Litecoin rolls back 13 blocks after MWEB exploit

Litecoin rolled back 13 blocks after a zero-day bug in its MWEB privacy layer enabled double-spend attacks and unauthorized peg-outs. The flaw was patched, some losses occurred, and the network is now stable.

Litecoin faced a major disruption when attackers exploited a zero-day vulnerability in its MimbleWimble Extension Block (MWEB) privacy layer. This flaw allowed outdated mining nodes to validate invalid MWEB transactions, enabling unauthorized peg-outs of coins to third-party decentralized exchanges. As a result, attackers executed double-spend attacks against several cross-chain protocols, with NEAR Intents reporting losses of around $600,000. The incident led to a 13-block chain reorganization, spanning blocks 3,095,930 to 3,095,943, which removed the invalid transactions while preserving legitimate ones. During the event, major mining pools suffered denial-of-service attacks, significantly slowing block production. The Litecoin Foundation confirmed the vulnerability has been fully patched and the network is stable, though some trading venues reported financial losses. The event sparked debate about a possible 51% attack due to the reorg's length, but it was clarified as a targeted response to the exploit. LTC's price dipped only slightly after the incident.

Related Tokens

Related News