Litecoin MWEB Zero-Day Triggered 13-Block Reorg After Invalid Transactions Passed Old Nodes

Litecoin MWEB Zero-Day Triggered 13-Block Reorg After Invalid Transactions Passed Old Nodes

N
News Editor 01
2026-07-23 16:20:16
Litecoin said a zero-day flaw in MWEB let outdated mining nodes accept malformed transactions, creating a temporary validation split. The network later carried out a 13-block reorganization and deployed a patch.
LitecoinMWEBchain-reorgzero-dayproof-of-work

Litecoin said a zero-day flaw in MWEB briefly disrupted the network after outdated mining nodes accepted malformed transactions that should have failed validation. During that window, invalid peg-out activity moved toward third-party decentralized exchanges. A patch has since been deployed, and Litecoin said normal operations were restored.

Outdated miners accepted malformed transactions while updated nodes rejected them

According to the Litecoin team, the incident started when older mining nodes failed to properly validate a malformed MWEB transaction. Those nodes processed transfers that updated software would not accept. The result was a temporary validation split across the network, with different parts of the system reaching different conclusions on the same activity.

The exploit also included a denial-of-service attack. That attack disabled certain nodes and reduced active hash power, making the exploit more effective during the incident window. Litecoin said this was not a majority-hash takeover. Its explanation was that the disruption came from a protocol flaw used at the right moment, not from a direct seizure of network control.

Litecoin removed invalid activity with a 13-block chain reorganization

To contain the issue, Litecoin carried out a 13-block reorganization. The rollback removed all invalid transactions from the main chain. The team said valid transactions from the same period were preserved, so legitimate network activity remained intact while the malformed transfers were stripped out.

The unusual activity covered blocks 3095930 through 3095943. Mining those blocks took more than three hours, far above the expected 30-minute window. That delay led some analysts to compare the pattern to a 51% attack, but Litecoin rejected that framing and said the event was tied to the bug rather than a hash-power takeover.

Disclosure timing and uneven protection drew criticism

Alex Shevchenko and Zacodil were among the first to flag the unusual mining delays. Shevchenko said the attacker appeared to be prepared ahead of time and added that funds linked to the exploit had been traced to Binance 38 hours earlier.

The report also said developers had identified related vulnerabilities weeks before public disclosure and had patched them privately. Critics argued that this left participants with uneven protection across the network: updated operators could reject the malformed transactions, while older nodes remained exposed. An XRP Ledger validator known as Vet also used the episode to criticize proof-of-work security, saying network safety depends on sufficient hash power to make attacks costly, while also noting that this case did not involve a majority hash attack.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.