Zano core just asked the network to throw away a month of history. The hyle-team/zano GitHub tag 2.2.3.600, published 2026-09-27 at 07:48 UTC as an emergency release, rolls the chain back to height 3833000 (timestamped 2026-08-26 15:50 UTC) and turns on hard fork 7 at that height. This Zano rollback is not a quiet daemon patch. Nodes that install the tag are choosing a new canonical history.
Bitcoin did not need a rewrite overnight. The desk CoinGecko snapshot had bitcoin at $83,922 as of 2026-09-28 01:45:14 UTC, with ether at $2,669.07. Coinbase BTC-USD last traded near $83,583.85 at 2026-09-28 02:07:37 UTC, with the venue 24-hour high still $85,158.50 and the low $83,453.32. That tape is a range, not a venue outage. The live event is on a smaller privacy chain, and it is about who still owns what after operators press install.
What happened
The 2.2.3.600 notes are blunt. The tag is labeled an emergency release meant to address a recent attack affecting the supply of Zano’s native coin and assets. It rolls the blockchain back to height 3833000. “All transaction in the previous chain after that point will no longer be part of the chain followed by this release,” the notes say, grammar included. The maintainers tell operators to review the changes before deploying, because installing means adopting both the rollback and the HF7 protocol changes in that announcement.
HF7 is not a slogan in the changelog. It activates at height 3833000 and temporarily disables gateway addresses. Predownload mainnet snapshots are updated to that same height. The release resets local p2p peer-list storage so nodes rediscover peers after the upgrade. The blockchain database folder changes to v4, and the previous v3 database is removed on upgrade, which triggers a resync. Wallet files bump to version 172. RPC getinfo now returns the daemon version. Builds are listed with SHA-256 hashes and a PGP-signed payload pointing at binaries on build.zano.org, plus a link to Zano’s own download verification docs.
That is a social fork with a software installer. Miners, stakers, exchanges, and anyone else running a node have to move together, or they do not share a ledger. The notes do not name a dollar figure for minted coins, do not name a second asset ticker, and do not publish a post-mortem. We are not filling those blanks from outlet recaps. The primary says supply of the native coin and assets was affected, gateway addresses are temporarily off, and history after 3833000 on the prior chain is discarded for nodes that follow this tag.
The public explorer already shows the new client in production. A reading of explorer.zano.org/api/get_info at 2026-09-28 02:11:38 UTC returned status OK, height 3835003, database height 3835002, version 2.2.3.600[e53cc8b], and last block hash ddd605256addbbde83d2d15a1a1049bf4445007c0b8cfb59926fa5206966deb1. The misspelled is_hardfok_active array was eight true values. Height 3835003 is 2,003 blocks past the rollback target. That is not proof every venue has upgraded. It is proof a 2.2.3.600-labeled explorer view is building on top of 3833000 instead of sitting on the discarded month.
Context
Gateway addresses were not invented in the emergency tag. The prior release, 2.2.2.513, published 2026-09-20 at 00:45 UTC, called itself a maintenance and hardening release on top of HF6. It listed continued gateway-address work: transactions validated before signing and relay, client-side history decryption, and richer gateway RPC. It also recorded an HF6-specific fix in generate_asset_surjection_proof_hf6() when a gateway output precedes a confidential output. Read those two tags in order and the picture is simple. HF6 shipped gateway accounts for services that did not want to live in raw outputs. Nine days later the emergency client turns those addresses off at the rollback height.
A rollback of this size is not a one-block reorg that traders shrug off. It is closer to a coordinated history cut. Anyone who received Zano, staked, traded an issued asset, or used a bridge during the discarded window now depends on whether their counterparty followed the new snapshot. Payments that already left Zano for another chain cannot be pulled back by a Zano installer. The GitHub text does not claim they can.
This is also why market structure matters more than the marketing line about privacy. Privacy chains sell the idea that the ledger is hard to seize and hard to rewrite. An emergency HF that deletes a month is the opposite trade: operators accept a rewrite to defend a supply cap. Ethereum’s documented upgrade path is slower and louder, which is why our ethereum history page is a useful contrast, not a price target. Zano is asking node operators to resync a v4 database and to treat old v3 files as trash.
If major listing venues pause deposits until they share height 3833000-plus, float gets trapped on the wrong history. If they credit balances from the discarded chain, they eat the inventory risk. Your claim is only as good as the operator’s chosen software. For a reminder of how easy it is to confuse a press write-up with a primary, use the desk guide on how to follow crypto news without getting played. Start with the GitHub tag, then the explorer reading, then the venues. Related desk coverage sits in blockchain news when a client, a court, or a filing actually moves the rails. This hour that rail is Zano’s signed installer, not bitcoin’s $84k handle.
Our read
Our stance: 2.2.3.600 is a coordination fork sold as an emergency supply repair. It may be the least-bad option for people who want the pre-attack cap back. It is still a rewrite. Holders who treated Zano finality as “once it is in a block, it stays” just learned the social layer can drop a month if enough operators agree. Narrative about unstoppable private money is cheap. Exit liquidity after a forced resync is not.
I am not going to pretend we measured the stolen float. The primary did not publish that number. I also will not dress HF7 up as a completed security audit. Gateway addresses are “temporarily” disabled, which is a live protocol flag, not a closed incident report.
Falsifiable claim: by 2026-10-12 23:59 UTC, either (a) a later non-prerelease tag on hyle-team/zano withdraws the height-3833000 rollback and tells operators to follow the pre-2.2.3.600 history, or (b) explorer.zano.org get_info reports a mainnet height below 3833000 while still advertising version 2.2.3.600. If (a) or (b) happens, the rollback did not become the live chain and this read is wrong. If the explorer stays above 3833000 on a 2.2.3.600-family daemon and no later tag restores the discarded month, the coordination fork stuck.
What to watch next
First, signed follow-up tags. We need a post-mortem in the same place the installer shipped: GitHub. Watch whether gateway addresses stay disabled, get a tighter spec, or quietly return in a minor bump without supply math.
Second, explorer and peer counts. Height climbing on 2.2.3.600 is necessary. It is not sufficient. If a competing daemon keeps serving the discarded month, deposits and withdrawals become a guess. Hashrate fields on the explorer JSON can wobble. Treat them as a dashboard, not a census of every staker.
Third, venue notices. A listing exchange that has not paused Zano funding while it resyncs to v4 is either already on the new history or is about to learn about support tickets the hard way. We will believe the status page and the GitHub tag over a screenshot thread.
Fourth, wallet users. Version 172 is a file-format bump. People who restore old files onto new binaries should expect friction. That is an operations story, not a reason to dump bitcoin. The BTC range is still the bitcoin story. The Zano rollback story tonight is whether operators actually share height 3833000.