Attacker Minted 36.9M Illicit ZANO Tokens Prior to Month-Long Blockchain Reversal

Attacker Minted 36.9M Illicit ZANO Tokens Prior to Month-Long Blockchain Reversal

The Zano project reports that a malicious actor exploited a Gateway Address security flaw to generate 36.9 million illegitimate ZANO tokens, prompting the team to reverse one month of blockchain transactions.

The Zano project has disclosed that a malicious actor who took advantage of a security weakness in its Gateway Address feature throughout the past month leveraged the vulnerability to generate 36.9 million Zano (ZANO) tokens, in addition to Freedom Dollar (fUSD) tokens, prior to the team's determination to reverse blockchain activity spanning one month.

According to a post-mortem analysis released on Thursday, Zano stated that the malicious actor initially took advantage of the security weakness on Aug. 29, generating roughly 18.4 million ZANO through a single transaction. The same attacker executed the exploit once more on Sept. 25, producing an additional 18.4 million ZANO, and subsequently employed an identical technique to generate fUSD. According to the team's report, some of the fraudulent tokens made their way into the Zano ecosystem.

"These coins functioned as authentic ZANO and could be spent normally," the team wrote in its post-mortem. Cointelegraph reached out to Zano for comment.

These numbers help explain the rationale behind the Zano team's decision to implement a rollback covering roughly one month of blockchain transaction history, which included legitimate user transactions. The development team recognized that implementing the rollback would damage community confidence but maintained it was essential to eliminate the unauthorized token supply since it was impossible to differentiate it from legitimately minted coins.

Attacker paid 100 ZANO exploit entry fee

According to Zano's post-mortem report, the malicious actor spent 100 ZANO to establish the groundwork for the exploit, which had a value of approximately $553 based on current market prices at the time of publication.

The malicious actor established a Gateway Address registration on Aug. 28, submitted the required registration fee, and then conducted testing with a fabricated asset prior to executing the first unauthorized token creation the following day.

The initial creation of 18.4 million ZANO remained undetected for close to a full month. According to the team's statement, the illegitimately created coins had the appearance of standard outputs, and the internal development teams only identified the suspicious activity following the second minting event.

According to Zano's disclosure, the vulnerability escaped detection through AI-assisted testing procedures, internal security audits, and bug bounty programs.

In related developments, Zano announced on Wednesday that it is actively working toward restoring impacted user balances through the utilization of its developer fund, personal funds contributed by team members, and additional pledged contributions. The recovery process will predominantly operate through cryptocurrency exchanges and payment service providers, with exchanges tasked with replaying withdrawal transactions that were reversed due to the rollback and the team providing credits for deposits that were affected.