Zano exploiter created 36.9M unauthorized ZANO before blockchain rollback
The unauthorized coins were indistinguishable from legitimate ZANO, leaving the team unable to remove them without rolling back the blockchain.
Zano revealed that the attacker who exploited its Gateway Address vulnerability over the last month used it to create 36.9 million Zano (ZANO), along with Freedom Dollar (fUSD) tokens, before the decision was made to roll the blockchain back by a month.
In a post-mortem published Thursday, Zano said the attacker first exploited the vulnerability on Aug. 29, creating approximately 18.4 million ZANO in a single transaction. The attacker repeated the exploit on Sept. 25, minting another 18.4 million ZANO, before using the same method to create fUSD. The team said a portion entered the Zano ecosystem.
“These coins functioned as authentic ZANO and could be spent normally,” the team wrote in its post-mortem. Cointelegraph reached out to Zano for comment.
