
Zano has published a post-mortem detailing how an attacker exploited a “Gateway Address” vulnerability over the past month—producing tens of millions of newly minted tokens before the project rolled back its blockchain by about a month to remove the unauthorized supply.
In its report, the Zano team said the attacker first used the bug on Aug. 29, then repeated the same minting method on Sept. 25. The attacker ultimately created 36.9 million Zano (ZANO) and 1.8 quadrillion Freedom Dollar (fUSD) tokens using fabricated assets, according to Zano’s findings. Zano marketing and growth head Quinten van Welzen told Cointelegraph that only a small portion reached external markets, largely constrained by liquidity on exchanges.
Key takeaways
- Zano’s post-mortem attributes the exploit to two separate unauthorized minting events on Aug. 29 and Sept. 25, totaling 36.9 million ZANO.
- The same exploit was used to mint roughly 1.8 quadrillion fUSD tokens, which the team says behaved like normal Zano outputs.
- Zano executed a rollback of about one month of blockchain history because the project could not reliably distinguish unauthorized tokens from legitimate ones.
- Recovery is planned through exchanges and payment services, with affected withdrawals reversed and deposits credited, with funds coming from the developer fund, team members’ personal funds, and committed contributions.
What the exploit did—and how the attacker repeated it
Zano’s post-mortem says the attacker took advantage of the Gateway Address vulnerability after registering a Gateway Address on Aug. 28 and paying the associated fee. The attacker then tested a fabricated asset the next day before conducting the first unauthorized mint.
According to Zano, the first exploit run occurred on Aug. 29, when the attacker created approximately 18.4 million ZANO in a single transaction. The team added that the second minting event happened on Sept. 25, again creating about 18.4 million ZANO using the same approach.
After minting ZANO twice, the attacker used the same methodology to generate roughly 1.8 quadrillion fUSD tokens. Zano said these coins operated as if they were authentic ZANO and could be spent normally—an important detail explaining why the activity could blend in with regular on-chain outputs for a period of time.
Why Zano chose a month-long blockchain rollback
The project’s reasoning for rolling the blockchain back by about a month centers on the nature of the compromised tokens. Zano acknowledged that a rollback harms trust because it rewinds not only attacker activity but also legitimate transactions recorded during the affected window.
However, Zano argued that the unauthorized supply could not be distinguished from legitimate coins with sufficient certainty. As a result, leaving the tokens in place would risk a persistent contamination of the ledger—something the team viewed as worse for long-term confidence than reversing history.
Zano’s report also sheds light on why detection lagged: the unauthorized mints were, in the team’s words, “ordinary outputs,” and internal teams identified the activity only after the second mint.
Earlier coverage from Cointelegraph noted the decision to roll back the chain following the Gateway Address exploit.
Detection gaps and testing failures
Zano said multiple defenses failed to catch the vulnerability in time. The post-mortem cited AI-assisted testing, internal audits, and bug bounties—efforts meant to uncover issues before deployment or exploitability.
The team’s timeline suggests that even after an initial mint on Aug. 29, the exploit went unnoticed for nearly a month. Zano described that the attacker’s first 18.4 million ZANO mint did not trigger detection because the tokens looked legitimate at the output level. That changed only after the second mint, when the internal flags triggered further review.
Another detail from the report points to how the attacker secured access: Zano said the attacker paid an entry fee of 100 ZANO to set up the exploit, which Zano estimated at about $553 at the time of publication. After registering the Gateway Address on Aug. 28 and conducting a preliminary test, the attacker proceeded with the unauthorized mint the following day.
How affected users will be restored
Zano also outlined the next phase: restoring impacted balances using a combination of sources. The project said it is working to restore affected balances through its developer fund, team members’ personal funds, and committed contributions.
Recovery, Zano said, will run primarily through exchanges and payment services. Because the rollback reverses certain chain history, Zano stated that exchanges to replay withdrawals that were reversed by the rollback will be credited for affected deposits.
In addition, Zano’s marketing and growth lead Quinten van Welzen told Cointelegraph that only a small fraction of the minted tokens reached the market, attributing this to liquidity limitations on exchanges. That suggests that while the exploit created significant amounts of ZANO and fUSD on-chain, the practical ability to distribute those tokens externally may have been limited.
For users watching the fallout, the key practical detail is that Zano is not only addressing the supply problem via the rollback—it is also coordinating with downstream services to restore balances. That execution will likely determine how quickly traders and holders can regain confidence in the system’s accounting and their ability to transact normally.
Going forward, readers should monitor Zano’s post-rollback recovery process with exchanges and payment services, and watch for updates on any new security measures intended to prevent Gateway Address-style vulnerabilities from slipping through audits and testing again.
https://www.cryptobreaking.com/zano-exploiter-minted-over-1/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Zano%20Exploiter%20Minted%20Over%201%20Quadrillion%20fUSD%20Before%20Rollback%20
Comments
Post a Comment