Zano exploiter created 36.9M unauthorized ZANO before blockchain rollback
Zano disclosed that a Gateway Address vulnerability was used to mint 36.9 million ZANO and some Freedom Dollar (fUSD) over about a month, prompting a rollback of roughly one month of blockchain history. The attacker paid a 100 ZANO registration fee, registered a Gateway Address on Aug. 28, then created about 18.4 million ZANO in a first unauthorized mint on Aug. 29 and another 18.4 million ZANO on Sept. 25 before using the same method to mint fUSD. The coins behaved like valid ZANO and could be spent normally, with some entering the ecosystem. Zano said the illicit supply could not be distinguished from legitimate coins, so a rollback was needed despite the trust costs. The bug went undetected for nearly a month, and AI testing, audits, and bug bounties missed it. Zano is now working to restore affected balances using its developer fund, team funds, and outside contributions.
