
Zano Rolls Back Blockchain After Exploit Creates Quadrillions of Tokens
Vexoda Newsroom
An attacker exploited a vulnerability in Zano's Gateway Address to mint over 36.9 million unauthorized ZANO and fUSD tokens. The Zano team responded with a one-month blockchain rollback to rectify the
In a significant security event, the Zano blockchain experienced a major exploit that led to the creation of a vast quantity of unauthorized digital assets. An attacker leveraged a critical vulnerability within Zano's Gateway Address functionality to mint an enormous supply of both native ZANO tokens and fUSD stablecoins. This unprecedented minting activity was only discovered after the attacker had already generated a substantial amount of these digital currencies, prompting a drastic response from the Zano development team to protect the ecosystem.
The exploit occurred over several weeks, beginning on August 29th. The attacker initially minted approximately 18.4 million ZANO coins in a single transaction, utilizing the Gateway Address vulnerability. This unauthorized minting was repeated on September 25th, adding another 18.4 million ZANO to the circulating supply. Following these actions, the attacker then employed the same exploit method to create a significant, though unspecified, quantity of fUSD tokens, with a portion of these tokens eventually entering the Zano ecosystem, indistinguishable from legitimate assets.
To understand the gravity of the situation, it's crucial to note that the exploited Gateway Address feature allowed for the creation of new tokens. The attacker paid a nominal fee of 100 ZANO, approximately $553 at the time, to register the address and initiate the exploit. The fabricated assets produced by the attacker were functionally identical to genuine ZANO and fUSD tokens, meaning they could be transacted and integrated into the ecosystem without immediate detection. This technical characteristic presented a major challenge for the Zano team.
The Zano development team made the difficult decision to implement a one-month blockchain rollback to counteract the exploit. This drastic measure, while intended to purge the system of the unauthorized tokens, acknowledged that it would inevitably impact user trust and disrupt legitimate transactions that occurred within that timeframe. The rollback was deemed necessary because the minted coins were indistinguishable from authentic ones, making manual removal or simple exclusion infeasible without reverting the blockchain's state.
The market implications of such a substantial unauthorized token mint and subsequent rollback are considerable. While Zano's native token price may see short-term volatility due to the uncertainty and the rollback's impact on user confidence, the swift action to address the exploit demonstrates a commitment to network integrity. However, the incident highlights the ongoing challenges in securing decentralized systems against sophisticated exploits, particularly those that can generate undetectable, counterfeit assets.
Looking ahead, Zano traders and users will be closely monitoring the recovery process. The Zano team has stated its intention to restore affected balances using a combination of developer funds, personal contributions from team members, and other resources. The primary channel for this restoration will be through exchanges, which will need to reverse withdrawals and credit affected deposits. Transparency regarding the progress of these recovery efforts will be paramount for rebuilding trust within the Zano community and the broader market.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.