Litecoin Zero-Day Exploit: 13-Block Reorg, NEAR Intents $600K at Risk, v0.21.5.4 Emergency Patch

Litecoin Zero-Day Exploit: 13-Block Reorg, NEAR Intents $600K at Risk, v0.21.5.4 Emergency Patch

N
News Editor 01
2026-07-22 15:10:14
Litecoin network saw a 13-block reorg on the 25th due to an MWEB input validation bug, putting $600K of NEAR Intents assets at risk. Developers rushed out v0.21.5.4 and urged all nodes and wallets to upgrade.
LitecoinMWEBzero-day exploitblock reorgNEAR Intents

Litecoin's network experienced a security incident on the 25th: an input validation flaw in the MimbleWimble Extension Blocks (MWEB) protocol triggered a continuous 13-block reorg that lasted over three hours. Litecoin normally produces one block every 2.5 minutes.

Initial chain monitoring tools flagged unusual activity, leading some observers to suspect a 51% attack. Core developers later confirmed the root cause was a logic bug within the MWEB protocol, not external hash rate hijacking.

Root Cause: MWEB Kernel Sum Imbalance

According to Litecoin's official announcement, the vulnerability (commit 1dcbf3f) allowed the MWEB kernel sum to fall into an unbalanced state, breaking the integrity of MWEB input-output accounting. An attacker could exploit this to unlock MWEB coins and move them to a third-party decentralized exchange (DEX).

Developer Loshan stated in the release: "This release contains important security fixes and everyone should upgrade to this release ASAP."

Patch v0.21.5.4 includes multiple fixes: dual validation of input commitments and public keys for MWEB inputs (commit e7cbf1d); a fix for kernel fee integer overflow during MWEB transaction verification (42e7071); block data cleanup for mutated blocks to prevent miner DoS (742ee94); and miners no longer accepting MWEB transactions when input/output commitments sum to zero (f423a84).

NEAR Intents: $600K Exposed, Compensation Promised

NEAR Intents disclosed that the reorg exposed roughly $600,000 in platform assets to potential risk. The protocol has pledged to compensate affected users and temporarily suspended LTC-related operations until network stability is confirmed.

The network resumed normal consensus later that day, and the vulnerabilities were fully patched with the release of v0.21.5.4.

MWEB Coverage Over 90%, Ecosystem Remains Stable

Since its launch in 2022, MWEB now boasts over 90% node support and holds total balances of 260,000 LTC, making it a core pillar of Litecoin's privacy features. This bug impacted ledger logic at the protocol layer and was not limited to specific wallets — all nodes running older versions were at risk.

Stability fixes in v0.21.5.4 also address: data corruption during PMMR rewind (23e5eac), MMR file write durability improvements, added MWEB view keys in wallet dumpwallet output, and Boost >= 1.78 compatibility.

LTC is currently trading around $56.26. In March, the SEC-CFTC joint framework classified LTC as a "digital commodity," with spot LTC ETFs seeing continued inflows; LitecoinVM zk-rollup testnet went live in early April. This security event was an unexpected protocol-layer incident, but the development team responded quickly, and the long-term ecosystem trajectory remains unchanged.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.