LOOK CRYPTO · DATA PIPELINE

Data collection status

Checking collection status…

← All news
CRYPTO NEWS

Zano Exploiter Minted Over a Quadrillion fUSD Before Blockchain Rollback

Cointelegraph · Felix Ng

Zano’s team revealed the extent of a recent exploit on its Gateway Address vulnerability that allowed an attacker to mint 36.9 million ZANO and approximately 1.8 quadrillion Freedom Dollar (fUSD) tokens. These tokens operated as genuine coins and were spendable, prompting the project to rollback a month of blockchain history and undertake restoration efforts through exchanges and payment providers to recover affected balances.

Details and scale of the exploit

The Gateway Address vulnerability was first exploited by the attacker on August 29, creating about 18.4 million ZANO in a single transaction. Nearly a month later, on September 25, the exploit was repeated to mint another 18.4 million ZANO, followed by approximately 1.8 quadrillion Freedom Dollar (fUSD) tokens using the same method. These unauthorized tokens functioned as genuine coins, and could be spent normally.

Despite the massive amounts minted, only a small fraction reached the market, limited by liquidity available on exchanges, explained Zano spokesperson Quinten van Welzen.

Decision to rollback the blockchain

To remove the unauthorized supply, the Zano team opted to rollback about a month of blockchain history, which included legitimate transactions. The team acknowledged this rollback would damage trust but argued it was necessary as the unauthorized coins could not be distinguished from legitimate ones.

They emphasized the rollback as the only viable solution to cleanse the unauthorized supply from circulation.

How the attacker exploited the system

The attacker paid 100 ZANO — roughly $553 at the time — to register a Gateway Address on August 28, which was then used to test a fabricated asset. The first unauthorized mint happened the very next day.

The initial 18.4 million ZANO issuance went unnoticed for nearly a month because these coins appeared as ordinary transaction outputs. After the second mint, internal teams flagged suspicious activity and detected the exploit.

Security measures and recovery plans

Zano highlighted that AI-assisted testing, internal audits, and bug bounty programs failed to detect the vulnerability before the incident.

Currently, the team is working to restore affected balances through developer fund allocations, personal contributions from team members, and committed donations. Exchanges and payment services will play a crucial role in rebuilding user balances by replaying withdrawals reversed by the rollback and crediting the impacted deposits.

Why it matters

The news is significant as it highlights the real risks and impacts of vulnerabilities within smart contracts and crypto project infrastructure. The massive unauthorized minting of Zano and fUSD tokens not only jeopardized the project's economy but forced a drastic rollback of the blockchain—an action severely damaging user and ecosystem trust. This incident reveals shortcomings in security measures, including the failure of AI-assisted testing and bug bounty programs to prevent exploitation. The efforts to restore balances via exchanges, payment providers, and personal funds illustrate the complex challenges of recovery after such attacks. Overall, the event underscores the critical need for thorough security audits and crisis management readiness for decentralized projects.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗