Zano exploiter minted more than a quadrillion fUSD before blockchain rollback

요약:Zano says an attacker created 36.9 million unauthorized ZANO using a Gateway Address vulnerability before the project rolled its blockchain back by a month.

Update (Oct. 2 at 6:53 am UTC): This article has been updated to include a comment from Zano head of marketing and growth, Quinten van Welzen.

Zano revealed that the attacker who exploited its Gateway Address vulnerability over the last month used it to create 36.9 million Zano (ZANO), along with 1.8 quadrillion Freedom Dollar (fUSD) tokens, before the decision was made to roll the blockchain back by a month.

In a post-mortem published Thursday, Zano said the attacker first exploited the vulnerability on Aug. 29, creating approximately 18.4 million ZANO in a single transaction. The attacker repeated the exploit on Sept. 25, minting another 18.4 million ZANO, before using the same method to create approximately 1.8 quadrillion fUSD.

“These coins functioned as authentic ZANO and could be spent normally,” the team wrote in its post-mortem. Zano spokesperson Quinten van Welzen told Cointelegraph only a small fraction reached the market as it was limited by liquidity available on exchanges.

The figures shed light on why the Zano team called for a rollback of about a month of blockchain history, including legitimate transactions. The team acknowledged that the rollback would hurt trust but argued it was necessary to remove unauthorized supply as it could not be distinguished from legitimate coins.

Attacker paid 100 ZANO exploit entry fee

Zanos post-mortem said the attacker paid 100 ZANO to set up the exploit, worth about $553 at the time of publication.

The attacker registered a Gateway Address on Aug. 28, paid the registration fee, then tested a fabricated asset before the first unauthorized mint the next day.

The first 18.4 million ZANO mint went unnoticed for nearly a month. The team said the unauthorized coins appeared like ordinary outputs, and internal teams flagged the activity after the second mint.

Related: Zano rolls blockchain back a month after Gateway Address exploit

Zano said AI-assisted testing, internal audits and bug bounties failed to pick up the bug.

Meanwhile, Zano said Wednesday it is working to restore affected balances using its developer fund, team members personal funds and committed contributions. Recovery will primarily run through exchanges and payment services, with exchanges to replay withdrawals reversed by the rollback and the team credited the affected deposits.

Magazine: China warns foreign spies about crypto, Singapore dominates Asia: Asia Express

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

미국 2.9만개 일자리 추가…비트코인·금 상승 이유?

다음

Circle, MiCA 검토에서 EU에 스테이블코인 준비금 규정 개정 촉구