Litecoin Hack
What happened
On April 25-26, 2026, Litecoin experienced an exploit-triggered denial-of-service and 13-block reorganization involving its Mimblewimble Extension Block (MWEB) privacy layer. The invalid chain was later reorged out; Litecoin's post-mortem says the April event did not establish a final third-party loss amount.
The MWEB validation path did not fully revalidate supplied input metadata against the actual MWEB UTXO, allowing inflated peg-out data; the later rejection path also mishandled mutated block data and could block normal mining operations.
How it happened
A malformed MWEB input could make an invalid peg-out appear to carry more value than the underlying UTXO. In April, updated mining nodes rejected the malformed block but mutated-block handling could hang block-submission RPCs, while unupdated miners extended the invalid chain until coordinated recovery overtook it.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.