  • The illicit tokens were indistinguishable from legitimate ZANO and could be spent normally, leaving a blockchain rollback as the mechanism for removing the unauthorized supply.
  • Zano rolled back roughly one month of blockchain history and is working to restore affected balances through exchanges, payment services and contributions from its developer fund and team.

The Zano blockchain was forced to roll back approximately one month of transaction history after an attacker exploited a Gateway Address vulnerability to create 36.9 million unauthorized ZANO, exposing the difficulty of reversing supply inflation when malicious tokens are indistinguishable from legitimate assets.

According to Zano’s post-mortem, the attacker first exploited the vulnerability on Aug. 29, creating approximately 18.4 million ZANO in a single transaction. The exploit was repeated on Sept. 25, producing another 18.4 million ZANO before the attacker used the same vulnerability to create Freedom Dollar (fUSD) tokens.

Zano said a portion of the unauthorized assets entered its ecosystem before the vulnerability was identified.

Unauthorized ZANO Appeared Legitimate

The central problem was that the newly created coins did not carry an identifiable marker distinguishing them from legitimate ZANO.

The project said the unauthorized coins functioned as authentic ZANO and could be spent normally. Because the blockchain could not reliably distinguish the illicit supply from legitimate coins, developers concluded that simply removing the attacker’s tokens was not technically feasible.

That ultimately led the team to support a rollback covering approximately one month of blockchain history, including legitimate transactions that occurred during the affected period.

Zano acknowledged that reversing valid transactions could damage confidence in the network but argued that restoring the intended monetary supply required removing the unauthorized coins from the chain.

Attacker Paid 100 ZANO to Exploit the Bug

The post-mortem indicates that the attacker spent only 100 ZANO to gain access to the exploit mechanism, worth approximately $553 at the time of publication.

The attacker registered a Gateway Address on Aug. 28 and paid the required registration fee. The address was then used to test a fabricated asset before the first unauthorized ZANO mint the following day.

The initial creation of approximately 18.4 million ZANO remained undetected for almost a month. Zano said the unauthorized coins appeared as ordinary blockchain outputs, making them difficult to identify through routine monitoring.

The team detected the activity after the attacker performed the second major mint on Sept. 25.

Security Testing Did Not Detect Vulnerability

Zano said the Gateway Address vulnerability was not identified through its AI-assisted testing, internal audits or bug bounty program.

The disclosure highlights the difficulty of detecting vulnerabilities that involve interactions between asset issuance mechanisms and blockchain accounting rules. In this case, the exploit allowed unauthorized supply creation while leaving the resulting coins indistinguishable from valid assets.

The project has not indicated that the attacker’s ability to create the unauthorized supply was based on a weakness in Zano’s cryptographic security itself; the disclosed issue centered on the Gateway Address mechanism.

Zano Begins Balance Recovery

The rollback also created a separate challenge for users and businesses whose legitimate transactions were reversed.

Zano said it is working to restore affected balances using resources from its developer fund, contributions from team members and additional committed funds.

Recovery will primarily be coordinated through cryptocurrency exchanges and payment services. Exchanges are expected to replay withdrawals that were reversed by the rollback, while the Zano team will credit affected deposits.

The approach is intended to restore legitimate balances without reintroducing the unauthorized supply created through the exploit.

Outlook

The Zano incident demonstrates the operational consequences of a supply-creation vulnerability when unauthorized assets cannot be distinguished from legitimate coins at the protocol level. Rather than attempting to identify and destroy individual illicit holdings, the project opted to reverse the affected blockchain history.

The rollback preserves the intended ZANO supply but also introduces reconciliation work for legitimate users, exchanges and payment providers. Zano’s recovery effort will therefore be an important part of determining how effectively the ecosystem can restore balances and resume normal operations after the exploit.

 

Comparison, examination, and analysis between investment houses

Leave your details, and an expert from our team will get back to you as soon as possible

    Share

    Don't Miss

    SKN | CLARITY Act Stalls as SEC and CFTC Move Ahead With Crypto Rules

    Key Points: The CLARITY Act failed to advance in the U.S. Senate on Sept. 15, leaving comprehensive congressional market-structure legislation unresolved. The SEC...

    SKN | LATAM Stablecoin Liquidity May Depend on Small Group of Providers

    Key Points: A report analyzing 494 companies in Latin America identified only 16 primarily focused on wholesale stablecoin-to-fiat liquidity, treasury and credit. Verda...

    Related Articles

    SKN | Core Lightning Warns Attackers Are Targeting Unpatched Bitcoin Nodes

    Key Points Core Lightning urged operators running version 26.06.7 or earlier to...

    SKN | Bitget Says $388M Hack Exploited Third-Party Security Vulnerability

    Key Points: Bitget CEO Gracy Chen said the exchange’s $388 million exploit...

    SKN | Sequans Exits Bitcoin Treasury Strategy After Selling Remaining 314 BTC

    Key Points Sequans Communications sold its remaining 314 BTC, completing its exit...

    SKN | North Korean Fake Recruiters Infect 30,000 Devices and Steal $10.7M in Crypto

    Key Points North Korean-linked cyber group WaterPlum targeted developers and IT professionals...

    Investcoin

    GET A FREE, EXPERT-BACKED
    INVESTMENT COMPARISON TODAY