Zano has warned users that a fake wallet website is distributing a Windows installer containing a remote-access trojan capable of capturing passwords, wallet recovery phrases, keystrokes, screen activity, microphone input and webcam data.
The project identified the domain as zanowallet[.]io and said it is not affiliated with Zano. According to the official security warning, a community member discovered that the website was offering software designed to look similar to the legitimate Zano wallet while installing a remote-access trojan, or RAT, when executed.
The attack is more serious than a conventional phishing page that simply asks users to enter a recovery phrase. Once installed, remote-access malware can potentially observe activity elsewhere on the infected computer. A wallet password typed into a legitimate application could be recorded through keystrokes, while a recovery phrase displayed on screen could potentially be captured through screen monitoring.
Zano is telling anyone who executed the installer to assume the computer is fully compromised. Its guidance is to use a separate clean device to create a new wallet with a new seed phrase, move funds immediately, change important passwords from the clean device and wipe and reinstall the infected operating system.
The Fake Wallet Appeared at the Worst Possible Time
The warning comes during an unusually sensitive period for the Zano ecosystem.
Zano’s core team has separately disclosed a serious vulnerability involving the public Gateway Addresses introduced with Hard Fork 6. According to the project, the flaw enabled unauthorized ZANO and fUSD to enter circulation, although it says ordinary wallet spend keys, transaction privacy and the core consensus mechanism were not compromised.
The response has gone well beyond a routine software patch. Zano said the blockchain has been restarted from block height 3,833,000, immediately before Hard Fork 6, affecting approximately one month of chain history. Transactions confirmed during that period are not part of the recovered chain, and users have been told to update their software and verify transaction status before resending payments.
A new emergency release, version 2.2.3.600, has been published as part of the recovery effort. Nodes, miners, stakers, exchanges, bridges and other services must migrate to the recovered chain, while Zano is bringing services back online individually.
That creates an unusually effective social-engineering opportunity. Users who know that a real emergency upgrade is underway have a legitimate reason to search for a new wallet installer. A convincing clone site does not have to manufacture urgency from scratch; the network incident has already created it.
This mirrors a broader pattern in recent crypto impersonation attacks, where criminals exploit circumstances or channels that users already have reason to trust. The dangerous element is increasingly not an obviously absurd promise but a fraudulent instruction inserted into a genuine moment of uncertainty.
No Confirmed Evidence Yet Links the Site to Search Ads or Wallet Drains
One important question remains unresolved: how users are finding the fake wallet.
Zano specifically advised users to type zano.org directly or use a bookmark and warned them not to trust search results or advertisements. That warning makes search-engine distribution an obvious area for investigation, but the project has not publicly said that zanowallet[.]io was discovered in a sponsored result.
No independently verified evidence located so far confirms paid search placement for the domain. That distinction matters because malicious sponsored results can dramatically increase exposure by placing a fraudulent download above an organic project page, particularly during periods when users are urgently searching for software updates.
There is also no verified public figure for funds stolen through the malicious installer. Zano’s alert describes the malware capabilities and remediation steps but does not identify drained wallets or publish a total victim-loss estimate.
Until wallet addresses, victim reports or forensic data emerge, claims about the amount stolen would be speculation.
The lack of a disclosed loss figure does not reduce the severity of the threat. A RAT can expose far more than one cryptocurrency wallet. Password managers, exchange sessions, email accounts and other financial credentials accessible from an infected computer may all become relevant depending on what access the malware actually obtained.
A Seed Phrase Does Not Need to Be Entered Into a Fake Website to Be Stolen
This is the part of the incident that changes the risk model.
Crypto users have been trained for years to avoid typing a seed phrase into a website. That remains good advice, but it is not sufficient when the computer itself is compromised.
If an attacker controls the operating environment, the distinction between a legitimate wallet interface and a phishing page becomes much less useful. A seed phrase could be exposed when a user restores a wallet inside authentic software. A wallet password can be captured when the user unlocks an application. Clipboard contents, screenshots and other credentials may also become accessible depending on the malware’s capabilities.
The problem resembles the lesson from the recent D’CENT XRP wallet drain: once recovery credentials themselves may be compromised, simply moving funds while continuing to use the same seed does not solve the underlying problem. New key material must be generated in a trusted environment.
It also shows an important limitation of self-custody. Holding your own keys removes dependence on a centralized custodian, but it also moves the security boundary toward the device that stores and uses those keys. Self-custody protects against one class of counterparty risk while creating greater responsibility for endpoint security and software provenance.
The Emergency Upgrade Makes Software Provenance the Bigger Story
The overlap between the malicious wallet warning and Zano’s network recovery is what makes this incident particularly important.
Emergency upgrades compress decision-making. Users who would normally verify a domain, compare checksums and confirm a release through several official channels may instead be focused on getting their wallet working again as quickly as possible.
Attackers do not need to compromise Zano’s blockchain to exploit that behavior. They only need to position malicious software between the project and users searching for the update.
The financial industry has dealt with similar impersonation risks through clone websites, but cryptocurrency raises the stakes because successful credential theft can produce irreversible transactions within minutes. There may be no bank fraud desk capable of reversing a transfer once an attacker gains valid signing authority.
The next evidence worth watching is therefore distribution and victim impact.
If investigators establish that the domain was appearing in sponsored searches, the story expands from a malicious download to a distribution-platform problem. If wallet drains can be connected to machines that installed the software, the scale of the financial damage becomes measurable. Malware samples, command-and-control infrastructure and the installer’s digital signatures could also help establish whether the campaign is narrowly targeting Zano holders or belongs to a broader credential-stealing operation.
There is another complication: Zano’s chain recovery itself means users need to distinguish legitimate transaction discrepancies caused by the rollback from losses caused by malware. Transactions from roughly the affected month of chain history need to be reconciled on the recovered network, while an actual stolen wallet would represent an entirely different problem.
For now, the clearest distinction is also the most useful one. Zano says the emergency network upgrade does not require users to provide their seed phrase. Anyone being asked for one as part of an upgrade should treat that request as a critical warning sign.
And anyone who already ran the installer from zanowallet[.]io faces a different problem entirely: according to Zano, the safest assumption is that the device itself can no longer be trusted.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

