Zano Says Over $200M in Illicit Tokens Led to 30-Day Blockchain Rewind – Bitcoin News
Key Takeaways
Zano disclosed that one exploit transaction created roughly 18.4 million ZANO, with further tokens created thereafter.Zano traced possible tainted activity across 117,941 outputs and 65,301 transactions.The Zano team explained that affected balances will be restored without changing ZANO supply.
One Missing Check, 18.4 Million ZANO
Zano’s 30-day blockchain rewind already sounded drastic. Now the team has explained what was lurking underneath it, and the mechanics are arguably stranger. A flaw introduced with Hard Fork 6 allowed an attacker to create coins that the network accepted as genuine, beginning Aug. 29.
According to the dev team, the first real exploit minted 2^64 base units, roughly 18.4 million ZANO, in a single transaction. Nobody caught it for nearly a month. By the time Zano’s internal tools sounded the alarm on Sept. 25, the counterfeit supply had become tangled inside a privacy system deliberately built to make transactions difficult to trace.
The trouble started with Gateway Addresses, a new address type introduced in Hard Fork 6 to make Zano easier to integrate with centralized exchange (CEX) platforms, bridges, and other services. Gateway outputs expose an amount and asset ID, unlike Zano’s standard confidential outputs, where both are hidden.
The implementation, however, was missing a critical verification. Zano disclosed that an attacker could construct a specially calculated asset identifier that still satisfied the network’s transaction proofs while slipping an arbitrary amount into a hidden output.
“In short, every Zano transaction must prove that coins were created from consensus rules,” the team explained. “Because of a missing verification, an attacker could satisfy this proof while ‘hiding’ extra coins within the transaction.”
Those coins weren’t decorative accounting entries. The team said:
“These coins functioned as authentic ZANO and could be spent normally.”
The First Mint Sat Quietly for Nearly a Month
The attacker registered a Gateway Address on Aug. 28, paying the required 100 ZANO fee, and apparently tested whether Zano would accept a constructed nonexistent asset. The next day, the gloves came off.
One transaction minted roughly 18.4 million ZANO, currently valued around $102 million worth. Nearly a month later, on Sept. 24, the attacker made two legitimate deposits of just 0.05 ZANO each, apparently testing the ordinary deposit route. On Sept. 25, another 18.4 million ZANO was created, followed by the same 2^64-base-unit maneuver using the fUSD stablecoin. All told, that’s more than $200 million worth of illicit crypto tokens.
Here’s the kicker. Zano had conducted artificial intelligence (AI)-assisted testing, team audits, and bug bounty programs before Hard Fork 6. None caught it the vulnerability.
“The initial exploit went undetected for nearly one month because the increased output appeared like any other private output,” the team said.
Privacy Did Its Job, and That Became the Problem
Once the phony coins entered Zano’s confidential transaction system, identifying exactly where they went became a different proposition. Ring signatures mix spends with other outputs, causing uncertainty to spread every time coins move.
Zano scanned every output potentially connected to the three minting transactions. By block 3,878,388, the trail touched 117,941 outputs created through 65,301 transactions. Roughly 165,700 outputs had subsequently been created from the first mint, representing about 71% of network activity during the period.
“That is privacy working as intended,” Zano said. “No one, including the Zano team, can accurately determine which outputs are affected.”
That left the project in a jam. The very privacy properties users expected from Zano prevented developers from surgically separating legitimate coins from unauthorized ones. “The only way to verify supply integrity is to continue the chain from a point prior to the first exploit,” the team detailed.
A Month Gets the Ax, and Recovery Begins
That point was block 3,833,000, before Hard Fork 6. Hard Fork 7 restarted the chain from there and disabled Gateway Addresses, meaning transactions, staking rewards, and mined blocks from the affected period no longer exist on the updated ledger.
Zano further said affected balances will be recovered in full without changing ZANO’s supply or emission schedule. Funding will come from the development fund, team members’ personal money, and outside contributors. Exchanges must now comb through a month of activity, transaction by transaction, before reopening access.
“No action is needed right now,” the team told users on its social media channels.
