Zano exploiter minted more than a quadrillion fUSD before blockchain rollback

摘要:Zano says an attacker created 36.9 million unauthorized ZANO using a Gateway Address vulnerability before the project rolled its blockchain back by a month.

Update (Oct. 2 at 6:53 am UTC): This article has been updated to include a comment from Zano head of marketing and growth, Quinten van Welzen.

Zano revealed that the attacker who exploited its Gateway Address vulnerability over the last month used it to create 36.9 million Zano (ZANO), along with 1.8 quadrillion Freedom Dollar (fUSD) tokens, before the decision was made to roll the blockchain back by a month.

In a post-mortem published Thursday, Zano said the attacker first exploited the vulnerability on Aug. 29, creating approximately 18.4 million ZANO in a single transaction. The attacker repeated the exploit on Sept. 25, minting another 18.4 million ZANO, before using the same method to create approximately 1.8 quadrillion fUSD.

“These coins functioned as authentic ZANO and could be spent normally,” the team wrote in its post-mortem. Zano spokesperson Quinten van Welzen told Cointelegraph only a small fraction reached the market as it was limited by liquidity available on exchanges.

The figures shed light on why the Zano team called for a rollback of about a month of blockchain history, including legitimate transactions. The team acknowledged that the rollback would hurt trust but argued it was necessary to remove unauthorized supply as it could not be distinguished from legitimate coins.

Attacker paid 100 ZANO exploit entry fee

Zanos post-mortem said the attacker paid 100 ZANO to set up the exploit, worth about $553 at the time of publication.

The attacker registered a Gateway Address on Aug. 28, paid the registration fee, then tested a fabricated asset before the first unauthorized mint the next day.

The first 18.4 million ZANO mint went unnoticed for nearly a month. The team said the unauthorized coins appeared like ordinary outputs, and internal teams flagged the activity after the second mint.

Related: Zano rolls blockchain back a month after Gateway Address exploit

Zano said AI-assisted testing, internal audits and bug bounties failed to pick up the bug.

Meanwhile, Zano said Wednesday it is working to restore affected balances using its developer fund, team members personal funds and committed contributions. Recovery will primarily run through exchanges and payment services, with exchanges to replay withdrawals reversed by the rollback and the team credited the affected deposits.

Magazine: China warns foreign spies about crypto, Singapore dominates Asia: Asia Express

免责声明

本文观点仅代表作者个人观点,不构成本平台的投资建议,本平台不对文章信息准确性、完整性和及时性作出任何保证,亦不对因使用或信赖文章信息引发的任何损失承担责任
上一篇

USDT 十年后重回比特币交易

下一篇

ESMA主席表示MiCA重点从规则制定转向监管