Privacy-focused cryptocurrency project Zano has published a postmortem explaining why it rewound its blockchain by roughly 30 days, an unusually drastic step tied to the creation of more than $200 million in unauthorized tokens.
According to the team, the issue stemmed from a missing verification in Gateway Addresses, a feature added to simplify integrations with exchanges, bridges, and similar services. The flaw allegedly let an attacker mint about 18.4 million ZANO in a single transaction, repeat the process later, and carry out the same technique with the fUSD stablecoin.
How the bug worked
Gateway Addresses were introduced as a new address type whose outputs reveal an amount and asset ID, unlike Zano’s usual confidential outputs where both values are hidden. Zano said that implementation lacked a critical check tied to transaction validation.
The project said an attacker could craft a specially calculated asset identifier that still passed the network’s proofs while inserting an arbitrary amount into a hidden output. In Zano’s account, the result was not merely a display error or accounting anomaly: the minted coins behaved as normal ZANO and could be spent on the network.
Timeline of the exploit
Zano said the attacker first registered a Gateway Address on Aug. 28, paying the required 100 ZANO fee, and appears to have tested whether the network would accept a constructed nonexistent asset. The next day, a transaction created roughly 18.4 million ZANO, which the article values at about $102 million at current prices.
The first exploit was not detected for nearly a month. On Sept. 24, the attacker made two legitimate deposits of 0.05 ZANO each, which Zano believes may have been a test of the standard deposit path. On Sept. 25, another 18.4 million ZANO was minted, followed by the same 2^64-base-unit method applied to fUSD. Zano said the total value of the illicitly created tokens exceeded $200 million.
The team added that AI-assisted testing, internal audits, and bug bounty work conducted before Hard Fork 6 did not identify the vulnerability.
Why privacy made cleanup harder
Zano said the exploit became much harder to isolate once the unauthorized coins entered its confidential transaction system. Because ring signatures mix spends with other outputs, uncertainty spread as those coins moved across the network.
By block 3,878,388, the project said its review had linked the trail to 117,941 outputs generated through 65,301 transactions. It also estimated that about 165,700 outputs had later been created from the first mint alone, accounting for roughly 71% of network activity during the affected period.
The team said this meant it could not accurately distinguish legitimate outputs from tainted ones. In its view, the only reliable way to restore supply integrity was to continue the chain from a point before the first exploit occurred.
Rollback, recovery and next steps
Zano chose block 3,833,000, a point before Hard Fork 6, as the restart location. Under Hard Fork 7, the network resumed from there and Gateway Addresses were disabled. As a result, transactions, mined blocks and staking rewards recorded during the affected month no longer exist on the updated chain.
The project said affected balances would be restored in full without changing ZANO’s supply or emission schedule. It said the recovery effort would be funded through the development fund, team members’ personal contributions and outside supporters.
For now, exchanges are expected to review roughly a month of activity before reopening access. Zano said users do not need to take any action at this stage, while the ecosystem works through the chain restart and balance recovery process.
Source: news.bitcoin.com