The Gateway Address Vulnerability: What Happened and What Comes Next

On 25 September 2026, a vulnerability was identified in Zano's Gateway Address implementation that allowed ZANO and fUSD to be artificially created.

Zano Security Update

Summary

On 25 September 2026, a vulnerability was identified in Zano's Gateway Address implementation that allowed ZANO and fUSD to be artificially created. No user funds or privacy was compromised, but unauthorized new supply was minted.

The vulnerability was introduced with Hard Fork 6 (HF 6). It was used to mint unauthorized coins starting on 29 August 2026. The proposed solution was a network upgrade that continues the chain from block 3,833,000, the last block before HF 6, completely disabling Gateway Addresses until further review. This post covers what the vulnerability was, how it was used, why it was initially undetected, and what comes next.

The vulnerability

HF 6 introduced a new type of address: Gateway Addresses. They are implemented through new models of transaction inputs and outputs. By design, Gateway outputs have a plain-text amount and asset ID, unlike standard confidential Zano outputs, which have both fields hidden (committed).

A Gateway output's asset ID is an elliptic curve point that must correspond to an asset already registered within the network. However, in the HF 6 code, the asset ID was only checked against the genuine native-coin identifier, allowing a malicious sender to craft a specially calculated point that maintained the transaction proofs (including the balance proof) while permitting a hidden output with an arbitrary amount. Such outputs are indistinguishable from standard confidential outputs and can be spent.

In short, every Zano transaction must prove that coins were created from consensus rules. Because of a missing verification, an attacker could satisfy this proof while “hiding” extra coins within the transaction. These coins functioned as authentic ZANO and could be spent normally.

What happened

All dates below are in UTC.

On 28 August 2026, an attacker registered a Gateway Address, gwZ5srqAWD6…, burning the 100 ZANO registration fee in tx 03edb09ab5d9ec759aa2c2b98b377499cdb136e6a222622c75445d095902c517. Subsequently, tx 4de583a6cbbe0c5813df87b6c79e850ff076b9abbf603c722d9eda5d46edee25 carried a constructed, non-existent asset, most likely to test whether the network would accept it.

On 29 August 2026, the first real exploit followed in tx cea38b652f00bad1c7e20a8742481028c7ebc2f596e550fb8e04c621f0591da1. A single transaction minted 2^64 base units of ZANO, approximately 18.4 million ZANO, with the visible output sent to the attacker's Gateway Address.

Nearly one month later, on 24 September, the attacker made two small, legitimate deposits of 0.05 ZANO to his Gateway Address, in txs 9947348ff64c68779c24a47f50e0bc1008cf25ddb1cfbc42f509855e4e641a9b and 59d63f117d055300896273fa3356b25832752083dc90073f5f721e7fa2b8d763, most likely to test the standard deposit path.

On 25 September, the exploit was performed twice more. Tx a053b649afe5dc7420c9c6c2756558d0a76630f38482624cca7e865b626c277e minted another 2^64 base units of ZANO, and subsequently tx 180a97e40d7d2dedd744b9a199840709796b03c4771412f08e02d1789ecb521f minted 2^64 base units of fUSD via the same method. Note, these values represent the total amount of ZANO and fUSD created; of which a portion was introduced into the greater Zano ecosystem.

How it went undetected

Prior to HF 6, thorough AI-assisted testing, team audits, and bug bounty programs did not discover the vulnerability. Upon release of HF 6, the core team and multiple external cryptographers were focused on continuous monitoring and validation of Zano consensus: range proofs, the Zarcanum proof-of-stake construction, Confidential Assets math, and CLSAG ring signatures. It was expected that any potential issues would appear within these complexities. A log-checking harness was likewise tuned to detect potential failures such as math disagreement, p2p DDoS and broken proofs.

However, the vulnerability ultimately was a check in the Gateway path implementation. The initial exploit went undetected for nearly one month because the increased output appeared like any other private output. On 25 September, internal analysis tools flagged on-chain activity, which was ultimately traced back to 29 August.

What we were able to verify

The only assets affected were ZANO and fUSD. All assets require a visible Gateway output, and because those outputs are public, all affected balances can be determined. No user funds were affected and no private keys or other private data were exposed. The vulnerability was specifically isolated to creating unauthorized supply.

Additionally, wrapped ZANO (wZANO) on Ethereum was not affected. The ZANO collateral is stored within a Zano auditable wallet, so every wrap and unwrap is visible. The bridge processed wraps and unwraps during the affected period, and those Zano transactions are not part of the updated chain. The wZANO bridge is currently paused and is no longer active on the prior chain. When it restarts, it will replay the unwraps from that period, so no bridge user loses anything.

The major limitation was the traceability of the exploited ZANO and fUSD coins. Once created, they were indistinguishable from any other private Zano output, and because ring signatures mix every spend with other outputs, uncertainty spreads with each transaction.

Every output that could potentially be linked to the three minting transactions was scanned, directly or through a chain of transactions. As of block 3,878,388, they lead through ring references to 117,941 outputs, created by 65,301 transactions. Around 165,700 outputs were subsequently created from the first mint at block 3,836,983, approximately 71% of all network activity within the period.

That is privacy working as intended. No one, including the Zano team, can accurately determine which outputs are affected. The only way to verify supply integrity is to continue the chain from a point prior to the first exploit.

How the network upgrade works

Continuing the chain from block 3,833,000 guarantees that all exploited ZANO and fUSD is completely removed from the network. The proposed update was Hard Fork 7 (HF 7), which activates at the same height as HF 6 and disables Gateway Addresses. This feature will remain disabled until all code has been completely reassessed and audited without time constraints. Like every hard fork, HF 7 took effect only because node operators, miners, stakers and exchanges chose to adopt it. Nodes, wallets and exchanges that have upgraded now follow the updated chain. Continuing from block 3,833,000 means that all transactions, staking rewards and mined blocks from the affected period are not part of the updated chain.

Conclusion

This was a serious vulnerability, and the team recognizes its impact on real users and businesses. With this post, we wanted to be fully transparent about what happened, and how it affects the Zano community. Gateway Addresses remain an important step in making Zano easier to integrate for exchanges, bridges and other services. This feature will be proposed once the reworked code has been thoroughly reviewed and tested.

Based on the community action and support, we are confident that Zano is well positioned to move forward. The core team will continue working closely with the entire ecosystem throughout the recovery process and share updates as it progresses.