Zano Rolls Back a Month of Blockchain History After Gateway Exploit
• September 27, 2026 11:12 pm • CommentsZano has taken one of the most disruptive recovery steps available to a blockchain: it restarted the network from a checkpoint that erases roughly a month of chain history.
The move follows a Gateway Address vulnerability that allowed unauthorized ZANO and Freedom Dollar, or fUSD, to enter circulation. The recovered chain begins at block 3,833,000, immediately before Hard Fork 6 activated the affected feature.
In a detailed update, Zano said the restart removes the unauthorized activity but also means legitimate transactions confirmed during the affected period are no longer part of the recovered chain. Users and businesses were told to retain transaction IDs and trade records and to check final status before resending any payment.
Zano network update: Recovery solution for Gateway Address vulnerability
The core team has identified a serious issue involving Gateway Addresses, which enabled unauthorized ZANO and fUSD to enter circulation.
Our investigation has found no compromise of wallet spend keys or…
— Zano (@zano_project) September 27, 2026
The most important practical point is the scope of the recovery. Nodes, miners, stakers, pools, exchanges, bridges and payment services must adopt the emergency release and move to the recovered chain.
Zano is bringing its own services back one at a time, but third-party operators remain responsible for their upgrades.
That makes reconciliation the immediate challenge. A payment that once appeared final may no longer exist on the recovered ledger.
A payment settled elsewhere — in USDT, DAI or another asset on a separate network — cannot be reversed simply because Zano changed its own chain history.
Cointelegraph reported that the chain restarted at block 3,833,000, immediately before Hard Fork 6 introduced Gateway Addresses, and that every participating node, miner, staker, exchange and service must adopt the recovery update before normal operations can safely resume across the ecosystem. The report also says the flaw allowed unauthorized ZANO and Freedom Dollar into circulation while leaving ordinary wallet spend keys and transaction privacy intact.
Its reporting makes the user cost clear: legitimate transactions from the discarded month disappear alongside the unauthorized ZANO and fUSD, affected users may need to reconcile transfers with exchanges and counterparties, services have to confirm they are following the recovered chain before accepting deposits or withdrawals, and the rollback grew far beyond an earlier one-day recovery concept as the team moved to the pre-fork checkpoint that removed the affected feature entirely from the recovered ledger while preparing a later claims and reimbursement process.
The report adds that Zano is restoring its mobile wallet node and wrap service in stages while exchanges and other independent services must upgrade on their own schedules. That leaves users with a practical waiting period in which a familiar interface may still point at the abandoned chain, making operator confirmation and transaction-by-transaction checks essential before funds move again.
Zano introduced Gateway Addresses to make its privacy-focused network easier for exchanges, bridges and payment systems to integrate. Its documentation describes them as account-based addresses that let a service track a direct balance instead of rebuilding activity from many separate unspent outputs.
That design was meant to lower an important adoption barrier. It also created new code at the boundary between Zano’s privacy architecture and outside infrastructure.
The team says the vulnerability did not compromise ordinary wallet spend keys, ordinary transaction privacy or Zano’s core consensus, but it did affect asset issuance through Gateway Addresses.
Today, I've read the criticism of how Zano handled the Gateway Address exploit, including from people I consider friends of the project. A lot of it is fair, and I want to respond personally.
First, we made mistakes. A bug made it into Hard Fork 6 and went unnoticed for weeks.…
— Quinten (Mr. Kwibs) | Zano (@Mr_Kwibs) September 27, 2026
The rollback solves only the ledger problem. Zano still has to publish the technical cause, review adjacent Gateway Address code, explain how affected users and businesses will be made whole, and set clear conditions for safely resuming normal activity.
The team has acknowledged mistakes and said confidence must be earned. That is the right standard.
A one-month rollback can remove unauthorized tokens from a chain, but it cannot restore trust by itself.
For users, the safest near-term approach is simple: install software only from Zano’s official site or GitHub release page, verify checksums, confirm that any exchange or service has migrated, and check each transaction on the recovered chain before acting again.
Zano made a blunt choice in favor of ledger integrity. Whether the network emerges stronger will depend on how transparently it handles the losses and how convincingly it proves that Gateway Addresses are safe before the feature returns.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
