Zano Attacker Exploits Gateway Address Vulnerability, Rolls Back Blockchain
A vulnerability in Zano's Gateway Address system allowed an attacker to mint a massive amount of unauthorized ZANO and fUSD tokens. The attack began on August 29, when the attacker created approximately 18.4 million ZANO, followed by another 18.4 million on September 25 and a staggering 1.8 quadrillion fUSD.
The forged outputs were indistinguishable from legitimate coins, making selective removal impossible once they entered the ledger. This forced the developers to roll back the blockchain to erase roughly one month of history, including legitimate transactions.
Only a small fraction of the minted tokens reached the market due to exchange liquidity limitations. The team is working to restore affected balances using developer funds and team contributions, while exchanges are expected to replay reversed withdrawals.