Particle.news
Download on the App Store

Litecoin Details MWEB Flaw That Forged 85,034 LTC and Led to 13-Block Invalid Chain

The disclosure highlights urgent upgrade needs for miners, nodes, and services.

Overview

  • A 13-block invalid chain was dropped after an exploit attempt on Saturday, April 25, with f2pool and other upgraded miners keeping work on the valid chain.
  • The issue stemmed from MWEB, a privacy add-on that lets users move coins into a side block, where a missing check let input metadata misstate the real value being spent.
  • In March 2026, an attacker used that gap to create a peg-out of 85,034.47285734 LTC from an input worth no more than 1.2084693 LTC.
  • Developers coordinated emergency releases with mining pools, froze the attacker’s outputs, secured a signed return minus an 850 LTC bounty, and pegged the funds back into MWEB with the rebalancing output frozen.
  • Litecoin Core 0.21.5.4 removes stored mutated block data and restores normal block acceptance, and third-party services such as NEAR Intents and THORChain are now tallying losses from swaps that disappeared in the reorg.