Zano Says Exploit Illicitly Minted 36.9 Million Tokens, to Roll Back Blockchain by a Month
Summary
- Zano said it confirmed that a vulnerability exploit led to the unauthorized minting of about 36.9 million ZANO and Freedom Dollar (fUSD).
- Zano said it decided on a roughly one-month blockchain rollback to remove the illegitimate issuance and will restore the chain to a point before the unauthorized minting.
- Zano said it plans to use its developer fund, personal funds from team members and external contributions to restore deposit and withdrawal records at exchanges and payment services affected by the rollback.
Forecast Trend Report by Period



Zano said it has confirmed that a vulnerability exploit led to the unauthorized minting of about 36.9 million tokens. The cryptocurrency project said it will roll back about one month of blockchain history to remove the illegitimately issued tokens.
Cointelegraph reported on Oct. 2 that Zano, in a post-mortem report, said an attacker exploited a flaw in a gateway address to illicitly mint large amounts of ZANO in two separate incidents.
The attacker minted about 18.4 million ZANO in a single transaction on Aug. 29. The same method was used again on Sept. 25 to create another 18.4 million ZANO. Freedom Dollar, or fUSD, was also minted without authorization.
The illicitly created tokens functioned the same way as legitimate ZANO. They could be used in ordinary transactions and were effectively indistinguishable from valid supply, Zano said. The project therefore decided to restore the chain by rolling it back to a point before the unauthorized minting.
The attacker registered the gateway address on Aug. 28 and paid a 100 ZANO fee. After conducting tests, the attacker carried out the first exploit the following day. The first unauthorized minting went undetected for about a month, and irregularities were discovered during an internal investigation after the second issuance.
Zano acknowledged that it had failed to detect the vulnerability in advance through artificial intelligence-based testing, internal audits and its bug bounty program.
Separate recovery procedures will be carried out for legitimate transactions canceled by the rollback. Zano said it plans to use its developer fund, personal funds from team members and external contributions to restore affected deposit and withdrawal records at exchanges and payment services in stages.