Aftermath of the attack: Litecoin (LTC) releases an update, other developers express skepticism about the "zero-day vulnerability" theory.
Cointelegraph
04-27 10:33

Litecoin, a Level 1 Proof-of-Work (PoW) blockchain network, suffered a zero-day vulnerability attack on Saturday, causing a reorganization of 13 blocks on the chain, the Litecoin team said, while other developers said the vulnerability may have been known beforehand.

According to an update from the Litecoin team, the vulnerability launched a denial-of-service (DoS) attack on mining pools running the newly updated software, suppressing their computing power.

The team stated that this allows older nodes to "peg out" tokens to decentralized exchanges and cross-chain exchange protocols, resulting in invalid transactions being written into the network's MimbleWimble Extension Blocks (MWEB) privacy layer.

The Litecoin team stated that the updated node eventually regained control of the network's hash power, executed a 13-block reorganization, and rolled back invalid transactions that would not appear on the main chain. The vulnerability has now been fully patched.

This incident comes at a time when the number of zero-day vulnerabilities is rising—vulnerabilities in code that software developers are unaware of at the time of product release but which can be exploited—as AI systems like Anthropic's Claude Mythos outperform humans in identifying such attack surfaces.

Some people may have known about the software vulnerability in advance.

According to Alex Shevchenko, co-founder of the Layer 2 scaling network Aurora.sayEarlier this week, a Binance address provided funds to the attacker, suggesting that the attack may have been pre-planned and that the attacker was aware of the code vulnerability beforehand. He said:

"The protocol automatically handled the reorganization after the DoS stopped, which is good, indicating that some computing power was actually running the updated code. Therefore, this vulnerability is known and is not a zero-day vulnerability."

Blockchain developer Vadim later stated, "The timing and target of the attack indicate that this was not a random opportunity." He added, "Low-hashrate layer-one networks are no longer secure collateral for cross-chain value."

Cross-chain bridges, responsible for transferring digital assets between different blockchain protocols, have long been a major attack surface in the crypto space, causing billions of dollars in losses over the years.

A recent high-profile cross-chain bridge vulnerability case was the attack on the Kelp restaking protocol on April 18, which resulted in the platform losing approximately $293 million earlier this month.

Tip
$0
Like
0
Save
0
Views 362
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Defend Developers formed the PAC to lobby for the Clarity Act to protect developers.
Defend Developers formed the PAC to push for developer protection provisions in the CLARITY Act, while the Senate is still negotiating related content.
Cryptonews
·2026-06-04 00:36:57
483
Foreign media: Author of the "barrel theory" discusses Bitcoin pullback
Amid a Bitcoin pullback, Robert Kiyosaki reiterated his bullish stance on Bitcoin, Ethereum, and precious metals, emphasizing that investors should pay attention to fund flows and make their own judgments.
U.Today
·2026-05-31 19:42:41
420
Zcash initiates emergency protocol upgrade due to Orchard vulnerability.
Zcash has initiated an emergency upgrade due to an Orchard vulnerability, temporarily suspending related transactions, while other network functions remain normal.
AMBCrypto
·2026-06-02 22:25:30
669
Trezor discloses vulnerability in Safe 7 chip: claims user assets unaffected
Trezor claims that the chip used in Safe 7 has a lab-level vulnerability, but user assets are not affected.
CoinDesk
·2026-06-03 18:15:35
269
Meta fixes AI customer service vulnerability after Instagram account was compromised.
Meta has patched a security vulnerability on Instagram that allowed attackers to reset passwords and take over some accounts using an AI-powered chatbot.
TechCrunch
·2026-06-02 02:44:09
431