Community Trust ScoreVerified
A privacy coin project just had one of the messier months in recent crypto memory. Zano, a blockchain focused on confidential transactions, confirmed that an attacker exploited a flaw in its Gateway Address system to mint 36.9 million unauthorized ZANO tokens — and the team’s only real fix was to roll the entire chain back by roughly one month.
Why It Matters
The rollback of the Zano blockchain underscores the significant vulnerabilities that can exist within decentralized systems and the drastic measures that may be required to address security breaches. Such actions not only affect user trust but also raise questions about the long-term viability of privacy-focused projects, as they must balance the need for confidentiality with the integrity of their networks. This incident may prompt other blockchain projects to reevaluate their security protocols and contingency plans to prevent similar attacks.
That’s a drastic call. Rolling back a blockchain wipes out legitimate user transactions alongside the bad ones, and it’s the kind of move that can shatter confidence fast. But Zano says it didn’t have a choice. The unauthorized coins were, for all practical purposes, indistinguishable from real ZANO. You can’t surgically remove fake coins when the network can’t tell them apart from genuine ones.
How the Attack Actually Unfolded
The attacker started quietly. On August 28, they registered a Gateway Address on the network, paying the standard 100 ZANO fee — worth roughly $553 at the time. Not a huge upfront cost for what came next. They ran a small test first, fabricating an asset to check that the method worked, then went big.
On August 29, they minted around 18.4 million ZANO in a single transaction. Just like that. The coins hit the network and blended right in with legitimate outputs. Nobody caught it. Zano’s internal teams, running AI-assisted testing and internal audits, didn’t flag anything. The bug bounty program didn’t catch it either. The exploit sat undetected for almost a month.
Then on September 25, the attacker did it again. Another 18.4 million ZANO, same method. That second minting is what finally got noticed. By then, the attacker had also produced approximately 1.8 quadrillion Freedom Dollar (fUSD) tokens using the same vulnerability. Quadrillion. That’s not a typo.
The fUSD situation made things worse. Those tokens could circulate in transactions too, compounding the mess. The Zano team was now looking at a network with two different types of unauthorized supply — ZANO and fUSD — both of which looked completely normal to the chain’s own systems.
The Rollback Decision and Recovery Plan
Zano decided to roll back the blockchain by one month. It’s a painful call under any circumstances. Legitimate transactions get wiped. Users who made deposits or withdrawals during that window are suddenly in limbo. Trust takes a hit regardless of how necessary the move was.
Per Zano spokesperson Quinten van Welzen, only a small fraction of the unauthorized ZANO actually made it to market. Liquidity constraints on exchanges limited how much the attacker could actually move, which probably saved the situation from being significantly worse than it already was.
Recovery is now centered on exchanges and payment services. The team is replaying withdrawals that the rollback reversed, working directly with exchanges to credit affected deposits back to users. It’s slow, cooperative work — the kind that doesn’t make headlines but matters a lot to anyone whose funds got caught in the middle.
To cover affected balances, Zano is pulling from its developer fund, personal funds from team members, and external contributions. No specific dollar figure was given for how much that restoration pool totals, so it’s unclear yet whether it’s enough to cover everything cleanly.
Security Failures and What Comes Next
Zano didn’t try to spin this. The team admitted directly that AI-assisted testing, internal audits, and bug bounties all failed to catch the vulnerability before it was exploited twice. That’s a pretty damning list of failed safeguards. It’s also not entirely surprising — privacy-focused chains have complex transaction structures almost by design, and that complexity can create blind spots that standard testing frameworks don’t reach.
The first minting on August 29 went undetected for 27 days. That’s a long time for 18.4 million unauthorized coins to sit quietly on a network before anyone noticed. The detection only came after the second incident, which means the attacker probably could have kept going if they’d been more patient.
Zano says it’s now reviewing its auditing processes and testing protocols. The team wants to find potential vulnerabilities before they can be exploited rather than after. Specific details on what those new measures look like weren’t provided — unclear whether that means third-party audits, formal code reviews, or something else entirely.
For users, the immediate priority is getting funds restored. Exchanges are replaying reversed withdrawals. Deposits are being credited back. The 100 ZANO fee the attacker paid on August 28 — around $553 — remains one of the few concrete costs they absorbed before walking away with a network-level exploit that forced a month-long chain rollback.
Frequently Asked Questions
How many unauthorized tokens did the Zano attacker create?
The attacker minted 36.9 million unauthorized ZANO tokens across two transactions, plus approximately 1.8 quadrillion fUSD tokens using the same Gateway Address vulnerability.
How is Zano restoring user balances after the rollback?
Zano is using its developer fund, personal funds from team members, and external contributions to restore affected balances, with exchanges replaying reversed withdrawals and crediting deposits back to users.





