TLDR
- A malicious actor leveraged a Gateway Address vulnerability on the Zano network to generate 36.9 million illegitimate ZANO tokens and 1.8 quadrillion fUSD stablecoins.
- The security breach remained undetected from August 29 through September 25 before discovery by the development team.
- Network administrators implemented a blockchain reorganization spanning approximately 30 days to eliminate counterfeit assets.
- Valid user transactions processed during the affected timeframe were also removed in the rollback.
- Compensation for impacted users will come from the project’s development treasury and team member donations.
The Zano development team has officially acknowledged that a malicious actor successfully exploited a critical vulnerability within its Gateway Address infrastructure to generate massive quantities of illegitimate tokens. Complete incident details were disclosed in a comprehensive post-mortem analysis released on Thursday.
According to the timeline provided, the perpetrator initially discovered the security flaw on August 28. After registering a Gateway Address and submitting a minimal registration fee, they conducted preliminary testing using a fabricated asset.
The following day, August 29, marked the first major exploitation event when approximately 18.4 million ZANO tokens were fraudulently created in a single blockchain transaction. This initial compromise remained completely invisible to network monitoring systems for nearly four weeks.
On September 25, the attacker executed a second wave of the same exploit pattern. An additional 18.4 million ZANO tokens were manufactured through identical methodology.
The hacker subsequently deployed the vulnerability once more to fabricate approximately 1.8 quadrillion units of fUSD, the stablecoin asset native to Zano’s ecosystem.
Technical Breakdown of the Vulnerability
According to Zano’s technical analysis, the counterfeit tokens were completely identical to legitimate ZANO at the protocol level. No distinguishing characteristics existed to separate authentic from fraudulent assets after blockchain integration.
“These coins functioned as authentic ZANO and could be spent normally,” the development team stated in their official incident report.
Quinten van Welzen, serving as spokesperson for the Zano project, confirmed to Cointelegraph that only a fractional percentage of the manufactured tokens successfully reached secondary trading markets. He attributed this limited distribution to insufficient liquidity depth across cryptocurrency exchanges.
The financial investment required to execute this entire attack amounted to merely 100 ZANO tokens. Based on current market valuations, this represents approximately $553 in total attack costs.
Network security personnel only identified the breach following the second minting event in late September. The initial August exploitation had completely evaded all monitoring protocols.
The development team acknowledged that their standard security infrastructure failed to identify this vulnerability prior to exploitation. This included artificial intelligence-enhanced testing frameworks, comprehensive internal security audits, and active bug bounty reward programs.
Rationale Behind the Blockchain Reorganization
Given that fraudulent tokens possessed no distinguishing features from legitimate assets, selective removal proved technically impossible. Network administrators determined that a complete blockchain rollback represented the only viable remediation strategy.
The chain reorganization encompasses approximately one month of historical blockchain data. Consequently, all legitimate user transactions executed during this window were also nullified.
Zano’s leadership acknowledged that this controversial decision would inevitably damage community confidence. However, they maintained that preserving long-term network integrity required this drastic intervention.
In response to the rollback execution, Zano has initiated a comprehensive user compensation framework. Funding will be sourced from the project’s designated development treasury, supplemented by voluntary contributions from core team members.
Cryptocurrency exchanges and payment infrastructure providers will serve crucial functions in the restoration process. These platforms will manually replay withdrawal transactions that were invalidated through the rollback procedure.
User deposit balances affected by the chain reorganization will be manually restored by participating exchange platforms. The project has not yet established definitive completion deadlines for this restoration initiative.
This incident demonstrates how isolated technical vulnerabilities can necessitate comprehensive blockchain restructuring. It simultaneously reveals significant limitations in contemporary security testing methodologies for identifying token generation exploits before active deployment.



