TLDR
- An attacker exploited a Gateway Address bug in Zano to mint 36.9 million unauthorized ZANO and 1.8 quadrillion fUSD tokens.
- The exploit ran from August 29 to September 25 before Zano caught it.
- Zano chose to roll back about a month of blockchain history to remove the fake coins.
- The rollback also erased legitimate transactions made during that period.
- Zano plans to restore affected balances using its developer fund and team contributions.
Zano has confirmed that an attacker used a flaw in its Gateway Address system to create a large amount of unauthorized tokens. The team shared the details in a post-mortem report published Thursday.
JUST IN: Zano exploiter minted 36.9M unauthorized ZANO before a planned rollback to remove them, exposing potential risk of chain re-orgs and user exposure. $ZANO pic.twitter.com/BMQbnTDKSH
— Bpay News (@bpaynews) October 2, 2026
The attacker first found the bug on August 28. They registered a Gateway Address, paid a small fee, and tested a fake asset.
The next day, on August 29, the attacker created about 18.4 million ZANO in one transaction. This went unnoticed by the team for almost a month.
On September 25, the attacker repeated the exploit. They minted another 18.4 million ZANO using the same method.
The attacker then used the bug again to create about 1.8 quadrillion fUSD, a stablecoin used on the Zano network.
How the Exploit Worked
Zano said the fake coins looked exactly like real ZANO. There was no way to tell them apart once they entered circulation.
— Zano (@zano_project) October 1, 2026
“These coins functioned as authentic ZANO and could be spent normally,” the team wrote in its report.
Zano spokesperson Quinten van Welzen told Cointelegraph that only a small part of the unauthorized coins reached the open market. He said this was due to limited liquidity on exchanges.
The total cost for the attacker to set up the exploit was just 100 ZANO. At the time of publication, that was worth about $553.
Internal teams only noticed the problem after the second mint took place in September. The first mint in August had gone undetected.
Zano said its usual safety checks did not catch the bug before the attack happened. This included AI-assisted testing, internal audits, and bug bounty programs.
Why Zano Chose a Rollback
Because the fake coins were indistinguishable from real ones, Zano could not simply remove them from the network. The team said rolling back the blockchain was the only option left.
The rollback covers about one month of blockchain history. This means some real, legitimate transactions during that time were also erased.
Zano admitted this decision would hurt user trust. The team said it was a necessary step to protect the integrity of the network going forward.
Following the decision, Zano is now working on a recovery plan. The plan will use the project’s developer fund, along with personal contributions from team members.
Exchanges and payment services will play a main role in the recovery process. They will replay any withdrawals that were reversed by the rollback.
Deposits affected by the rollback will also be credited back to users by the exchanges involved. Zano has not given a fixed timeline for when this process will be complete.
The case shows how a single technical flaw can lead to a full blockchain reorganization. It also highlights the limits of current testing methods for finding token-minting bugs before they are exploited.







