Overview of Zano’s Security Breach
In a recent analysis of their security breach, Zano has revealed the technical vulnerabilities that triggered an unprecedented 30-day blockchain rewind. The issue arose when an attacker exploited a flaw related to Gateway Addresses, allowing for the illegal minting of approximately 18.4 million ZANO coins in a single transaction, followed by a similar exploit involving fUSD. This initial breach went unnoticed for almost a month, during which the illegitimate coins became increasingly blended within Zano’s privacy-centric infrastructure, complicating their detection.
Details of the Exploit
On August 29, following the rollout of Hard Fork 6, the attacker was able to create coins indistinguishable from legitimate ones due to a lack of crucial verification. The Zano development team later explained,
“The operation was facilitated by a bug that allowed the perpetrator to construct a special asset identifier that could bypass standard transaction proofs.”
To put it succinctly, the exploits allowed the hacker to inflate the coin supply without triggering standard network defenses. The attacker set up a Gateway Address on August 28, paying the requisite fee of 100 ZANO, and began testing if Zano would recognize the counterfeit coin creation. The very next day, they successfully minted about 18.4 million ZANO, worth nearly $102 million at the time. Besides, by September 24, the attacker had deposited two minimal amounts to further probe the system before another colossal minting of the same amount occurred a day later, along with a duplicate operation involving fUSD.
Impact of the Breach
In total, the malicious activities resulted in the creation of more than $200 million in fake tokens. Despite prior rigorous measures undertaken by Zano—including AI-driven testing, team audits, and a bug bounty program—this critical vulnerability remained undetected until the internal alarm was triggered on September 25.
Once the counterfeit coins were introduced into Zano’s privacy-oriented ecosystem, tracking their flow proved extremely challenging. The inherent privacy features, designed to safeguard user transactions, obstructed the ability of Zano developers to delineate which assets were compromised. The Zano team noted,
“The way our privacy system is designed makes it impossible to ascertain the affected outputs directly.”
Response and Recovery
To remedy the situation, Zano determined that the only viable solution was to revert the blockchain to a state prior to the lapse in security. They decided to resume operations from block 3,833,000, effectively nullifying any transactions conducted with Gateway Addresses under Hard Fork 6 and securing the network against future vulnerabilities. This reset was formalized with the upgrade to Hard Fork 7.
Zano assured users that while the three minting transactions had serious implications, their balances would be restored in full. They clarified that there would be no disruptions to ZANO’s overall supply or emissions, with recovery efforts funded through contributions from team members, external supporters, and the development fund. As access to Zano exchanges remains restricted, users have been advised that no immediate action is necessary on their part as exchanges conduct thorough reviews of the impacted transactions. On a positive note, the Zano team confirmed that a hotfix has been implemented, reiterating that the network remains stable.