Zano exploiter minted more than a quadrillion fUSD before blockchain rollback
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Zano suffered an exploit of its Gateway Address vulnerability, allowing an attacker to mint 36.9 million Zano (ZANO) tokens and approximately 1.8 quadrillion Freedom Dollar (fUSD) tokens. The unauthorized minting occurred between August 29 and September 25, prompting Zano to roll back about a month of blockchain history, including legitimate transactions. The attacker paid 100 ZANO to set up the exploit, which initially went unnoticed.
Why it matters
Zano’s team argued the rollback was necessary to remove unauthorized token supply that could not be differentiated from legitimate tokens, despite acknowledging the rollback would harm user trust. The incident revealed weaknesses in Zano’s security processes, including AI-assisted testing and audits that failed to detect the vulnerability.
Key context
The exploit involved registering a Gateway Address and minting unauthorized tokens that functioned as genuine coins. The rollback reversed legitimate transactions along with fraudulent ones to restore network integrity. Recovery efforts include using developer and team funds, with exchanges replaying reversed withdrawals and crediting affected deposits.
Key numbers and entities
The attacker minted 36.9 million ZANO and 1.8 quadrillion fUSD tokens. The exploit setup cost the attacker 100 ZANO, valued at about $553 at the time. Quinten van Welzen, Zano’s head of marketing and growth, provided commentary on the incident.
What remains unclear
The source does not specify how much of the unauthorized tokens entered the market or how the attacker intended to use the fake tokens beyond minting. Details on the long-term effects on user confidence or platform governance after the rollback are also not established.