
Zano has rolled its blockchain back to a point before the launch of its Gateway Address system after an attacker exploited a transaction-validation flaw to create about 36.9 million unauthorized ZANO and roughly 1.8 quadrillion fUSD.
The emergency recovery moved the network back to block 3,833,000, the point immediately before Zano’s Hard Fork 6 introduced Gateway Addresses on August 26, 2026. Zano then activated Hard Fork 7, which disables the Gateway Address transaction components associated with the exploit. The changes were distributed through emergency release v2.2.3.600 on GitHub.
The incident was initially described as an inflation bug affecting Gateway Addresses, but the scale became clearer as Zano investigated the affected transaction history. The project said the unauthorized ZANO behaved as genuine coins and could be spent normally, making it difficult to isolate and remove the attacker’s funds without affecting other transactions.
How the attacker created the unauthorized coins
Gateway Addresses were introduced in Hard Fork 6 to provide an account-style mechanism intended to simplify integrations for exchanges, bridges, decentralized exchanges and payment services. Unlike Zano’s conventional confidential transaction model, Gateway Address activity exposes the amount and asset involved around the gateway account.
The vulnerability involved a missing validation check in the Gateway Address transaction logic. According to Zano’s post-incident account, the attacker was able to construct a specially manipulated asset identifier that could pass the relevant transaction proofs while allowing additional value to be concealed inside a confidential output.
The first unauthorized creation occurred on August 29, three days after Hard Fork 6 went live. Approximately 18.4 million ZANO was created in that transaction. A second mint of roughly the same size took place on September 25, bringing the total unauthorized ZANO creation to about 36.9 million.
The same vulnerability was also used to create approximately 1.8 quadrillion fUSD, a confidential asset on the Zano network.
Zano’s documentation describes Gateway Addresses as a feature designed to make deposits, withdrawals and other integrations easier for services that need account-style balances. Registration required a 100 ZANO fee that was permanently burned. The exploited feature has now been disabled on the recovered chain.
Why Zano chose a month-long rollback
The first unauthorized mint was not detected immediately. Zano says the counterfeit ZANO moved through normal network activity and became difficult to distinguish from legitimate funds because of the blockchain’s privacy mechanisms.
Investigators identified 117,941 potentially connected outputs across 65,301 transactions by block 3,878,388. Zano also reported that roughly 165,700 outputs were subsequently created from the first unauthorized mint.
That made a targeted blocklist or simple wallet freeze impractical. Because Zano’s privacy system obscures transaction relationships, the project said it could not reliably determine every affected output and separate unauthorized funds from legitimate coins that had passed through the same transaction history.
Instead of trying to identify every contaminated output, the network was restored to the chain state immediately before Gateway Addresses were activated. The rollback removed the affected period rather than selectively deleting individual transactions.
As a result, legitimate activity during the rollback window was also removed from the recovered chain. Zano has warned that transactions confirmed after block 3,833,000 on the pre-rollback chain are not part of the new canonical history.
Wallet keys were not compromised
Zano has distinguished the incident from a conventional wallet breach. The project said user spend keys were not compromised and that the exploit did not break the privacy of ordinary Zano transactions.
The problem was instead tied to how the network validated asset issuance through the newly introduced Gateway Address functionality. That allowed the attacker to create new value without obtaining users’ private keys.
The episode also exposed a gap in the security checks performed before Hard Fork 6. Zano said the Gateway system had undergone internal audits, AI-assisted testing and bug bounty work before the upgrade, but the vulnerability was not identified through those processes.
Exchanges and users face reconciliation work
The rollback has also affected exchanges and services that processed ZANO or fUSD transactions during the discarded period. MEXC, for example, suspended ZANO and fUSD deposits and withdrawals after the incident.
Zano’s recovery plan says exchange withdrawals made during the affected period can be replayed on the recovered chain, while deposits will be reconciled with exchanges so affected users can have their balances restored. The project has also said it intends to address qualifying losses using its development fund, contributions from team members and committed contributors rather than changing ZANO’s normal emission schedule.
The project has cautioned users about separate recovery scams and said it will not initiate direct messages asking for wallet seed phrases. Zano has also warned about a fake wallet website, zanowallet[.]io, which it says was distributing malware.
The emergency recovery was implemented through Zano’s v2.2.3.600 release on GitHub, with the network adopting Hard Fork 7 at the restored height. The new rules disable the Gateway Address functionality that enabled the exploit.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.



