Key points

  • Zano restarted its blockchain at block 3,833,000, immediately before Hard Fork 6, reversing approximately one month of chain history.
  • The project says a Gateway Address vulnerability allowed unauthorized ZANO and fUSD into circulation, while ordinary wallet spend keys and transaction privacy were unaffected.
  • Transactions from the removed period are not part of the recovered chain, and payments already settled on other networks cannot be reversed by the restart.

Privacy-focused blockchain Zano has restarted its network at block 3,833,000 after a vulnerability in its Gateway Address system allowed unauthorized ZANO and Freedom Dollar tokens to enter circulation. The selected height sits immediately before Hard Fork 6, meaning the recovery removes roughly one month of blockchain history rather than applying only a forward-looking software patch.

The recovery rewrites a month of history

Zano's core team said the restart eliminates the unauthorized activity from the recovered chain. It also removes legitimate transactions confirmed after the selected block. Users have been told to retain transaction IDs and trade records, update their wallets and verify final status on the recovered chain before resending any payment.

Related reporting: Zcash holders back 25-second blocks while keeping halving schedule

The change requires miners, stakers, full nodes, pools, exchanges, bridges and payment services to adopt the emergency release. Zano is restoring its own mobile-wallet node and wrap service in stages, but third-party providers must upgrade separately. That creates a period in which services may show different states or remain unavailable until they confirm that they are following the recovered chain.

What the Gateway Address issue affected

Gateway Addresses were introduced to give exchanges, bridges and payment services an account-style way to manage balances on a network otherwise built around unspent transaction outputs. According to the project, the flaw affected asset issuance and enabled unauthorized ZANO and fUSD to circulate. The team said ordinary wallet spend keys were not compromised, standard transaction privacy remained intact and Zano's underlying consensus was unaffected.

Those statements narrow the incident but do not yet explain its technical cause. Zano has not published the promised postmortem, an accounting of unauthorized issuance or a complete list of affected services. The team says it will release the root cause, its review of adjacent Gateway Address code and criteria for safely resuming activity after the recovery work advances.

Cross-chain payments remain outside the rollback

Restarting Zano can remove activity recorded on Zano's own ledger, but it cannot reverse USDT, DAI or other assets already settled on separate blockchains. That distinction matters for bridges, traders and merchants that may have released value elsewhere in response to transactions later removed from Zano's recovered history. The project says it is working with affected counterparties and plans to publish a reimbursement and claims process, but no detailed process was available at verification time.

Operational risks remain

A chain restart can restore the intended token record while leaving reconciliation work for users and service operators. Exchanges must ensure deposits and withdrawals point to the accepted chain, merchants need to compare records against the recovered ledger, and anyone involved in cross-chain transfers may need evidence from both networks. Users should rely on official wallet releases and published checksums rather than unsolicited upgrade links or requests for seed phrases.

What to watch next

The immediate test is whether a majority of infrastructure providers converge on the emergency release without another split. Longer term, the unanswered questions are the amount of unauthorized issuance, the losses that cannot be reversed, the design of compensation and whether the Gateway Address feature can return safely. The restart is a completed recovery action, but it is not proof that every financial and operational consequence has been resolved.

Sources

AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.