Zano faces 24-hour rollback after asset issuance flaw

Wait 5 sec.

Zano, a privacy-oriented blockchain, revealed on September 25 that a problem with its public Gateway Addresses affected asset issuance and could require the network to roll back a day’s worth of transactions. Unlike the common crypto hacks that involve stolen wallets or compromised keys, this one is related to how assets were created on the network.Zano said its privacy features were unaffected and that no wallets or spend keys were compromised. Instead, the flaw was connected to how assets are issued, including its fUSD stablecoin. This renders the flaw particularly serious since it calls into question whether affected assets have been created in compliance with the protocols of Zano.Why an issuance flaw is different from a wallet drainZano revealed in an X post that the issue was connected to its public Gateway Addresses. It asked node operators, mining pools, and exchanges to prepare for a coordinated network upgrade. In a follow-up post, Zano assured that user balances are secure and that it would address any discrepancies connected to the affected addresses.What makes this flaw different is that it did not involve an attacker simply gaining control of existing assets. A compromised private key gives an attacker control over coins or tokens that are already there. An inflation bug, on the other hand, can allow the issuance of coins or tokens that should never have been created.Security update and coordinated upgrade:The core team has identified a vulnerability in public Gateway Addresses that affects asset issuance, including fUSD. Transaction privacy is unaffected, and no spend keys or wallets are compromised. We will coordinate a network…— Zano (@zano_project) September 25, 2026This clarifies why Zano made the unusual decision of asking its users to temporarily stop their transactions involving ZANO and Confidential Assets while the team addresses the issue. The objective here was not just to prevent further theft from taking place, but also to stop transactions from accumulating while they determine the affected assets and balances.The market responded quickly to the news. In an article by Bitcoin.com, it stated that the price of ZANO dropped approximately 20% after the issue was reported, while data from CoinGecko indicated that ZANO closed the day on September 24 at $7.50 after being above $8 just a few days earlier.A day of blockchain history may disappearAccording to a report by Bitcoin.com, ZANO was preparing for a rollback that would cover about 24 hours of accepted transactions. If the rollback takes place, miners, stakers, and nodes will use a revised chain history that does not include the affected period.The concept is rather straightforward: reverse the chain and discard the transactions in question. However, the issue that arises is its impact on all other transactions made in that time frame. Legitimate payments will also get lost, forcing exchanges, traders, and the users of these services to go through the list of previous transactions they believed were finalized.At the time Zano first brought the news to light, many important facts were still unknown, such as the number of the assets issued without authorization, the specific place in the code where the issue originated, or the method that will be used for the rollback.The infrastructure designed to attract exchangesThe irony is that Gateway Addresses were designed to make integration with Zano easier for exchanges and other platforms.According to Zano’s documentation, these addresses use an account-based model that keeps balances directly on-chain, making it easier for exchanges and other services to integrate with Zano than its traditional UTXO system. They were designed for exchanges, bridges, DEXs, and payment gateways. Registering a Gateway Address costs 100 ZANO.According to Zano’s update for August, Gateway Addresses were launched with Hard Fork 6 at block 3,833,000 on August 26, after nearly a year of development. Zano introduced Gateway Addresses partly to simplify the integration process for those exchanges that have previously viewed its network as too difficult to support.And this makes the flaw extremely ironic since it occurred exactly in the system that was intended to make Zano more accessible to exchanges and other platforms.Where Zano fits into a wider patternZano isn’t the only recent example of how a security flaw can cause asset creation without any authorization. The consequences reveal how swiftly these types of failures can affect not only the token’s price but also the level of trust the network enjoys among users.According to Cryptopolitan, an attacker minted 408.5 million NTX unlawfully in the Fetch.ai and NuNet case after a private key was compromised. As a result, the value of the NuNet token plunged dramatically.The Liquid Network incident unfolded differently, but it exposed a similar weakness. Chainalysis found that attackers exploited a transaction-validation flaw to create unbacked L-BTC and withdraw about $320 million in real bitcoin. Roughly 85% of the bitcoin was returned afterwards.Zano, NuNet and Liquid Network issuance bugs comparedThese incidents belong to a larger series of cryptocurrency security breaches. In the first half of 2026, TRM Labs recorded as many as 207 hacks. Only around 15% of breaches were infrastructure and operational problems, but losses from those make up around 76% of the total.Zano does not have a significant size for this event to be able to shake the crypto market as a whole. Nevertheless, the situation is serious because it illustrates how the problems within the infrastructure of a blockchain can influence the supply available and lead to loss of trust in the finality of transactions. As these systems become more complex, failures at that level can be much harder to unwind than a straightforward wallet theft.What comes next will depend on Zano’s final rollback parameters, patched release, reimbursement process, and the postmortem analysis it has promised.If you're reading this, you’re already ahead. Stay there with our newsletter.