First the sore point: for the privacy chain Zano, to patch the Gateway Address inflation loophole, it directly restarted the chain to block height 3,833,000—eliminating exactly one full month of transaction history.
Let’s lay out the hard facts first:
1️⃣ The Gateway Address that launched with Hard Fork 6 (around Aug 26 activated at block 3,833,000). Intended to provide exchanges/bridges/payment providers with an “account-style balance” integration interface; as a result, an unauthorized minting path for $ZANO + Freedom Dollar (fUSD) was exploited.
2️⃣ Core team says: transaction privacy is unaffected; the spend key / regular wallet has not been compromised; the consensus layer itself also hasn’t been breached—the issue lies in the new integrated native protocol.
3️⃣ Restore requirements: nodes, miners, the staking parties, and exchanges must synchronize updates. Transactions within the rollback interval that are valid will be invalidated as well, and any cross-chain settled USDT/ETH/DAI, etc., cannot be recovered.
4️⃣ Freedom Dollar official (Sept 27): In preliminary accounting, the project’s holdings of “millions of dollars” worth of assets were exchanged for counterfeit fUSD. The project team absorbed the loss themselves and requested that, before the patched chain stabilizes, fUSD trading/conversion/deposits/withdrawals be paused.
The marketing head Quinten van Welzen put it very plainly: allowing counterfeit money to circulate indefinitely is equivalent to diluting all holders—and also telling the next attacker that “the stolen coins can still be worth something.”
Selection criteria: this is a supply-integrity incident plus enforced social costs (the month’s history has been rewritten), not a “sure-to-surge” narrative. Rollback ≠ loss is fully settled; reimbursement/claims procedures are not in place yet, and no post-mortem has been released. Exchanges should reconcile on their own—don’t use unconfirmed on-chain balances as the basis for settlement.
Not investment advice.
Source: Freedom Dollar official blog (2026-09-27) + Cointelegraph (2026-09-28) + Bitcoin.com quoting the Zano team statement / @zano_project security update.