Zano, a privacy-centric layer-1 blockchain, has undergone a significant network restart following a vulnerability that allowed unauthorized tokens to infiltrate its ecosystem. This rollback has effectively erased about one month’s worth of transaction history, raising questions about the platform’s security measures and the implications for its users.
The decision to restart the blockchain was executed at block 3,833,000, just prior to the implementation of Hard Fork 6, which had introduced the problematic Gateway Addresses feature in August. This feature was intended to simplify connections between exchanges, bridges, and payment services by providing a more streamlined account-style balance. However, a flaw in this system enabled the unlimited creation of unauthorized ZANO and Freedom Dollar tokens, undermining the fixed supply principle upon which Zano was established.
In response to the exploit, Zano’s team has stated that they will not issue new tokens to cover losses incurred. Instead, reimbursements will be sourced from the development and team funds. This announcement has sparked concern among investors, particularly as the price of ZANO fell by over 12% within 24 hours of the incident, trading near $6.32 with a market cap of approximately $97.6 million.
The recovery process requires all participants in the network, including miners, stakers, and exchanges, to install updated software to align with the restored chain. Zano has released version 2.2.3.600 to facilitate this transition. For everyday users, the update can be completed without the need to re-enter seed phrases, which could help mitigate some user anxiety during this tumultuous period.
Current exchanges, such as MEXC, have temporarily paused deposits and withdrawals for ZANO and Freedom Dollar tokens while navigating the migration. No definitive timeline for resuming these services has been established yet, leading many to wonder how long this disruption will last.
Quinten van Welzen, Zano’s head of marketing and growth, emphasized that the team cannot independently enforce the rollback across the network. He noted that developers can only provide updated software and encourage node operators to adopt it, highlighting the influence of large mining pools in the decision-making process. The need for a more decentralized network structure was also mentioned, suggesting that a broader base of independent operators would enhance resilience against similar incidents in the future.
Unfortunately, transactions that occurred during the compromised month will not be reflected on the recovered chain, including both legitimate payments and the unauthorized tokens. This raises concerns for users who may have made important transactions during that time, as these will remain unaccounted for in the new chain. Additionally, any funds converted to USDT, DAI, or other tokens on separate networks cannot be reversed through this rollback.
Zano is actively collaborating with affected projects to assess losses, but as of now, a formal reimbursement process has yet to be outlined. Van Welzen has reassured users that the funds for reimbursement will come from existing resources, as no new ZANO will be minted to cover these losses.
As the dust settles, Zano has committed to publishing a technical report detailing the exploit’s cause and a thorough review of related code. The Gateway Addresses feature will remain offline until the team completes their investigation, signaling a cautionary approach in restoring this functionality.
The incident serves as a stark reminder of the vulnerabilities that can exist within blockchain systems, even those designed with privacy and security in mind. As Zano navigates this recovery process, the broader crypto community will be watching closely, eager to see how the team addresses these challenges and rebuilds trust among its user base.
