Litecoin said a zero-day flaw in MWEB briefly disrupted the network after outdated mining nodes accepted malformed transactions that should have failed validation. During that window, invalid peg-out activity moved toward third-party decentralized exchanges. A patch has since been deployed, and Litecoin said normal operations were restored.
Outdated miners accepted malformed transactions while updated nodes rejected them
According to the Litecoin team, the incident started when older mining nodes failed to properly validate a malformed MWEB transaction. Those nodes processed transfers that updated software would not accept. The result was a temporary validation split across the network, with different parts of the system reaching different conclusions on the same activity.
The exploit also included a denial-of-service attack. That attack disabled certain nodes and reduced active hash power, making the exploit more effective during the incident window. Litecoin said this was not a majority-hash takeover. Its explanation was that the disruption came from a protocol flaw used at the right moment, not from a direct seizure of network control.
Litecoin removed invalid activity with a 13-block chain reorganization
To contain the issue, Litecoin carried out a 13-block reorganization. The rollback removed all invalid transactions from the main chain. The team said valid transactions from the same period were preserved, so legitimate network activity remained intact while the malformed transfers were stripped out.
The unusual activity covered blocks 3095930 through 3095943. Mining those blocks took more than three hours, far above the expected 30-minute window. That delay led some analysts to compare the pattern to a 51% attack, but Litecoin rejected that framing and said the event was tied to the bug rather than a hash-power takeover.
Disclosure timing and uneven protection drew criticism
Alex Shevchenko and Zacodil were among the first to flag the unusual mining delays. Shevchenko said the attacker appeared to be prepared ahead of time and added that funds linked to the exploit had been traced to Binance 38 hours earlier.
The report also said developers had identified related vulnerabilities weeks before public disclosure and had patched them privately. Critics argued that this left participants with uneven protection across the network: updated operators could reject the malformed transactions, while older nodes remained exposed. An XRP Ledger validator known as Vet also used the episode to criticize proof-of-work security, saying network safety depends on sufficient hash power to make attacks costly, while also noting that this case did not involve a majority hash attack.

