A critical zero-day in Litecoin’s MimbleWimble Extension Block (MWEB) transaction handling was actively exploited to launch a denial-of-service attack that disrupted major mining pools, caused some unpatched nodes to accept malformed or invalid transactions, and temporarily affected transaction finality and mining operations. Reports said the flaw stemmed from an input-validation failure in MWEB processing, allowing attackers to inject invalid data and, in some cases, enable unauthorized peg-out activity tied to third-party decentralized exchanges.
Litecoin developers publicly confirmed the incident, issued a patch within hours, and coordinated a 13-block chain reorganization to remove illegitimate transactions and restore chain integrity. The team said legitimate transactions remained valid overall, some transactions in reorganized blocks were reversed, and users and exchanges were not expected to lose funds. The incident highlighted the operational risk of delayed patch adoption across proof-of-work infrastructure, particularly around newer privacy-related features such as MWEB.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Litecoin publicly confirmed the bug, fully patched the vulnerability within hours of the incident, and instructed node operators and mining pool administrators to upgrade immediately. The team stated that users and exchanges were not expected to lose funds and that no funds were lost.
In response to the attack, Litecoin developers and network stakeholders carried out a 13-block chain reorganization to remove the illegitimate MWEB transactions and restore chain integrity. Some transactions in the reorganized blocks were reversed, but the team said legitimate transactions remained valid.
Attackers exploited a zero-day input validation flaw in Litecoin's MimbleWimble Extension Block transaction handling, injecting malformed transactions that some unpatched nodes and major mining pools accepted. The incident disrupted mining operations, affected transaction finality, and enabled illegitimate peg-out activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.