Loading IndicatorLoading Indicator

Zano Says 36.9 Million Tokens Were Illicitly Minted in Exploit, Plans One-Month Blockchain Rollback

Source
YM Lee

Summary

  • Zano said it confirmed that about 36.9 million ZANO and Freedom Dollar (fUSD) were minted without authorization through an exploit.
  • Zano said it will roll back about a month of blockchain records to a point before the anomalous issuance to remove the illegitimate supply.
  • Zano said it plans to restore deposits and withdrawals at exchanges and payment services in stages for legitimate transactions canceled by the rollback, using its developer fund, team members' personal funds and outside contributions.

Forecast Trend Report by Period

Loading IndicatorLoading Indicator
Photo: Shutterstock
Photo: Shutterstock

Cryptocurrency project Zano said it confirmed that about 36.9 million unauthorized tokens were minted through an exploit. It plans to roll back about a month of blockchain history to remove the illegitimate issuance.

Cointelegraph reported on Oct. 2 that, in a post-mortem report, Zano said an attacker exploited a vulnerability in a gateway address to mint large amounts of ZANO in two separate incidents.

The attacker minted about 18.4 million ZANO in a single transaction on Aug. 29. The same method was used again on Sept. 25 to create another 18.4 million ZANO, and Freedom Dollar, or fUSD, was also minted without authorization.

The illicitly created tokens functioned the same way as legitimate ZANO. Zano said they could be used in ordinary transactions and were effectively indistinguishable from valid supply. The project therefore decided to restore the chain by rolling it back to a point before the unauthorized minting.

The attacker registered a gateway address on Aug. 28 and paid a 100 ZANO fee. After conducting tests, the attacker carried out the first exploit the following day. The first unauthorized mint went undetected for about a month, and irregularities were discovered during an internal investigation after the second issuance.

Zano also acknowledged that it failed to detect the vulnerability in advance through artificial intelligence-based testing, internal audits and its bug bounty program.

A separate recovery process will be carried out for legitimate transactions canceled by the rollback. Zano said it plans to use its developer fund, team members' personal funds and outside contributions to restore affected deposits and withdrawals at exchanges and payment services in stages.

#Blockchain Hack
#Crypto Security
YM Lee

YM Lee

20min@bloomingbit.ioCrypto Chatterbox_ tlg@Bloomingbit_YMLEE

What do you think about this news?

‌
‌
‌
‌
‌
‌
‌

PiCK News

‌
‌
‌
‌
‌

Hashtag News

‌
‌
‌
‌