Privacy-focused blockchain project Zano says an attacker exploited a Gateway Address vulnerability twice over the past month, creating 36.9 million unauthorized ZANO as well as Freedom Dollar, or fUSD, tokens before the network was rolled back.

In a post-mortem, the team said the first exploit took place on Aug. 29 and a second on Sept. 25. Because the newly created coins were indistinguishable from legitimate supply and some entered the wider ecosystem, Zano said it chose to reverse about a month of blockchain history, including valid user activity.

Two exploit events created 36.9 million ZANO

According to Zano, the attacker first used the bug on Aug. 29 to mint roughly 18.4 million ZANO in a single transaction. The same vulnerability was used again on Sept. 25 to create another 18.4 million ZANO, bringing the total unauthorized issuance to 36.9 million tokens.

The project said the attacker also applied the method to create fUSD. Zano added that at least part of the unauthorized assets made its way into the network’s economy before the issue was caught.

In its post-mortem, the team said the coins behaved like normal ZANO and could be spent without obvious differences, which complicated efforts to isolate or invalidate them after the fact.

Exploit setup reportedly cost 100 ZANO

Zano said the attack was inexpensive to initiate. The attacker allegedly registered a Gateway Address on Aug. 28, paid a 100 ZANO registration fee and then tested a fabricated asset before carrying out the first large mint the following day.

At the time of publication, that fee was worth about $553, according to the team’s disclosure. Zano said the first unauthorized issuance then went undetected for nearly a month because the outputs looked like ordinary activity on the chain.

The project said internal teams only flagged the behavior after the second mint on Sept. 25, when the pattern became visible.

Why Zano chose a rollback

The newly disclosed mint totals help explain why Zano opted for a rollback of roughly one month, a measure that also erased legitimate transactions made during that period.

The team acknowledged that such a step would damage trust, but said it saw no other practical way to remove the unauthorized supply because the illicitly created coins could not be reliably separated from valid ones.

Zano also said that AI-assisted testing, internal audits and bug bounty efforts had not identified the underlying flaw before it was exploited.

Recovery plan will run mainly through intermediaries

Zano said it is now trying to restore affected balances using its developer fund, personal funds from team members and other committed contributions.

The recovery process is expected to be handled mainly through exchanges and payment services. Under the plan described by the team, exchanges would replay withdrawals that were reversed by the rollback, while Zano would credit affected deposits.

The project has not, in the source material provided, outlined a broader onchain remedy beyond the rollback and the exchange-led balance restoration effort.

Source: cointelegraph.com