Zano has disclosed details of the exploit that forced a 30-day blockchain rewind in late September. An attacker exploited a missing verification in Gateway Addresses—a new address type introduced in Hard Fork 6—to mint roughly 18.4 million ZANO tokens in a single transaction, then repeated the exploit with the fUSD stablecoin, creating over $200 million worth of illicit tokens.
The flaw allowed attackers to construct a specially calculated asset identifier that satisfied the network's transaction proofs while hiding arbitrary amounts in outputs. These counterfeit coins functioned as authentic ZANO and could be spent normally.
Timeline of the Exploit
The attacker registered a Gateway Address on August 28 and apparently tested the vulnerability the following day. On August 29, the first transaction minted approximately 18.4 million ZANO, currently valued around $102 million. The exploit remained undetected for nearly a month until September 25, when the team's internal tools detected the anomaly.
On that day, the attacker created another 18.4 million ZANO using the same method, then repeated the process with fUSD. During the affected period, the illicit tokens became intertwined with legitimate coins through Zano's privacy system, making them difficult to trace and isolate.
Why Detection Failed
Zano had conducted artificial intelligence-assisted testing, team audits, and bug bounty programs before Hard Fork 6, yet the vulnerability went undetected. According to the team, the initial exploit went unnoticed because the extra output appeared identical to any other private output in Zano's confidential transaction system.
Once the counterfeit coins entered the network, Zano's privacy features—ring signatures that mix spends with other outputs—made it impossible to determine exactly where the illicit tokens traveled. Scanning every potentially affected output revealed that the trail touched 117,941 outputs created through 65,301 transactions, with roughly 165,700 outputs subsequently created from the first mint, representing approximately 71% of network activity during that period.
Recovery and Resolution
Unable to surgically separate legitimate coins from unauthorized ones due to privacy protections, Zano initiated Hard Fork 7, which restarted the chain from block 3,833,000—prior to Hard Fork 6 and the initial exploit. All transactions, staking rewards, and mined blocks from the affected period no longer exist on the updated ledger. Gateway Addresses have been disabled.
Zano stated that affected balances will be recovered in full without changing ZANO's total supply or emission schedule. Funding for recovery will come from the development fund, team members' personal contributions, and outside contributors. Exchanges must now review a month of activity transaction by transaction before resuming access to the network.


