Zano rolls back blockchain after major token exploit
Zano rolled back its blockchain by 30 days after a vulnerability allowed an attacker to mint 36.9 million ZANO and 1.8 quadrillion fUSD. Both fake and legitimate transactions were erased. User balances will be restored.
Zano's blockchain experienced a major rollback following the discovery of a critical vulnerability in its Gateway Address system. This flaw enabled an attacker to mint 36.9 million unauthorized ZANO tokens and 1.8 quadrillion fUSD stablecoins. The exploit began on August 29, with 18.4 million ZANO created in a single transaction, and was repeated on September 25, using the same method to generate both ZANO and fUSD tokens. The fraudulent coins were indistinguishable from legitimate ones, circulating within the network and making detection challenging. The breach remained unnoticed for nearly a month before the Zano team identified the issue. In response, they decided to roll back approximately 30 days of blockchain history, which also erased legitimate transactions from that period. To address user losses, the team has pledged to restore affected balances using the development fund and team contributions, while maintaining the overall supply and emission schedule. The incident has sparked renewed debate about blockchain immutability and highlighted the risks associated with chain reorganizations and user exposure during such events.