An attacker who exploited a flaw in Zano’s Gateway Address feature minted roughly 36.9 million unauthorized ZANO before the project reversed about a month of blockchain history, according to a post-mortem released by the team.
The disclosure, published Thursday, describes two large minting events.
On August 29, 2026 the attacker created about 18.4 million ZANO in a single transaction.
The same method was used again on September 25 to produce another 18.4 million ZANO.
The attacker also generated an enormous volume of Freedom Dollar (fUSD), on the order of 1.8 quadrillion tokens, through the same vulnerability.
A portion of the unauthorized assets entered the wider Zano ecosystem.Gateway Addresses were introduced with Hard Fork 6 to make integration easier for exchanges, bridges, and payment services.
The feature lets those operators track funds through an account-style balance rather than reconstructing activity from individual outputs.
The bug allowed new supply to be created without authorization.
The team said the resulting coins behaved like ordinary ZANO: they appeared as normal outputs and could be spent in the usual way.
Because the unauthorized units could not be reliably separated from legitimate ones, selective removal was not practical.
The sequence began the day before the first mint.
On August 28 the attacker registered a Gateway Address and paid the required 100 ZANO registration fee, worth about $553 at the time of the report.
The address was then used to test a fabricated asset before the larger mint the following day.
The initial 18.4 million ZANO creation went unnoticed for nearly a month. Internal review flagged the activity only after the second mint.
Zano said AI-assisted testing, internal audits, and its bug-bounty program had not caught the defect before it was exploited.
That timeline shaped the recovery decision.
The chain was restarted from block 3,833,000, the last block before Hard Fork 6, which effectively erased roughly a month of history and disabled Gateway Addresses pending further review.
Legitimate transactions recorded in that window were invalidated along with the unauthorized supply.
— Zano (@zano_project) October 1, 2026
Payments already settled on other networks could not be reversed by the rollback.
Project representatives have acknowledged that reversing chain history damages confidence, while arguing that leaving the extra supply in circulation would have diluted holders and undermined the fixed-supply premise of the asset.
Quinten van Welzen, Zano’s head of marketing and growth, told news media outlets that only a small fraction of the minted coins reached the open market, constrained by available exchange liquidity.
The team has said it is working to restore balances affected by the rollback, drawing on the developer fund, personal contributions from team members, and other committed funds.
Recovery is expected to run mainly through exchanges and payment services: exchanges would replay withdrawals that the rollback reversed, and the project would credit affected deposits.
Wallet spend keys and ordinary transaction privacy were not compromised, according to the investigation, and core consensus rules were unaffected.
The episode underscores how an integration feature intended to lower barriers for services can become a supply-integrity risk when validation fails, and how privacy-oriented designs can complicate cleanup once unauthorized units are indistinguishable from genuine ones.