Privacy blockchain Zano plans 24-hour rollback after Gateway Address flaw allows unauthorized asset issuance

BlockchainCrypto Coin Show News Team·September 26, 2026·3 min read

Zano, a privacy-focused blockchain, disclosed a flaw in its Gateway Address system that let assets including its fUSD stablecoin be issued outside protocol rules, prompting the team to plan a 24-hour rollback of transaction history. The bug does not touch wallets, spend keys or the network’s privacy layer, but it strikes at asset issuance itself, a category of failure that TRM Labs says accounted for roughly 76% of all crypto losses in the first half of 2026 despite representing only about 15% of incidents.

  • ZANO fell roughly 20% after the disclosure, closing September 24 at $7.50 versus above $8 days earlier.
  • The core team is preparing a rollback covering about 24 hours of accepted transactions across the network.
  • Gateway Addresses, which cost 100 ZANO to register, launched with Hard Fork 6 at block 3,833,000 on August 26, 2026.
  • 20% ZANO’s price drop versus its recent $8 high
  • 24hrs transaction history Zano may erase in a rollback
  • $320M bitcoin drained in the comparable Liquid Network exploit

Zano said the vulnerability sits in its public Gateway Addresses, an account-based feature built specifically to make the network easier for exchanges, bridges and payment gateways to integrate, according to Zano’s documentation. The team asked node operators, mining pools and exchanges to prepare for a coordinated network upgrade while it identifies which assets and balances were affected.

Zano Says fUSD Issuance Compromised, Wallets Untouched

Zano’s disclosure separates this incident from a typical exchange hack. A stolen private key hands an attacker control of coins that already exist; an issuance bug lets new coins be created that should never have existed at all. The company said in a post on X that transaction privacy remains intact and that no spend keys or wallets were compromised, but confirmed the flaw affects asset issuance including fUSD.

In a follow-up post, Zano told users their balances are secure and that it would resolve discrepancies tied to the affected Gateway Addresses. The team also asked users to pause transactions involving ZANO and Confidential Assets while it isolates the damage.

ZANO Drops to $7.50 as 24-Hour Rollback Looms

Data from CoinGecko shows ZANO closing September 24 at $7.50, down from above $8 just days before, a roughly 20% slide following the disclosure. A rollback of this scale would force miners, stakers and nodes to adopt a revised chain history that excludes the affected window, discarding not just fraudulent issuance but every legitimate transaction processed alongside it.

Exchanges and traders would need to re-verify any transaction they considered final during that 24-hour period. Zano has not yet specified how many assets were improperly issued, where in the code the flaw originated, or the exact rollback method it will use.

The irony is structural. Gateway Addresses, described in Zano’s documentation as an account-based system meant to simplify integration for exchanges that had previously found Zano’s UTXO model too complex to support, are the exact feature that failed. The same tool built to attract institutional counterparties is now the source of the network’s most serious issuance risk.

TRM Labs Ties Issuance Bugs to 76% of 2026 Crypto Losses

Zano is not the first network to see unauthorized issuance undermine trust in a token’s supply. In the Fetch.ai and NuNet case, an attacker exploited a compromised private key to mint 408.5 million NTX, sending the token’s value sharply lower.

The Liquid Network suffered a different but related failure when attackers used a transaction-validation flaw to create unbacked L-BTC and withdraw about $320 million in real bitcoin, of which roughly 85% was later returned.

Zano’s own size limits its capacity to shake the broader market, but the pattern is what matters to institutional counterparties. TRM Labs counted 207 hacks across the first half of 2026, and while infrastructure and operational failures made up only about 15% of them, those incidents produced roughly 76% of total losses, far outweighing simple wallet compromises.

Failures embedded in issuance logic are proving harder to contain than a straightforward theft, precisely because they call the finality of the chain itself into question.

The CCS read. Institutional counterparties evaluating smaller privacy chains should treat this as a custody-adjacent risk rather than a market-cap event. A 24-hour rollback resets ledger finality, the exact property exchanges and stablecoin issuers rely on for settlement guarantees, and any venue holding fUSD or ZANO balances needs its own reconciliation process before treating post-rollback balances as final.

Zano has promised a patched release, a reimbursement process for affected balances, and a full postmortem. Exchanges and node operators are now waiting on the team to confirm the exact rollback parameters and the scope of unauthorized issuance before resuming ZANO and Confidential Asset transactions.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe