Close Menu
    What's Hot

    Gate 预测市场名义交易量跃居全网第一,世界杯赛事持续带动市场热度 – BitRss – Crypto World News

    June 14, 2026

    Kalshi、Polymarket 等预测市场平台联合起诉肯塔基州 14.25% 交易税

    June 14, 2026

    Catcher Predict:“巴西对摩洛哥” 巨鲸单笔 128,366.1 美元买入 “平局(巴西对摩洛哥)” – BitRss

    June 13, 2026
    Facebook X (Twitter) Instagram
    memecoinelinator.com
    • Home
    • Bitcoin
    • Crypto News
    memecoinelinator.com
    Home»Bitcoin»Litecoin’s 13-block reorg wasn’t a zero-day, GitHub commit history shows otherwise
    Bitcoin

    Litecoin’s 13-block reorg wasn’t a zero-day, GitHub commit history shows otherwise

    April 26, 2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A 13-block chain reorganization on LTC$56.21 late Friday and Saturday rewound roughly 32 minutes of network activity after attackers used a vulnerability in its Mimblewimble Extension Block (MWEB) protocol.

    The bug had enabled a denial-of-service attack against major mining pools, allowing the invalid MWEB transactions to slip through nodes that had not updated, before the network’s longest valid chain corrected them.

    The Foundation said in Asian morning hours on Sunday the bug was fully patched and the network is operating normally.

    However, prominent researchers say the litecoin-project GitHub repository tells a different story. Security researcher bbsz, who works with the SEAL911 emergency response group for crypto exploits, posted the patch timeline pulled from the public commit log.

    Now that stuff has been made public on the Litecoin GitHub, we have a better sense of timeline and what happened.

    In the age of Mythos, this timeline simply doesn’t fly.

    The post-mortem says one zero-day caused a DoS that let an invalid MWEB tx slip through. The git log on… https://t.co/zMMrheQLPP pic.twitter.com/O3DtdwV0rF

    — bbsz (@blackbigswan) April 26, 2026

    The consensus vulnerability that allowed the invalid MWEB peg-out was privately patched between March 19 and March 26, roughly four weeks before the attack. A separate denial-of-service vulnerability was patched on the morning of April 25.

    Both fixes were rolled into release 0.21.5.4 the same afternoon, after the attack had already begun.

    “The post-mortem says one zero-day caused a DoS that let an invalid MWEB transaction slip through,” bbsz wrote. “The git log tells a slightly different story.”

    A zero-day refers to a vulnerability unknown to defenders at the time of an attack.

    Litecoin’s commit history shows the consensus vulnerability was known and patched privately a month before the exploit, but the fix had not been broadcast publicly or required to all mining pools.

    That created a window where some miners ran the patched code while others ran the still-vulnerable version, and the attackers appear to have known which was which.

    Alex Shevchenko, CTO of NEAR Foundation’s Aurora project, raised parallel concerns in a thread.

    Blockchain data showed the attacker pre-funded a wallet 38 hours before the exploit through a Binance withdrawal, with the destination address already configured to swap LTC into ETH on a decentralized exchange.

    The denial-of-service attack and the MWEB bug were separate components, Shevchenko argued, with the DoS designed to take patched mining nodes offline so the unpatched ones would form the chain that included the invalid transactions.

    The fact that the network automatically handled the 13-block reorganization once the DoS stopped suggests enough hashrate was running updated code to eventually overpower the attack, but only after the unpatched fork had run for 32 minutes.

    A hit on Litecoin shows how attacks on various networks differ in how code maintainers and developers react to exploits. Newer chains with smaller, more centralized validator sets coordinate upgrades through chat groups and can push patches network-wide in hours.

    Older proof-of-work networks like Litecoin and bitcoin rely on independent mining pools choosing when to upgrade, which works for non-urgent changes but creates a window of vulnerability when a security patch needs to reach everyone before an attacker exploits the gap.

    The Litecoin Foundation has not publicly addressed the GitHub timeline as of Sunday morning.

    The amount of LTC pegged out during the invalid block window and the value of any swaps completed before the reorganization reversed them have not been disclosed.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Brazil’s central bank bans stablecoin and crypto settlement in cross-border payments

    May 2, 2026

    Bitcoin Price Yet To Bottom Based On MVRV Bands — $43K Still Possible?

    May 2, 2026

    A16z Backs CFTC in Fight Against State Prediction Market Bans

    May 2, 2026

    Prediction markets are ditching the ‘casino’ label to become a regular part of how people track the news

    May 2, 2026
    Add A Comment

    Comments are closed.

    Latest News

    Gate 预测市场名义交易量跃居全网第一,世界杯赛事持续带动市场热度 – BitRss – Crypto World News

    June 14, 2026

    Kalshi、Polymarket 等预测市场平台联合起诉肯塔基州 14.25% 交易税

    June 14, 2026

    Catcher Predict:“巴西对摩洛哥” 巨鲸单笔 128,366.1 美元买入 “平局(巴西对摩洛哥)” – BitRss

    June 13, 2026

    数据:若 ETH 跌破 1,597 美元,主流 CEX 累计多单清算强度将达 5.2 亿美元 – BitRss

    June 13, 2026

    数据:过去 24 小时全网爆仓 1.24 亿美元,主爆多单 – BitRss

    June 13, 2026
    • Home
    • Bitcoin
    • Crypto News
    © 2026 Memecoineliminator.com.

    Type above and press Enter to search. Press Esc to cancel.