Litecoin zero-day DoS exploit allowed invalid MWEB transactions to peg coins to external DEXs; a 13-block reorg reversed the attack.
Security & Exploits ·
A zero-day bug in Litecoin triggered a denial-of-service attack affecting major mining pools, according to an update from the project. Non-updated mining nodes processed an invalid MWEB transaction that enabled coins to be pegged out to third-party decentralized exchanges. The network responded with a 13-block reorg that reversed the invalid transactions, preventing their inclusion in the main chain while preserving all valid transactions from the same period.
The patch has been deployed and the network is operating normally. Transactions processed during the attack window that were valid remain unaffected by the reorg. No additional details have been disclosed about the specific mechanics of the vulnerability or the scope of coins involved in the peg-out attempts.