Zano Exploiter Minted 36.9 Million Unauthorized ZANO Before Month-Long Blockchain Rollback
Key Takeaways
- β’The attacker minted roughly 18.4 million ZANO on Aug. 29 and another 18.4 million on Sept. 25, before using the same method to create about 1.8 quadrillion fUSD tokens.
- β’Because the counterfeit coins were identical to legitimate ones, Zano determined a rollback invalidating a month of history, including valid transactions, was the only way to remove the unauthorized supply.
- β’The attacker registered a Gateway Address on Aug. 28, paid a 100 ZANO fee worth about $553, and tested a fabricated asset one day before the first unauthorized mint.
- β’The initial 18.4 million ZANO mint went unnoticed for nearly a month, and Zano's AI-assisted testing, internal audits and bug bounties all failed to detect the vulnerability.
- β’Zano is restoring affected balances using its developer fund, team members' personal funds and committed contributions, with exchanges replaying reversed withdrawals while the team credits affected deposits.

Editor's note (Oct. 2, 6:53 am UTC): This article has been updated to include a comment from Zano head of marketing and growth, Quinten van Welzen.
Zano revealed that the attacker who exploited its Gateway Address vulnerability over the past month used the flaw to create 36.9 million Zano (ZANO), along with 1.8 quadrillion Freedom Dollar (fUSD) tokens, before the project decided to roll its blockchain back by one month.
In a post-mortem published Thursday, the team said the attacker first exploited the vulnerability on Aug. 29, creating approximately 18.4 million ZANO in a single transaction. The exploit was repeated on Sept. 25, minting another 18.4 million ZANO, before the same method was used to create approximately 1.8 quadrillion fUSD.
"These coins functioned as authentic ZANO and could be spent normally," the team wrote in the post-mortem. Van Welzen told Cointelegraph that only a small fraction of the tokens reached the market, as the spending was limited by the liquidity available on exchanges.
The figures shed light on why the team called for a rollback of roughly one month of blockchain history, including legitimate transactions. A rollback rewinds a chain to a chosen block height and discards every transaction mined after that point, whether it was in good faith or not, which is why ordinary deposits and withdrawals from the affected month also have to be reversed and restored. Zano acknowledged that the rollback would hurt trust but argued it was necessary to remove the unauthorized supply, since it could not be distinguished from legitimate coins. That indistinguishability is what left the team with few options: once counterfeit coins are identical to genuine ones, they can only be removed from circulation by invalidating the history in which they were created.
Attacker paid 100 ZANO exploit entry fee
According to the post-mortem, the attacker paid 100 ZANO to set up the exploit, worth about $553 at the time of publication. The attacker registered a Gateway Address on Aug. 28, paid the registration fee, and tested a fabricated asset before the first unauthorized mint the following day.
The initial 18.4 million ZANO mint went unnoticed for nearly a month. The team said the unauthorized coins appeared like ordinary outputs, and internal teams flagged the activity only after the second mint. Zano added that AI-assisted testing, internal audits and bug bounties failed to detect the bug.
Related: Zano rolls blockchain back a month after Gateway Address exploit
On Wednesday, Zano said it is working to restore affected balances using its developer fund, team members' personal funds and committed contributions. Recovery will primarily run through exchanges and payment services, with exchanges set to replay withdrawals reversed by the rollback while the team credits the affected deposits. Because the restoration depends on coordination with individual platforms, users who deposited or withdrew during the affected month may need to watch for announcements from the exchanges and payment services where they held funds. The team has also shared updates on X.
The original report was published by Cointelegraph.