
Zano Blockchain Rollback After Exploiter Minted Millions in Unauthorized Tokens
Vexoda Newsroom
An exploiter created 36.9 million ZANO and fUSD tokens by leveraging a Gateway Address vulnerability before the Zano team initiated a one-month blockchain rollback to rectify the situation.
The Zano blockchain experienced a significant security incident where an attacker exploited a vulnerability within its Gateway Address system. Over the course of several weeks, this exploit was used to mint a substantial amount of unauthorized ZANO (ZANO) and Freedom Dollar (fUSD) tokens. The core of the problem lay in the fact that these newly created coins were indistinguishable from legitimate ZANO, posing a complex challenge for the Zano development team to address without drastic measures.
The attacker's actions involved two primary minting events of ZANO, each producing approximately 18.4 million tokens, totaling nearly 36.9 million. The first significant mint occurred on August 29th, followed by a second on September 25th. Following these ZANO mints, the same exploit method was employed to create fUSD tokens. To initiate the exploit, the attacker reportedly paid a registration fee of 100 ZANO, a relatively small sum considering the scale of the unauthorized token creation.
This incident highlights a critical vulnerability in the way Zano handled Gateway Address registrations and asset creation. The vulnerability went undetected by various security measures, including AI-assisted testing, internal audits, and bug bounty programs, underscoring the sophisticated nature of the exploit. The attacker first tested the exploit with a fabricated asset before proceeding with the unauthorized minting of ZANO, with the initial large-scale minting going unnoticed for almost a month.
In response to the unprecedented creation of unauthorized currency, the Zano team made the difficult decision to execute a blockchain rollback. This involved reverting the blockchain's state by approximately one month, effectively undoing all transactions and mints that occurred during that period. While acknowledging that this action would inevitably impact user trust and disrupt legitimate transactions, the team deemed it a necessary step to preserve the integrity of the ZANO ecosystem and remove the indistinguishable counterfeit tokens.
The implications of this exploit and subsequent rollback are significant for Zano and its community. The rollback, while solving the immediate problem of unauthorized tokens, introduces complexities for users and exchanges who experienced legitimate transactions within the rolled-back period. The Zano team has committed to restoring affected balances, utilizing a combination of their developer fund, personal contributions from team members, and expected contributions to mitigate the impact on users.
Moving forward, traders and observers will be closely watching the Zano ecosystem's recovery and the implementation of enhanced security protocols. The team's approach to compensating users and rebuilding trust will be a key factor in the project's future stability. Furthermore, the incident serves as a stark reminder of the ongoing security challenges within the cryptocurrency space, emphasizing the need for continuous vigilance and robust auditing processes for all blockchain projects.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.