Litecoin Network Patches Zero-Day Bug After Exploit
- On April 25, a zero-day bug affected major Litecoin mining pools, allowing invalid MWEB transactions via non-updated nodes.
- A network response led to a 13-block reorganization that reversed these invalid transactions.
- The Litecoin team confirmed all valid transactions were unaffected and the bug has been fully patched.
- NEAR Intents initially reported $600K in exposure but actual losses are likely lower after the invalid transactions were removed.
- The incident highlights vulnerabilities in proof-of-work networks running older software versions, as noted by Zcash founder Zooko Wilcox.
A zero-day bug in the Litecoin network allowed attackers to exploit non-updated nodes, leading to invalid MWEB transactions pegged out to DEX platforms. The network’s corrective action involved a reorganization of blocks to remove these fraudulent transactions, ensuring the safety of all valid operations during this period.
Despite initial concerns about potential losses up to $600K reported by NEAR Intents, the removal of invalid transactions suggests lower actual losses. This event underscores the importance of maintaining updated software on proof-of-work networks to prevent similar exploits in the future. (Source)