Zano Rolls Back One Month After Gateway Exploit

Zano Rolls Back One Month After Gateway Exploit

Zano has restarted its blockchain from block 3,833,000 after a vulnerability in its Gateway Address feature allowed unauthorized ZANO and Freedom Dollar (fUSD) to enter circulation. The recovery point sits immediately before Hard Fork 6, which introduced Gateway Addresses, removing approximately one month of subsequent blockchain history. The rollback eliminates the unauthorized issuance but also removes legitimate transactions that had already been confirmed during the affected period.

In its official incident statement, the Zano team said wallet spend keys and ordinary transaction privacy were not compromised and that the core consensus mechanism remained unaffected. The security boundary instead sits within Gateway Addresses, an account-style feature designed to simplify integrations for exchanges, bridges and payment providers. Zano has not yet published the technical exploit mechanism or a confirmed exploitation timeline, making claims that the attack ran specifically from September 25 through September 28 premature.

Rollback Removes Both Unauthorized and Legitimate Activity

The recovery requires nodes, miners, stakers, pools, exchanges and other infrastructure providers to adopt emergency client version 2.2.3.600 and follow the restored chain. Transactions confirmed after the rollback point are no longer part of that canonical history, and users have been told to retain transaction IDs and trading records while counterparties reconcile their balances. A transaction disappearing from Zano’s recovered chain does not automatically reverse economic settlement that already occurred somewhere else. Payments completed in USDT, DAI or other assets on external networks remain beyond the rollback’s reach.

That accounting distinction is central to understanding the incident. Unauthorized token creation is not automatically equivalent to an equal amount of realized financial loss, as demonstrated by a separate Cosmos EVM exploit that inflated roughly $50 million in nominal NES value while producing far smaller executable proceeds. Zano has not yet disclosed the amount of unauthorized ZANO or fUSD created, sold or moved externally, so the final economic damage cannot be calculated from the available official information.

The decision also represents a materially different recovery strategy from incidents where networks preserve transaction history while correcting future issuance. Core DAO’s emergency hard-fork response to excess validator rewards explicitly avoided rolling back confirmed transactions, while Harmony later confronted the operational consequences of a large rollback after a supply exploit. Zano instead prioritized restoration of its intended asset supply over preserving roughly one month of accepted ledger history, requiring participants to reconcile legitimate activity removed alongside the exploit.

Claims Process and Technical Post-Mortem Remain Pending

Zano says it is working with affected projects and counterparties to calculate losses and intends to publish a reimbursement and claims process. The team also said community members have pledged resources toward restoring affected assets. The formal incident statement does not yet specify a complete funding formula for reimbursements or confirm the value that will ultimately need to be covered, so compensation should remain described as planned rather than completed.

The episode also illustrates why the exact security boundary matters. Another recent case involving unbacked L-BTC created through a Liquid Network software vulnerability did not constitute a failure of Bitcoin’s base-layer consensus. Likewise, Zano says its own core consensus and normal wallet privacy were unaffected even though Gateway Address asset issuance was compromised. The failure was tied to a newly introduced protocol feature, not to compromised user keys or a general break of Zano’s privacy system.

The next concrete milestones are the promised technical post-mortem, completion of the claims process and confirmation that exchanges and third-party services have migrated to the recovered chain. Until Zano publishes the exploit mechanics and reconciles transactions erased by the rollback, the full quantity of unauthorized issuance and resulting economic losses remains unresolved.

Follow Us

Ads

Main Title

Sub Title

It is a long established fact that a reader will be distracted by the readable

Ads
banner 900px x 170px