Zano Rolls Back Blockchain a Month After Gateway Address Exploit
Zano restarts network to stop token exploit
The Zano blockchain has been restarted at block 3,833,000. This move comes after a security flaw allowed unauthorized ZANO and Freedom Dollar tokens to enter the system. The restart undoes approximately one month of blockchain history.
The team stated that the rollback occurred immediately before "Hard Fork 6." This update introduced the "Gateway Address" feature, which caused the vulnerability. All participants, including miners, stakers, and exchanges, must adopt the new update to continue operating on the chain.
Key details of the recovery
- The blockchain was reset to the block height right before Hard Fork 6.
- The exploit involved Gateway Addresses, a feature meant to simplify how exchanges manage funds.
- Legitimate transactions from the past month will no longer appear on the restored chain.
- The team cannot reverse payments that were already settled on other blockchains.
- A reimbursement and claims process for losses is currently being prepared.
How the exploit worked
Before the introduction of Gateway Addresses, Zano wallets tracked funds as separate transaction outputs, known as UTXOs. Services had to scan the entire blockchain to find incoming payments. The new Gateway Address feature allowed these services to manage funds through a single account-style balance. A vulnerability in this new system allowed attackers to create unlimited amounts of ZANO and Freedom Dollar (fUSD).
Freedom Dollar is a custom digital asset that operates on the Zano blockchain. Zano itself is a layer-1 blockchain focused on private payments, where standard transactions hide sender, receiver, and amount details.
Team rationale for the rollback
Quinten van Welzen, Zano's head of marketing and growth, explained the decision. He stated that doing nothing would have led to unlimited unauthorized tokens circulating. This would have diluted the value for every holder and broken the promise of a fixed supply. Van Welzen noted that allowing exploited coins to keep their value would encourage future attacks.
He acknowledged that restarting the chain costs a month of history and damages trust. However, he argued it was necessary to restore the supply and save the project's long-term viability.
What remains uncertain
At the time of publication, the team has not released a detailed post-mortem report explaining exactly how the exploit happened. While the team is working on a plan to account for losses, the specific details of the reimbursement process have not yet been published.
Next steps for the network
The recovery relies on participation from the community. Nodes, miners, stakers, exchanges, and other services must update their software to the new version to join the restarted chain. The team indicated they are actively working to finalize the claims process for affected users.