Zano exploiter created 36.9M unauthorized ZANO before blockchain rollback
The unauthorized coins were indistinguishable from legitimate ZANO, leaving the team unable to remove them without rolling back the blockchain.
Asanat Analysis — Why it matters
A critical vulnerability in Zano's minting logic allowed an exploiter to generate 36.9M unauthorized tokens—representing a significant inflation attack on the protocol. The fact that fake coins were cryptographically indistinguishable from legitimate ZANO highlights a fundamental design flaw: the blockchain couldn't differentiate between valid and fraudulent supply at the protocol level, forcing the team into the extreme measure of a full rollback rather than surgical removal.
Blockchain rollbacks are rare and carry severe consequences for ecosystem confidence, especially for a privacy-focused project like Zano. This incident signals that privacy coin architectures—which intentionally obscure transaction details—create operational blindspots during security incidents. It also underscores why supply-side bugs are existential threats to cryptocurrency projects: unlike DeFi contract exploits that typically affect specific user balances, minting vulnerabilities corrupt the core monetary assumption that underpins all holder valuations.