Zano Exploits Gateway Address for $67M in Unauthorized Tokens
Zano, a cryptocurrency project, has revealed the details of a recent exploit that led to the minting of millions of unauthorized tokens. The vulnerability was exploited through the Gateway Address feature, which allowed an attacker to create 36.9 million ZANO tokens and additional stablecoin-like assets called Freedom Dollars (fUSD).
The attack occurred in two stages: on August 29, the attacker minted approximately 18.4 million ZANO, followed by another 18.4 million on September 25. The unauthorized coins were not 'stuck' in an easily identifiable state but could be spent normally.
Zano's team chose to roll back about a month of blockchain history to remove the unauthorized supply, citing that it was the only way to cleanly eliminate coins that couldn't be reliably distinguished from legitimate outputs. However, this decision was met with concerns over user trust and potential disruptions to legitimate transactions included in the reverted history.
The team acknowledges that internal monitoring, audits, and bug bounties failed to detect the issue until after the second mint. Zano is currently working on recovery efforts using a mix of developer funds, team member contributions, and other committed resources, with primary routing through exchanges and payment services.