Litecoin Attack: Researchers Challenge 'Zero-Day' Claim with GitHub Proof

TECH
Whalesbook Logo
AuthorAarav Shah|Published at:
Litecoin Attack: Researchers Challenge 'Zero-Day' Claim with GitHub Proof
Overview

Litecoin's network experienced a 13-block reorganization, undoing 32 minutes of activity, after an exploit targeted its MWEB protocol. The attack caused a denial-of-service on mining pools. The Litecoin Foundation said the issue is fixed and the network is stable. However, security researchers cite GitHub data showing the vulnerability was privately patched weeks before the attack, challenging the foundation's "zero-day" claim.

Instant Stock Alerts on WhatsApp

Used by 10,000+ active investors

1

Add Stocks

Select the stocks you want to track in real time.

2

Get Alerts on WhatsApp

Receive instant updates directly to WhatsApp.

  • Quarterly Results
  • Concall Announcements
  • New Orders & Big Deals
  • Capex Announcements
  • Bulk Deals
  • And much more

The Exploit and the Dispute Over 'Zero-Day' Status

The Litecoin Foundation stated that a recent 13-block chain reorganization, which rolled back approximately 32 minutes of network activity, was not the result of a "zero-day" vulnerability. However, researchers analyzing public GitHub commits found evidence suggesting a more complex timeline.

Researchers Cite GitHub Activity

Security researcher bbsz showed GitHub logs indicating a critical consensus vulnerability was privately patched between March 19 and March 26, weeks before the exploit occurred. This flaw let invalid MWEB transactions be sent.

Two Vulnerabilities, One Attack

A separate denial-of-service (DoS) flaw was fixed on April 25, the same day the attack began. Both fixes were in Litecoin Core v0.21.5.4, released that afternoon. A zero-day exploit is a flaw unknown to developers when it's used. The key disagreement is that the consensus bug was privately patched weeks earlier but not publicly disclosed or required for mining pools to adopt.

Attack Strategy and Network Recovery

Alex Shevchenko, CTO of NEAR Foundation's Aurora project, explained the attack. Data suggests the attacker funded a wallet and prepared to swap Litecoin (LTC) for Ether (ETH) 38 hours before the attack. Shevchenko believes the DoS flaw was used to disable mining nodes that had applied the patch, letting unpatched nodes process invalid transactions. The network naturally corrected itself with a 13-block reorganization, showing enough updated mining power was running to overcome the attack.

Challenges for Proof-of-Work Networks

Unlike newer blockchains, older proof-of-work networks like Litecoin require independent mining pools to voluntarily adopt patches. This decentralized approach leaves security gaps. The Litecoin Foundation has not yet commented on the detailed GitHub timeline. The amount of Litecoin affected and the value of any illicit exchanges are still unknown.

Get stock alerts instantly on WhatsApp

Quarterly results, bulk deals, concall updates and major announcements delivered in real time.

Disclaimer:This content is for educational and informational purposes only and does not constitute investment, financial, or trading advice, nor a recommendation to buy or sell any securities. Readers should consult a SEBI-registered advisor before making investment decisions, as markets involve risk and past performance does not guarantee future results. The publisher and authors accept no liability for any losses. Some content may be AI-generated and may contain errors; accuracy and completeness are not guaranteed. Views expressed do not reflect the publication’s editorial stance.