Zano faces 24-hour rollback after asset issuance flaw
Privacy-focused blockchain Zano faces a potential 24-hour network rollback after discovering an asset issuance vulnerability tied to public Gateway Addresses, causing token prices to tumble.

On September 25, privacy-focused blockchain Zano disclosed that a vulnerability involving its public Gateway Addresses impacted asset issuance, potentially forcing the network to roll back 24 hours of transactions. Unlike standard crypto hacks involving compromised keys or stolen wallets, this incident centers on how tokens were generated on the network.
Zano noted that transaction privacy remained uncompromised, with all wallets and spend keys safe. Instead, the bug affected asset creation, including the fUSD stablecoin. This makes the security issue particularly critical, as it raises questions about whether certain assets were minted in accordance with Zano’s protocols.
Why an issuance flaw is different from a wallet drain
In a post on X, Zano explained that the vulnerability involved public Gateway Addresses and instructed mining pools, node operators, and exchanges to prepare for a synchronized network upgrade. A subsequent update from the project confirmed that user balances remain secure and that any discrepancies linked to the affected addresses will be resolved.
The fundamental difference with this bug is that it did not simply give an attacker control over existing assets. While a stolen private key grants access to pre-existing coins or tokens, an inflation bug can permit the creation of assets that should never have existed.
Security update and coordinated upgrade:
The core team has identified a vulnerability in public Gateway Addresses that affects asset issuance, including fUSD.
Transaction privacy is unaffected, and no spend keys or wallets are compromised.
We will coordinate a network…
— Zano (@zano_project) September 25, 2026
This explains why Zano took the unusual step of asking users to temporarily halt transactions involving ZANO and Confidential Assets while the team investigates. The goal was twofold: to prevent further theft and to stop new transactions from piling up while the developers identify impacted balances and assets.
The market reacted swiftly. Bitcoin.com reported that ZANO’s price tumbled by roughly 20% following the disclosure, while CoinGecko figures showed that ZANO finished September 24 at $7.50 after trading above $8 just days prior.
A day of blockchain history may disappear
According to Bitcoin.com, ZANO was getting ready to implement a rollback spanning about 24 hours of accepted transactions. Should this rollback proceed, stakers, miners, and nodes will transition to a revised transaction history that excludes the problem period.
While the concept is straightforward—reversing the chain to discard the questioned transactions—the complication lies in how it affects all other activity during that window. Legitimate transfers will also be undone, requiring traders, exchanges, and everyday users to review previous transactions they previously thought were settled.
When Zano first broke the news, several key details remained unclear, including the exact volume of unauthorized assets minted, the precise location of the bug in the codebase, and the mechanics of the rollback.
The infrastructure designed to attract exchanges
Ironically, Gateway Addresses were originally created to simplify platform and exchange integration with Zano.
Documentation from Zano explains that these addresses utilize an account-based framework storing balances directly on-chain, offering an easier integration path than the network’s traditional UTXO system. Built for payment gateways, DEXs, bridges, and exchanges, registering a Gateway Address carries a 100 ZANO fee.
Zano’s August update showed that Gateway Addresses debuted alongside Hard Fork 6 at block 3,833,000 on August 26, following nearly a year of development. They were introduced, in part, to ease onboarding for exchanges that previously found the network too complex to support.
This makes the vulnerability deeply ironic, as it emerged within the very feature built to make Zano more accessible to external platforms.
Where Zano fits into a wider pattern
Zano is not an isolated case of security vulnerabilities leading to unauthorized token creation. Such events demonstrate how rapidly technical failures can damage both token pricing and user confidence.
As Cryptopolitan noted regarding the Fetch.ai and NuNet incident, an attacker unlawfully minted 408.5 million NTX after compromising a private key, causing the NuNet token’s value to drop sharply.
The Liquid Network breach unfolded differently but highlighted a comparable vulnerability. Chainalysis reported that attackers exploited a transaction-validation loophole to generate unbacked L-BTC and withdraw roughly $320 million in genuine bitcoin, though about 85% of those funds were later returned.
These occurrences form part of a broader trend of crypto security breaches. TRM Labs logged 207 hacks during the first half of 2026. Although infrastructure and operational issues accounted for only about 15% of those breaches, they represented roughly 76% of total losses.
While Zano is not large enough for this incident to rattle the broader cryptocurrency market, the situation underscores how blockchain infrastructure flaws can alter token supply and undermine confidence in transaction finality. As these networks grow more sophisticated, resolving infrastructure-level failures is far more difficult than addressing a standard wallet theft.
The next steps will hinge on Zano’s final rollback terms, the deployment of a patched release, any reimbursement procedures, and the promised postmortem report.
The smartest crypto minds already read our newsletter. Want in? Join them.




Comments 0 responses