Zano exploiter minted more than a quadrillion fUSD before blockchain rollback
Zano said an attacker used a vulnerability in its Gateway Address system to mint roughly 36.9 million ZANO and about 1.8 quadrillion fUSD before the project rolled the blockchain back by about a month. The team said the unauthorized tokens were indistinguishable from legitimate coins, forcing the rollback to remove the extra supply.

Why It Matters
The exploit created fungible tokens that could be spent like genuine ZANO, undermining the integrity of circulating supply and prompting the team to erase a month of chain history — a step that affects legitimate users and could damage trust in the project. Restoring balances and reversing withdrawals will involve exchanges and the developer fund, highlighting operational and custodial challenges after on-chain compromises.
Key Facts
- Unauthorized ZANO minted: 36.9 million ZANO (two mint events of ~18.4 million each)
- Unauthorized fUSD minted: Approximately 1.8 quadrillion Freedom Dollar (fUSD) tokens
- First exploit date: Aug. 29 (attacker minted ≈18.4 million ZANO)
- Second exploit date: Sept. 25 (attacker minted ≈18.4 million ZANO and ≈1.8 quadrillion fUSD)
- Gateway Address registration fee: 100 ZANO (paid by attacker to set up the exploit)
Zano disclosed in a post-mortem that an attacker exploited a Gateway Address vulnerability to mint roughly 36.9 million ZANO and around 1.8 quadrillion fUSD before the team rolled the blockchain back by about one month. According to the timeline, the attacker registered a Gateway Address on Aug. 28, paid the 100 ZANO registration fee, tested a fabricated asset, then performed the first unauthorized mint on Aug. 29. A second mint occurred on Sept. 25, producing additional ZANO and the vast amount of fUSD.
The project said the unauthorized tokens behaved like regular outputs on the chain and could be spent normally, making them indistinguishable from legitimate coins. Zano spokesperson Quinten van Welzen told Cointelegraph that only a small portion of the illicit supply reached markets, constrained by the liquidity available on exchanges. The first mint remained unnoticed for nearly a month and was flagged only after the second mint triggered internal alerts.
Because the forged coins could not be separated from valid supply on-chain, the Zano team decided to perform a rollback of roughly a month of blockchain history to remove the unauthorized issuance. The team acknowledged the rollback would damage trust but argued it was necessary to eliminate the indistinguishable extra supply. Zano also said AI-assisted tests, internal audits and bug bounties had not detected the vulnerability prior to the exploit.
To restore affected balances, Zano plans to use funds from its developer fund, contributions from team members, and other committed contributions. Recovery will principally be handled through exchanges and payment services: exchanges will replay withdrawals reversed by the rollback and the project will credit affected deposits. The post-mortem outlines these remediation steps as the project works to make impacted users whole.
Keep Reading

Ethereum’s zkAPI brings privacy-preserving API payments to mainnet

Core Lightning warns attackers are targeting unpatched nodes

South Korea advances tokenized securities rules ahead of 2027 rollout
