Zano network update: Recovery solution for Gateway Address vulnerability
The core team has identified a serious issue involving Gateway Addresses, which enabled unauthorized ZANO and fUSD to enter circulation.
Our investigation has found no compromise of wallet spend keys or ordinary transaction privacy. Zano core consensus is unaffected.
The team has developed a solution to eliminate all unauthorized activity with a coordinated network upgrade. To ensure full network integrity, the Zano blockchain has been restarted from block height 3,833,000, immediately prior to Hard Fork 6. This affects approximately one month of chain history. The recovery requires participating nodes, miners, stakers, and services to adopt the update.
We are relaunching services such as the mobile wallet node and the wrap service one by one. It is up to each third-party wallet, exchange, and service to update on their own behalf. Before sending funds to or from any of them, check that they have moved to the recovered chain.
Transactions confirmed during the affected period are not part of the recovered chain. Keep transaction IDs and trade records, and do not resend a payment until you have updated your wallet and checked its final status on the recovered chain.
If you run a full node, mine, stake, operate a pool, or provide exchange, bridge, or payment services, please install the emergency release as soon as possible. Use only
zano.org/wallets or the official GitHub releases page, and verify the published checksums. Ordinary wallet users can now download the updated wallet from our website as well. Seed phrases are not required to perform this upgrade.
This update removes all unauthorized activity from Zano's chain. It cannot affect payments already settled in USDT, DAI, or other assets on separate networks. The team is working with affected projects and counterparties to account for any losses and will publish the reimbursement and claims process.
Real people and businesses have been affected. We intend for the community to be made whole throughout this process. Certain community members have already pledged support to ensure that assets are restored.
Pushing innovation carries risk, and this is a clear example. Serious incidents have occurred elsewhere: Bitcoin recovered from an exploited supply bug and chain reorganization in 2010; Zcash recently patched a potential counterfeiting flaw before any known exploitation; and Ethereum made an exceptional state change after the DAO attack. Each case was different, and none diminishes the harm here. We will publish the technical cause, the results of reviewing adjacent Gateway Address code, and the criteria for safely resuming activity. Confidence must be earned through that work, and the team is committed to working with the community to deliver on these efforts.