Privacy coin project Zano published a post-mortem on October 2, 2026 describing an exploit that let an attacker mint 36.9 million unauthorized ZANO over roughly a month. Because the counterfeit coins behaved exactly like legitimate ones, the team chose a blunt remedy: it rolled back about a month of blockchain history, erasing legitimate transactions alongside the fake supply. The details come from Zano's own disclosure, reported by Cointelegraph.
A flaw in the Gateway Address that ran for a month
The attack centered on Zano's Gateway Address feature. According to the post-mortem, the attacker registered a Gateway Address and paid a registration fee on August 28, then executed the first mint on August 29, producing 18.4 million ZANO. That batch went undetected for nearly a month. A second mint of another 18.4 million ZANO followed on September 25, bringing the total to 36.9 million unauthorized coins. The attacker also minted Freedom Dollar (fUSD) tokens through the same flaw.
The entry cost was trivial. Zano says the attacker paid 100 ZANO, about 553 dollars at the time, to register the Gateway Address that opened the door. For that outlay, the exploit generated tens of millions of tokens before anyone noticed.
Counterfeit coins that could not be isolated
The reason this incident forced such a heavy-handed fix sits in one line from the disclosure: the unauthorized coins "functioned as authentic ZANO and could be spent normally." They were cryptographically indistinguishable from legitimate ZANO. There was no tainted-address list to freeze, no marker to filter, no way to quarantine the fake supply while leaving honest balances intact.
That is the nightmare scenario for a privacy chain specifically. The same properties that make coins fungible and untraceable also mean a forged coin and a real coin are the same object to the network. Once the fakes mixed into circulation, the only way to remove them was to remove the stretch of history that contained them.
So Zano rolled back roughly one month of the chain. Legitimate transactions made during that window were reversed too, collateral damage of purging a supply the network could not otherwise separate.
Detection came late, and the usual safeguards missed it
Internal teams flagged the activity only after the second mint on September 25, nearly four weeks after the first one. Zano notes that AI-assisted testing, internal audits, and bug bounty programs had all failed to surface the Gateway Address vulnerability beforehand. The flaw sat in production, exploitable, through every layer of review the project had in place.
That gap is worth sitting with. A month of undetected inflation on a live chain is not a monitoring footnote; it is the difference between catching an exploit at 18.4 million fake coins and catching it at 36.9 million. Faster anomaly detection on total supply would have halved the damage here.
The restoration plan leans on the team's own money
Zano says it is "working to restore affected balances using its developer fund, team members' personal funds and committed contributions." The mechanics run largely through exchanges, which are expected to replay the reversed withdrawals so that users who moved coins during the rolled-back window are made whole.
That approach puts the cost of the fix on the project and its backers rather than on ordinary holders, which is the right call. It also underlines how expensive a rollback is in practice: reversing a month of history is not a clean undo, it is a manual reconciliation across every exchange and user that transacted in that window.
A reminder of where custody risk actually lives
For anyone who spends crypto, the Zano episode is a reminder that the asset layer itself can fail, not just the apps on top of it. A card or wallet is only as sound as the chain and tokens behind it. When a network can mint counterfeit units that spend like the real thing, no amount of front-end security helps.
It is one reason many users anchor day-to-day spending in assets with deep liquidity and transparent, auditable supply, and why stablecoin-denominated cards and self-custody setups appeal to people who want to limit their exposure to any single chain's failure mode. Supply integrity is a custody question as much as key management is. This incident is a clean example of the first kind failing while the second was never even in play.
Rollbacks remain the rarest and most disruptive tool a blockchain has. Zano reaching for one, and accepting reversed legitimate transactions as the price, shows how little room it had once counterfeit coins became indistinguishable from real ones.
Overview
Zano disclosed on October 2, 2026 that an attacker exploited a Gateway Address flaw to mint 36.9 million unauthorized ZANO in two batches, on August 29 and September 25, for an entry cost of 100 ZANO (about 553 dollars). Because the fake coins were indistinguishable from legitimate ZANO and spent normally, the team rolled back roughly a month of blockchain history, reversing honest transactions in the process. Detection came only after the second mint, despite prior AI-assisted testing, audits, and bug bounties. Zano plans to restore balances using its developer fund, team funds, and contributions, mostly via exchanges replaying reversed withdrawals.



