Zano Exploiter Minted 1.8 Quadrillion fUSD Before Blockchain Rollback

By Hassan Shittu

Key highlights:

  • Zano rolled back to block 3,833,000 after an attacker exploited a missing Gateway Address verification check to mint ~18.4M ZANO and ~1.8 quintillion fUSD base units between Aug. 29 and Sept. 25.
  • Ring signatures made the unauthorized outputs nearly indistinguishable from legitimate funds, potentially affecting 117,941 outputs across 65,301 transactions and ~71% of network activity.
  • Gateway addresses remain disabled pending audits. Zano will restore affected balances using its developer fund and community contributions.

Zano has rolled back its blockchain to remove unauthorized tokens created through a vulnerability in its Gateway Address system, after an attacker minted approximately 1.8 quadrillion fUSD and created additional ZANO tokens. 

The exploit exposed a flaw in the network’s transaction verification process, allowing specially constructed transactions to pass consensus checks even though they created assets that had not been legitimately issued.

Zano ultimately discarded roughly one month of transaction history and coordinated with exchanges, wallets, and payment providers to restore the network to a state before the exploit.

In a postmortem report, Zano said the vulnerability was introduced with Hard Fork 6 (HF 6) and was exploited from August 29, 2026. The team discovered the issue on September 25 after internal monitoring systems flagged suspicious on-chain activity.

The vulnerability allowed an attacker to create unauthorized ZANO and fUSD while making the transactions appear valid under the network’s consensus rules.

How the Zano exploit created millions of unauthorized coins

Zano said its investigation found no evidence that users’ private keys, ordinary transaction privacy, or existing wallet funds had been compromised. The primary problem was instead the creation of unauthorized supply, which undermined the integrity of the network’s asset balances.

The exploit centered on Gateway Addresses, a feature introduced in HF 6 to make it easier for exchanges, bridges, and other services to interact with Zano.

Unlike standard confidential transactions, Gateway outputs publicly reveal their amounts and asset identifiers. Under the intended design, the asset identifier must correspond to an asset registered on the network.

However, a missing verification check in the HF 6 implementation allowed the attacker to construct a specially calculated asset identifier that could pass the transaction proofs while concealing an arbitrary amount inside a confidential output.

Those hidden outputs could then be spent like ordinary Zano coins, making the unauthorized supply difficult to distinguish from legitimate funds.

The attacker first registered a gateway address on August 28, paying the required 100 ZANO fee. A subsequent transaction tested a constructed asset identifier before the first confirmed exploit occurred on August 29.

That transaction created 2^64 base units of ZANO, equivalent to approximately 18.4 million ZANO. 

The attacker repeated the process on September 25, creating another 2^64 base units of ZANO before using the same method to mint 2^64 base units of fUSD, amounting to approximately 18.4 quintillion base units.

The latter figure corresponds to roughly 1.8 quintillion fUSD if the asset uses 12 decimal places. 

Zano rolls back the chain after struggling to trace exploited funds

Noatbly, the post-mortem’s stated amount is in base units, so the distinction between base units and whole tokens is important when assessing the scale of the exploit.

Zano said the figures represent the total unauthorized amounts created, although only a portion entered the wider ecosystem.

The team initially struggled to trace the affected coins because the exploit outputs became indistinguishable from ordinary confidential transactions. 

Zano’s ring-signature system mixes transaction spends with other outputs, making it impossible to determine precisely which subsequent transactions involved the unauthorized funds.

By block 3,878,388, the investigation had identified 117,941 potentially connected outputs across 65,301 transactions. 

Around 165,700 outputs had also been created following the first minting transaction, representing approximately 71% of network activity during the period examined.

With no reliable way to separate legitimate funds from affected coins, Zano chose to restore the blockchain from block 3,833,000, the last block before HF 6. 

The resulting Hard Fork 7 disables Gateway Addresses until the code can undergo a fresh review and audit.

The recovery will also remove transactions, staking rewards, and mined blocks recorded during the affected period. 

Node operators, miners, stakers, and service providers must adopt the updated chain for the recovery to take effect across the network.

What happens to Zano users after the blockchain rollback?

Zano said its AI-assisted testing, internal audits, and bug bounty programs did not detect the vulnerability before it was exploited. 

The team said post-upgrade monitoring focused heavily on cryptographic components, while the flaw was located in the Gateway Address implementation.

The incident adds to a costly year for crypto security. CertiK recorded about $2.68 billion in gross losses through September 2026, including $766.5 million in September alone.

Zano said it would work to restore affected balances using its developer fund, contributions from team members, and pledged community support. 

Exchanges and payment providers have also been asked to review transactions from the affected period and coordinate separate recovery arrangements for deposits, withdrawals, and other payments.

The team urged users to update their wallets, retain transaction records, and wait for exchanges to confirm that deposits and withdrawals have resumed.

Gateway addresses remain disabled while Zano reviews the code and conducts further testing and audits before deciding whether to restore the feature.

Source:: Zano Exploiter Minted 1.8 Quadrillion fUSD Before Blockchain Rollback