Zano has disclosed that an attacker exploited its Gateway Address vulnerability to create 36.9 million ZANO and Freedom Dollar (fUSD) tokens, leading to a decision to roll back the blockchain by approximately one month. According to a post-mortem published on Thursday, the exploit began on Aug. 29 when the attacker minted roughly 18.4 million ZANO in a single transaction. The same method was repeated on Sept. 25 to mint another 18.4 million ZANO, followed by the creation of fUSD tokens. The team noted that these unauthorized coins functioned as authentic assets within the ecosystem and could be spent normally, making them indistinguishable from legitimate supply.
The initial 18.4 million token mint remained undetected for nearly a month because the outputs appeared ordinary; internal teams only flagged the activity after the second mint occurred. The attacker had registered a Gateway Address on Aug. 28, paying a registration fee of 100 ZANO, valued at about $553 at the time of publication, before testing a fabricated asset. Zano acknowledged that while the rollback would damage trust, it was necessary to remove the unauthorized supply. The project stated that AI-assisted testing, internal audits, and bug bounties failed to identify the vulnerability. Recovery efforts are underway using developer funds, personal contributions from team members, and committed external support, primarily coordinated through exchanges to replay reversed withdrawals and credit affected deposits.
The Zano incident underscores the critical risks associated with protocol-level vulnerabilities where unauthorized minting creates indistinguishable counterfeit supply. By rolling back the blockchain, the team prioritized economic integrity over immutability, a trade-off that directly impacts institutional confidence and user trust. The fact that the first exploit went unnoticed for nearly a month highlights significant gaps in real-time monitoring and anomaly detection systems, even those supported by AI-assisted testing and traditional audit frameworks. This suggests that current security protocols may be insufficient for detecting sophisticated exploits that mimic normal transaction patterns, particularly in privacy-focused or complex token ecosystems.
From a market structure perspective, the reliance on centralized exchanges to facilitate recovery introduces operational dependencies that may not align with decentralized principles. While the use of developer and personal funds for restitution is a pragmatic response, it sets a precedent for how projects handle catastrophic failures without insurance or robust treasury reserves. Stakeholders must consider whether such interventions create moral hazard, where users expect bailouts rather than assessing technical risk independently. Furthermore, the failure of bug bounties to catch this specific vector indicates a need for more rigorous adversarial testing methodologies that go beyond standard code review practices.


