Zano Rolled Back Its Own Blockchain to Erase 36.9M Fake Coins
An attacker minted 36.9 million unauthorized ZANO that looked identical to the real thing, forcing the project to rewrite its own chain to kill them. The rollback solved the problem and created three new ones.
Zano just rolled back its own blockchain to erase 36.9 million coins that never should've existed.
That's the short version. The long version is uglier, and it says a lot about what happens when a small chain runs into a bug it can't patch its way out of.
How It Unraveled
Here's the part that matters most. The attacker didn't steal 36.9 million ZANO. They created it. Fresh coins, out of thin air, straight into their own addresses.
Minting bugs aren't rare. Most chains catch them fast, freeze the funds, blacklist the address, move on. Zano couldn't do any of that. Because the 36.9 million unauthorized coins were, at the protocol level, indistinguishable from legitimate ZANO. Same encryption. Same metadata. Same everything.
So what do you do when the counterfeit is perfect?
You can't burn them. You can't flag them. You can't ask exchanges to filter them out, because there's nothing to filter on. A ZANO that shouldn't exist and a ZANO you mined last Tuesday look exactly the same to every node on the network.
That left one option. Roll the chain back.
And just like that, the project went from patching a bug to rewriting settled history. Validators and node operators had to coordinate on a snapshot point, rebuild from there, and discard everything that came after. Blocks that stakers had already produced got orphaned. Transactions that people had already sent, confirmed, and built their books around got unwound.
Exchanges did what exchanges always do in a moment like this. They paused deposits. Some paused withdrawals too, which is the part that stings, because a paused withdrawal means your coins are sitting on someone else's server while the chain gets demolished and rebuilt underneath them.
Nobody announced a clean timeline. There almost never is one. Rollbacks don't happen on a schedule. They happen when the team decides the alternative is worse.
Who Got Hurt
Let's be blunt about the winners and losers here, because crypto loves to skip that part.
Losers first. Anyone who bought ZANO inside the rollback window and moved it off an exchange. That trade doesn't exist anymore. Anyone who deposited during the exploit period might find their credited balance vanished when the exchange re-syncs to the new chain. Stakers who produced legit blocks in the discarded range watched their rewards evaporate. And every holder who now has to explain to themselves why the chain they own got rewritten by a handful of people.
The attacker? They lose the 36.9 million coins. But they were never going to be able to dump that size quietly anyway. Thirty-seven million units on a privacy coin with a thin order book is a dump that announces itself.
Winners: short sellers with good timing, rival privacy coins looking for a marketing angle, and anyone who's been arguing that small-cap chains are one bad commit away from a hard reset. They all got their receipts today.
This changes things, and not in a comfortable way for the privacy crowd. Confidential assets and untraceable transfers are the entire selling point of a chain like Zano. It's also the exact reason the fix had to be nuclear. The feature that makes the coin valuable is the same feature that made the 36.9 million fakes impossible to isolate.
That's not a design flaw you patch. That's a tradeoff baked in from the start, and Zano just paid it in public.
The market's verdict on rollbacks is always split, and it always comes down to who's holding the bag. Eth holders who lived through 2016 will tell you the DAO rollback saved the network. EthClassic holders who got left behind will tell you the opposite, loudly, for the rest of their lives. Both are right about their own experience.
Here's my take. The Zano team made the only call available to them. Letting 36.9 million counterfeit coins float around the supply would've been worse than a chain rewrite, and pretending otherwise is fantasy. But I'm not going to pretend the rollback is a happy ending either. Rollbacks are a confession. They tell you exactly how much trust the network puts in a small group of people to decide what's real.
What Comes Next
Three things to watch, and you can put dates on all of them.
First, the exchange reopenings. Watch what happens over the next 30 days as major venues re-enable ZANO deposits. If the deposit queues clear smoothly, the market forgives fast. If any exchange quietly delists instead, that's a louder signal than any price candle.
Second, the post-mortem. Small chains that survive an exploit of this size usually publish a full technical writeup within two to four weeks. Zano needs to show exactly how 36.9 million coins got minted, what the patch is, and whether the same bug exists in the confidential assets code. Anything vague, and traders will assume there's a second exploit waiting.
Third, a chain split. Rollbacks have a way of creating orphans in the community, not just in the blocks. If a meaningful group of node operators refuses to sync to the rewritten chain, you get two Zanos and a very confusing chart. That's the scenario nobody wants and everybody should be pricing in.
Traders are watching closely. They should be. The 36.9 million number is the headline, but it's not the story. The story is that a privacy coin with real users had to erase confirmed transactions to save itself, and everyone on that chain is now living with what that means.
Every ZANO in your wallet is real because a small group decided it's. That was always true. Today it's just harder to ignore.
Explore More
Key Terms Explained
A distributed database where transactions are grouped into blocks and linked together cryptographically.
Permanently removing tokens from circulation by sending them to an unusable wallet address.
A sudden, significant price drop usually caused by large sell-offs.
A marketplace where cryptocurrencies are bought and sold.