Zano exploiter created 36.9M unauthorized ZANO before blockchain rollback
The attacker minted 36.9 million ZANO and fUSD tokens using a Gateway Address flaw, leading Zano to roll back about a month of chain history.
Key takeaways
- 36.9M tokens minted. The exploiter created 36.9 million unauthorized ZANO in two 18.4 million mints.
- Rollback erased a month. Zano rolled back about a month of blockchain history, nullifying legitimate transactions.
- Attack cost $553. The attacker paid 100 ZANO, worth about $553, to set up the exploit.
What happened
Zano said an attacker exploited its Gateway Address vulnerability to create 36.9 million ZANO and fUSD tokens. The team rolled back about a month of blockchain history to remove the unauthorized supply.
The attacker registered a Gateway Address on Aug. 28 and paid a registration fee. The first exploit on Aug. 29 created about 18.4 million ZANO. A second mint on Sept. 25 created another 18.4 million ZANO.
The attacker used the same method to create fUSD. Reports say the attacker fabricated approximately 1.8 quadrillion units of fUSD.
Zano said the unauthorized tokens behaved like real ZANO and were spendable. The first 18.4 million ZANO mint went unnoticed for nearly a month. Internal teams flagged the activity after the second mint.
Why it matters
The rollback removed unauthorized supply but also nullified all legitimate user transactions in that window. Zano acknowledged the decision would hurt trust but said it was necessary because the coins could not be distinguished from legitimate ones.
The attack cost only 100 ZANO, worth about $553. Standard security measures, including AI-assisted testing, internal audits and bug bounties, failed to catch the bug.
Zano said it is working to restore affected balances using its developer fund, team members' personal funds and committed contributions. Recovery will run through exchanges and payment services.
What the data shows
- Total unauthorized ZANO created: 36.9 million.
- First mint on Aug. 29: approximately 18.4 million ZANO.
- Second mint on Sept. 25: another 18.4 million ZANO.
- Unauthorized fUSD created: approximately 1.8 quadrillion units.
- Attack cost: 100 ZANO, worth about $553.
- Only a fractional percentage of manufactured tokens reached secondary trading markets.
Background
- The attacker registered a Gateway Address on Aug. 28 and tested a fabricated asset before the first unauthorized mint.
- The first exploit on Aug. 29 created 18.4 million ZANO in a single transaction.
- The second exploit on Sept. 25 created another 18.4 million ZANO.
- The first mint went unnoticed for nearly a month, internal teams flagged activity after the second mint.
What is still unclear
- Reports do not specify the exact date the rollback took effect.
- Reports do not state the total dollar value of the 36.9 million ZANO or the fUSD tokens.
- Reports do not identify the attacker.
- Reports do not detail how much of the unauthorized supply was recovered or the full compensation plan.
Questions readers ask
What was the Zano exploit?
An attacker used a Gateway Address vulnerability to create 36.9 million unauthorized ZANO and fUSD tokens. The team rolled back about a month of blockchain history to remove them.
How much did the Zano attack cost?
The attacker paid 100 ZANO, worth about $553, to set up the exploit.
Why did Zano roll back the blockchain?
The unauthorized coins were indistinguishable from legitimate ZANO, so the team could not selectively remove them. A rollback was the only way to remove the unauthorized supply.
What happens to legitimate Zano transactions during the rollback?
The rollback nullified all legitimate user transactions executed in that window. Zano said recovery will run through exchanges and payment services, with exchanges replaying reversed withdrawals and crediting affected deposits.