Tuesday, April 28, 2026
No Result
View All Result
Coins League
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis
No Result
View All Result
Coins League
No Result
View All Result

MWEB Bug Let Attacker Fake 85,034 LTC Pegout Before Devs Froze Funds

April 28, 2026
in Bitcoin
Reading Time: 3 mins read
0 0
A A
0
Home Bitcoin
Share on FacebookShare on TwitterShare on E Mail


Key Takeaways:

A Litecoin MWEB validation bug let an attacker inflate and peg out 85,034 LTC in March 2026, however the actor returned the funds for an 850 LTC bounty. An April 2026 exploit try triggered a 13-block chain reorg, inflicting NEAR Intents to lose 11,000 LTC swapped for 7.78 BTC. Litecoin Core v0.21.5.4 patches each the inflation bug and the mining node stall that enabled the April reorg.

Litecoin Builders Launch Postmortem After MWEB Bug Causes Chain Reorg

The postmortem recognized the basis trigger as a lacking metadata test throughout block connection. When an MWEB enter spends a earlier output, the metadata it carries should match the precise UTXO being consumed. That test existed within the mempool and block-building paths, however builders confirmed it was not totally enforced on the block connection stage.

Builders found the vulnerability by way of inside assessment on March 19. A sequence scan confirmed exploitation had already occurred at block 3,073,882. The attacker used a malicious MWEB enter whose actual worth was not more than 1.2084693 LTC to help a pegout of 85,034.47285734 LTC.

Builders stated they coordinated privately with main mining swimming pools to comprise the inflated outputs earlier than public disclosure. An emergency launch, Litecoin Core 0.21.5, was pushed to miners to dam new malformed inputs. A follow-up launch, 0.21.5.1, added a historic exception for the already-accepted exploit block and quickly froze the three clear outpoints holding the attacker’s funds.

The actor tried to spend at the very least one frozen output. Upgraded miners rejected the transaction. Builders then contacted the actor straight. The actor agreed to cooperate and signed a restoration transaction that returned 84,184.47278630 LTC to a developer-controlled tackle whereas preserving 850 LTC as an agreed bounty.

Litecoin founder, Charlie Lee, bought the 850 LTC wanted to make the MWEB steadiness entire. The complete 85,034.47285734 LTC was pegged again into MWEB in a single transaction at block peak 3,078,098, and the ensuing MWEB output was frozen. No consumer funds had been in the end misplaced within the March incident.

In line with the postmortem, a second attacker tried the identical exploit path in April, triggering a separate failure. Upgraded nodes rejected the malformed block, however the way in which mutated MWEB block information was dealt with triggered sure mining RPC instructions to hold, together with the submitblock name. Upgraded mining nodes stalled whereas unupgraded miners continued extending the invalid chain.

The invalid chain grew to 13 blocks earlier than upgraded miners coordinated to overhaul it. The unhealthy chain was reorged out, however a number of third-party techniques had already processed exercise on the invalid chain earlier than the reorg accomplished.

NEAR Intents confirmed the attacker swapped 11,000 LTC for 7.78814476 BTC earlier than the reorg accomplished. These 11,000 LTC had been not current on the legitimate chain after the reorg, leaving NEAR Intents with a confirmed loss. Thorchain reported a separate loss after the attacker swapped 10 LTC for 0.00719957 BTC by way of its bridge earlier than the reorg.

Litecoin Core 0.21.5.4 addressed the mutated-block stall by erasing saved block information for blocks categorised as mutated, permitting legitimate information for a similar block hash to be accepted later. The discharge was constructed and deployed publicly on April 25.

The postmortem blogpost acknowledged a number of failures within the response, together with that MWEB validation relied too closely on checks that weren’t utilized at block connection, that the restoration required a number of staged miner releases every carrying coordination threat, and that the April mutated-block failure mode had not been examined in opposition to mining RPC habits.

Group sentiment following the postmortem X submit was largely supportive, with roughly 70% to 80% of replies citing appreciation for the crew’s transparency and pace. A number of responses famous that the chain itself held agency and that public disclosure constructed somewhat than broken belief.

Customers and node operators are suggested to improve to Litecoin Core v0.21.5.4 or later, confirm that their node is syncing usually, and reindex if the node stays caught after a restart. The postmortem follows Litecoin’s latest submit about doing higher in terms of posting on X. “These in control of posting from this [X] deal with will do higher sooner or later,” the official Litecoin X account wrote after the account was accused of being “infantile” earlier within the week.



Source link

Tags: AttackerBugDevsfakefrozeFundsLTCMWEBPegout
Previous Post

Israel’s foreign ministry accuses Venice Biennale’s jury of ‘politicising’ exhibition – The Art Newspaper

Related Posts

Colombia Bitcoin: Largest Pension Fund Adds BTC Exposure
Bitcoin

Colombia Bitcoin: Largest Pension Fund Adds BTC Exposure

April 28, 2026
Cardano Founder Draws ‘Red Lines’ In Feud With Iagon
Bitcoin

Cardano Founder Draws ‘Red Lines’ In Feud With Iagon

April 28, 2026
Ethereum Price Drops Below $2,350, Recovery Hopes Start To Fade
Bitcoin

Ethereum Price Drops Below $2,350, Recovery Hopes Start To Fade

April 28, 2026
Senate Democrats Warn SEC Crypto Exemptions May Undermine Investor Protections
Bitcoin

Senate Democrats Warn SEC Crypto Exemptions May Undermine Investor Protections

April 28, 2026
Be Scared If You Don’t Own Bitcoin
Bitcoin

Be Scared If You Don’t Own Bitcoin

April 28, 2026
Russia Crypto Sanctions Set to be Tightened by the EU
Bitcoin

Russia Crypto Sanctions Set to be Tightened by the EU

April 27, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Twitter Instagram LinkedIn RSS Telegram
Coins League

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at Coins League

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITEMAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 Coins League.
Coins League is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis

Copyright © 2023 Coins League.
Coins League is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In