Litecoin Hack

Reported loss Not disclosed
Litecoin (Mweb)
Consensus Validation Flaw

What happened

On April 25-26, 2026, Litecoin experienced an exploit-triggered denial-of-service and 13-block reorganization involving its Mimblewimble Extension Block (MWEB) privacy layer. The invalid chain was later reorged out; Litecoin's post-mortem says the April event did not establish a final third-party loss amount.

Technical root cause

The MWEB validation path did not fully revalidate supplied input metadata against the actual MWEB UTXO, allowing inflated peg-out data; the later rejection path also mishandled mutated block data and could block normal mining operations.

How it happened

A malformed MWEB input could make an invalid peg-out appear to carry more value than the underlying UTXO. In April, updated mining nodes rejected the malformed block but mutated-block handling could hang block-submission RPCs, while unupdated miners extended the invalid chain until coordinated recovery overtook it.

Protocol details

Classification Input Validation
Protocol Type Chain
Implementation language C++
Protocol links Website @LTCFoundation

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.