Zano’s rollback fixed the abnormal supply, but it also put the privacy system’s auditable boundaries on full display.
【Verified facts】On October 1, the Zano team released a post-incident report stating that on September 25 it found a vulnerability in the Gateway Address implementation that could allow the generation of ZANO and fUSD. The team said user funds and privacy were not affected. The official follow-up response said the rollback removed the unauthorized supply and the network is back to its expected state. On October 3, AMBCrypto, citing the team’s report, disclosed that the attacker minted approximately 36.89 million ZANO and 18.45 million fUSD. The roughly $250 million valuation of the forged assets was converted based on the assumed ZANO price of about $7 at the time; it does not equal actual user losses or realized stolen funds.
The report explains that privacy transaction outputs and normal outputs cannot be distinguished on a per-transaction basis, so the team found it difficult to accurately identify which outputs originated from the illicit minting. Therefore, it chose to roll back about a month of chain history. The official recovery update on September 28 also said it was verifying affected activities with partners and working out a recovery plan, and that users do not need to take action for the time being; the status of wallets, services, and exchanges and any subsequent guidance still need to be announced.
【My judgment and market ripple effects】The core trade-off in this incident is that while a rollback can remove the illegal supply from the current chain state, it also forces users, wallets, and trading services to re-check history and balances. The impact on $ZANO is primarily on project credibility, exchange integrations, and user confidence—not on a token-demand change that can be directly inferred. Privacy itself is not a vulnerability; however, when the system can’t distinguish legitimate from illegitimate outputs, incident handling becomes more dependent on a full-network rollback, coordination among service providers, and transparent remediation processes. If Gateway Address is to be restarted afterward, code audits, supply-conservation checks, and independent verification will become especially important.
【Response and what to watch】If you hold ZANO or have used related wallets, first wait for the team to publish details on network height, wallet synchronization, and service recovery, and do not transfer or sign transactions based on social-media DMs claiming you can “recover assets.” Watch three things next: whether the team provides verifiable code fixes and supply-minting validation; whether wallets, services, and exchanges are all restored and provide a clear block height; and whether the recovery plan explains the scope of verification and the outcomes of handling affected activities. Only if independent re-verification confirms the fix is effective, major services are restored, and the handling rules are clear, can trust risk potentially narrow gradually. If supply verification remains opaque, service recovery keeps fluctuating, or the team’s explanation of affected activities is inconsistent over time, then this assessment fails.
Market note: In this round of query, Binance Spot’s exchangeInfo showed no active ZANO/USDT trading pairs, so it does not reference Binance spot trading-volume rankings, prices, or price-change percentages.
Source: Zano official post-incident report (2026-10-01, written by the team) https://x.com/i/article/2105641163805917184;Official report announcement post (2026-10-01) https://x.com/zano_project/status/2105648653876474358;Official recovery update (2026-09-28) https://x.com/zano_project/status/2104650308513144955;Official supply recovery response (2026-10-01) https://x.com/zano_project/status/2105653717156663399;AMBCrypto coverage of the post-incident report (2026-10-03) https://ambcrypto.com/privacy-working-as-intended-zano-details-1-month-rollback-after-250m-exploit/。
#ZANO #区块链安全 #privacy