Zano's post-mortem disclosure reveals the attacker who exploited the Gateway Address flaw minted 36.9 million ZANO plus Freedom Dollar tokens before the project rolled back a month of chain history. The unauthorised supply blended into circulation without technical markers to separate it from legitimate issuance.
The first mint occurred on Aug. 29, creating roughly 18.4 million ZANO in one transaction. A second mint on Sept. 25 produced another 18.4 million ZANO, followed by fUSD generation using the same method. A portion of the fabricated tokens entered active use within the ecosystem, functioning identically to genuine coins and circulating without restriction.
Because the counterfeit output mirrored ordinary transaction structure, Zano concluded a rollback was unavoidable. The team acknowledged the measure would damage confidence but argued no alternative existed to excise supply that carried no distinguishing on-chain characteristics.
Registration fee of 100 ZANO opened attack path
Setting up the exploit required a 100 ZANO payment — approximately 553 dollars at current prices. On Aug. 28 the attacker registered a Gateway Address, settled the fee, then tested a fabricated asset. The following day the first unauthorised mint executed.
Internal monitoring missed the initial 18.4 million ZANO creation for nearly four weeks. The counterfeit outputs resembled standard entries, and teams flagged the anomaly only after the second mint triggered review.
Zano stated that AI-supported testing, internal audit processes and bug-bounty programmes all failed to surface the vulnerability before exploitation.
On Wednesday the project outlined a recovery plan drawing on its developer fund, personal contributions from team members and pledged support. Restoration will route primarily through exchanges and payment processors. Exchanges will replay withdrawals that the rollback reversed, while the team will credit affected deposit balances directly.
Hot Stories
- Fraud Schemes Third-Party Adapter Breach Drains $305K from Safe Wallets
- Investigations OFAC sanctions 10 for $40M ATM jackpotting using crypto
- Fraud Schemes Fake GIWA bridge steals $2M in Ether from DYORSWAP users
- Articles How Open-Weight AI Helps Hackers Find Code Vulnerabilities
- Investigations iOS app FomoPeek stole $579K in USDT via kernel exploits
- News Bitget confirms $351.6 million hack
- Investigations How AI Is Changing Attacks on Crypto Services
- News Bitget: reports of a possible $170M hack
- Investigations White-hat hackers exploit Liquid Network flaw to steal $320M BTC
- Investigations Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit
