Zano restarts chain at block 3,833,000 after exploit

Changelly
Ledger



Zano has restarted its blockchain from block 3,833,000 after a Gateway Address vulnerability allowed unauthorized ZANO and Freedom Dollar tokens to enter circulation, removing roughly one month of network history.

Summary

  • Zano restarted from block 3,833,000, removing roughly one month of transactions after the Gateway exploit.
  • Gateway Address vulnerability allowed unauthorized ZANO and fUSD to enter circulation without compromising wallet keys.
  • MEXC suspended ZANO and FUSD deposits and withdrawals while services migrate to the recovered chain.
  • Zano says reimbursement will use developer, team and large-holder funds without issuing additional ZANO tokens.
  • ZANO fell more than 12% over 24 hours as the network recovery process continued Sunday.

Zano’s core team said Sunday that the chosen block sits immediately before Hard Fork 6, which activated the Gateway Address feature in August. The emergency recovery requires miners, stakers, nodes, exchanges, pools and other services to install updated software and follow the recovered chain.

bybit

Transactions confirmed during the affected month no longer form part of the recovered blockchain. Users have been told to keep transaction IDs and trading records while checking the status of earlier transfers before sending payments again.

The rollback cannot reverse transactions completed outside Zano. Assets already settled as USDT, DAI or other tokens on separate networks remain outside the reach of the chain restart, according to the project.

Zano rollback removes Gateway Address activity since Hard Fork 6

Hard Fork 6 went live at block 3,833,000 on Aug. 26, bringing Gateway Addresses and several other protocol changes to Zano. The project had spent more than a year developing the address system before deployment.

Gateway Addresses were built for exchanges, bridges and payment providers that found Zano’s normal unspent transaction output model difficult to integrate. Unlike ordinary Zano wallets, the new addresses keep an account-style balance directly on the blockchain.

Before the upgrade, service operators had to scan outputs, track incoming transactions and manage which outputs were spent during withdrawals. Gateway Addresses were intended to give those operators one balance while preserving the privacy features used by ordinary Zano transactions.

Registration required a one-time fee of 100 ZANO, which the protocol permanently burned. Zano forum records showed at least two Gateway Addresses were registered during the feature’s first week on mainnet.

The team has not yet released the promised technical post-mortem explaining precisely how the vulnerability produced unauthorized assets. Its recovery notice said the issue affected asset issuance through Gateway Addresses, including native ZANO and fUSD.

According to the project’s investigation, ordinary transaction privacy and wallet spend keys were not compromised. The team described Zano’s underlying consensus as unaffected and said the emergency release removes activity created through the vulnerable feature.

Emergency release requires services to choose the recovered chain

A new Zano software release, version 2.2.3.600, appeared during the recovery process, according to the project’s official forum. Node operators, miners, stakers, pools and service providers were urged to install the emergency software and verify the published checksums.

Ordinary wallet users can install the updated wallet without entering their seed phrases. Zano has begun restoring its own services individually, including its mobile wallet node and wrapping service.

Third-party platforms must update separately. Zano warned users to confirm whether an exchange, wallet, bridge or payment provider has migrated before sending funds through those services.

MEXC has temporarily suspended deposits and withdrawals for both ZANO and FUSD following a request from the project team. The exchange had not announced a restart time when the notice was published.

The recovery depends on network participants accepting the new software. Quinten van Welzen, Zano’s head of marketing and growth, rejected descriptions suggesting the team could unilaterally erase blockchain history.

“The team can’t roll back Zano,” van Welzen said, explaining that developers can release software and ask network operators to adopt it.

He acknowledged that major mining pools carry substantial weight in deciding which chain receives support and said a larger base of independent operators would strengthen Zano.

The situation has parallels with other recent blockchain recovery attempts. In related coverage, crypto.news reported that Cronos validators restored the chain to a pre-exploit state after the Tectonic incident.

A later Cronos post-mortem found that validators reversed roughly USD 111.2 million of affected value, while USD 9.19 million remained outside the recovery after funds moved away from the network.

Crypto.news separately reported on Harmony’s proposed rollback after forged ONE entered circulation in August. The proposed recovery risked discarding more than 109,000 ordinary transactions.

Zano plans reimbursement without issuing new tokens

The month-long rollback invalidates legitimate payments made alongside the unauthorized token activity, leaving exchanges, businesses and users with records that may no longer match the recovered blockchain.

Zano said it is working with affected projects and counterparties to calculate losses. A formal reimbursement and claims process has yet to be published.

Van Welzen said funding would come from the development fund, team holdings and large holders who have committed resources to the recovery. He said the reimbursement plan would not involve creating extra ZANO.

“A month of payments between people” makes reimbursement complex, he said, while acknowledging that the team had not settled every part of the claims process.

The project initially described a much shorter rollback while investigators were still determining the scale of the flaw. Van Welzen later acknowledged that early communications referring to “24 hours” and “no other choice” were issued before the team fully understood the incident.

Restarting from the pre-Hard Fork 6 block ultimately expanded the affected period to roughly one month. The team said the deeper rollback removes unauthorized ZANO and fUSD from the recovered chain.

Zano plans to publish the technical cause of the exploit, findings from a review of related Gateway Address code and conditions that must be met before the feature can return. No date has been announced for reactivating Gateway Addresses.

ZANO price falls as recovery continues

ZANO traded near USD 6.32 during the recovery, down roughly 12.85% over 24 hours, according to CoinMarketCap. Its reported market capitalization stood near USD 97.6 million, while 24-hour trading volume was approximately USD 64,000.

Zano launched in 2019 as a privacy-focused layer-1 blockchain using a hybrid proof-of-work and proof-of-stake system. Its standard transactions use privacy tools that conceal sender and receiver information, amounts and asset types.

Hard Fork 6 had been presented as a way to make the network easier for exchanges and cross-chain services to integrate. Before the exploit, Zano said Gateway Addresses would provide service operators with directly readable balances while leaving normal wallet behavior unchanged.

The project now says Gateway Addresses will remain subject to a code review before their return. Its forthcoming technical report is expected to cover the exploit’s cause, related Gateway Address code and the criteria required before the feature can safely resume.



Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*