Litecoin’s 13-block reorg wasn’t a zero-day, GitHub commit historical past reveals in any other case

Litecoin’s 13-block reorg wasn’t a zero-day, GitHub commit historical past reveals in any other case

A 13-block chain reorganization on late Friday and Saturday rewound roughly 32 minutes of community exercise after attackers used a vulnerability in its Mimblewimble Extension Block (MWEB) protocol.

The bug had enabled a denial-of-service assault towards main mining swimming pools, permitting the invalid MWEB transactions to slide via nodes that had not up to date, earlier than the community’s longest legitimate chain corrected them.

The Basis mentioned in Asian morning hours on Sunday the bug was totally patched and the community is working usually.

Nevertheless, distinguished researchers say the litecoin-project GitHub repository tells a unique story. Safety researcher bbsz, who works with the SEAL911 emergency response group for crypto exploits, posted the patch timeline pulled from the general public commit log.

The consensus vulnerability that allowed the invalid MWEB peg-out was privately patched between March 19 and March 26, roughly 4 weeks earlier than the assault. A separate denial-of-service vulnerability was patched on the morning of April 25.

Each fixes have been rolled into launch 0.21.5.4 the identical afternoon, after the assault had already begun.

“The post-mortem says one zero-day caused a DoS that let an invalid MWEB transaction slip through,” bbsz wrote. “The git log tells a slightly different story.”

A zero-day refers to a vulnerability unknown to defenders on the time of an assault.

Litecoin’s commit historical past reveals the consensus vulnerability was identified and patched privately a month earlier than the exploit, however the repair had not been broadcast publicly or required to all mining swimming pools.

That created a window the place some miners ran the patched code whereas others ran the still-vulnerable model, and the attackers seem to have identified which was which.

Alex Shevchenko, CTO of NEAR Basis’s Aurora challenge, raised parallel issues in a thread.

Blockchain information confirmed the attacker pre-funded a pockets 38 hours earlier than the exploit via a Binance withdrawal, with the vacation spot tackle already configured to swap LTC into ETH on a decentralized alternate.

The denial-of-service assault and the MWEB bug have been separate elements, Shevchenko argued, with the DoS designed to take patched mining nodes offline so the unpatched ones would kind the chain that included the invalid transactions.

The truth that the community robotically dealt with the 13-block reorganization as soon as the DoS stopped suggests sufficient hashrate was operating up to date code to ultimately overpower the assault, however solely after the unpatched fork had run for 32 minutes.

A success on Litecoin reveals how assaults on varied networks differ in how code maintainers and builders react to exploits. Newer chains with smaller, extra centralized validator units coordinate upgrades via discussion groups and might push patches network-wide in hours.

Older proof-of-work networks like Litecoin and bitcoin depend on unbiased mining swimming pools selecting when to improve, which works for non-urgent adjustments however creates a window of vulnerability when a safety patch wants to achieve everybody earlier than an attacker exploits the hole.

The Litecoin Basis has not publicly addressed the GitHub timeline as of Sunday morning.

The quantity of LTC pegged out throughout the invalid block window and the worth of any swaps accomplished earlier than the reorganization reversed them haven’t been disclosed.

UPDATE (April 26, 11:04 UTC): Rewrites headline to deal with assault, treatment

Supply hyperlink

bitcoin
Bitcoin (BTC) $ 62,670.00 2.01%
ethereum
Ethereum (ETH) $ 1,665.33 3.56%
tether
Tether (USDT) $ 0.998829 0.01%
bnb
BNB (BNB) $ 577.52 2.03%
usd-coin
USDC (USDC) $ 0.999805 0.00%
xrp
XRP (XRP) $ 1.11 1.71%
solana
Solana (SOL) $ 69.63 3.17%
tron
TRON (TRX) $ 0.328923 1.38%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03 0.16%
staked-ether
Lido Staked Ether (STETH) $ 2,265.05 3.46%
hyperliquid
Hyperliquid (HYPE) $ 62.15 6.15%
dogecoin
Dogecoin (DOGE) $ 0.078841 4.32%
usds
USDS (USDS) $ 0.999673 0.00%
rain
Rain (RAIN) $ 0.015664 2.18%
leo-token
LEO Token (LEO) $ 9.54 0.41%
zcash
Zcash (ZEC) $ 415.97 5.94%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,779.67 3.22%
stellar
Stellar (XLM) $ 0.195085 3.70%
whitebit
WhiteBIT Coin (WBT) $ 51.03 2.24%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 76,243.00 3.12%
monero
Monero (XMR) $ 318.53 0.51%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762 0.02%
canton-network
Canton (CC) $ 0.151732 0.29%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,466.93 3.47%
chainlink
Chainlink (LINK) $ 7.63 2.98%
cardano
Cardano (ADA) $ 0.151379 4.37%
usd1-wlfi
USD1 (USD1) $ 0.998861 0.05%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,465.31 3.39%
dai
Dai (DAI) $ 0.99964 0.02%
susds
sUSDS (SUSDS) $ 1.08 0.16%
lab
LAB (LAB) $ 14.57 14.08%
ethena-usde
Ethena USDe (USDE) $ 0.998844 0.00%
the-open-network
Gram (prev. Toncoin) (GRAM) $ 1.58 6.69%
bitcoin-cash
Bitcoin Cash (BCH) $ 194.53 1.35%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 76,366.00 3.12%
memecore
MemeCore (M) $ 2.84 2.73%
hedera-hashgraph
Hedera (HBAR) $ 0.07748 1.45%
litecoin
Litecoin (LTC) $ 42.14 5.35%
weth
WETH (WETH) $ 2,268.37 3.40%
hashnote-usyc
Circle USYC (USYC) $ 1.13 0.00%
global-dollar
Global Dollar (USDG) $ 0.999912 0.02%
sui
Sui (SUI) $ 0.703774 2.16%
usdt0
USDT0 (USDT0) $ 0.998824 0.03%
avalanche-2
Avalanche (AVAX) $ 6.48 4.08%
paypal-usd
PayPal USD (PYUSD) $ 0.999767 0.01%
shiba-inu
Shiba Inu (SHIB) $ 0.000005 1.49%
crypto-com-chain
Cronos (CRO) $ 0.056521 2.92%
near
NEAR Protocol (NEAR) $ 1.98 4.20%
tether-gold
Tether Gold (XAUT) $ 4,086.66 2.09%
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00 0.00%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.22 0.04%
ondo-us-dollar-yield
Ondo US Dollar Yield (USDY) $ 1.14 0.26%
bittensor
Bittensor (TAO) $ 220.53 3.24%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.059486 1.09%
worldcoin-wld
Worldcoin (WLD) $ 0.544659 11.80%
pax-gold
PAX Gold (PAXG) $ 4,091.27 2.11%
uniswap
Uniswap (UNI) $ 2.92 1.92%
aster-2
Aster (ASTER) $ 0.635647 0.72%
mantle
Mantle (MNT) $ 0.515165 3.43%
okb
OKB (OKB) $ 77.04 3.97%
ripple-usd
Ripple USD (RLUSD) $ 0.999753 0.03%
little-pepe-5
Little Pepe (LILPEPE) $ 2.16 99,999.99%
htx-dao
HTX DAO (HTX) $ 0.000002 1.55%
syrupusdc
syrupUSDC (SYRUPUSDC) $ 1.15 0.04%
polkadot
Polkadot (DOT) $ 0.909238 2.71%
ondo-finance
Ondo (ONDO) $ 0.314409 4.32%
falcon-finance
Falcon USD (USDF) $ 0.995866 0.06%
pi-network
Pi Network (PI) $ 0.129281 3.89%
usdd
USDD (USDD) $ 0.999489 0.01%
bfusd
BFUSD (BFUSD) $ 0.998284 0.04%
sky
Sky (SKY) $ 0.056186 5.15%
internet-computer
Internet Computer (ICP) $ 2.21 1.21%
bitget-token
Bitget Token (BGB) $ 1.72 2.02%
pepe
Pepe (PEPE) $ 0.000003 4.06%
ethereum-classic
Ethereum Classic (ETC) $ 7.06 1.53%
aave
Aave (AAVE) $ 72.41 3.44%
dexe
DeXe (DEXE) $ 23.32 27.12%
morpho
Morpho (MORPHO) $ 1.64 7.88%
quant-network
Quant (QNT) $ 70.65 0.16%
jupiter-perpetuals-liquidity-provider-token
Jupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00 2.64%
united-stables
United Stables (U) $ 0.999999 0.00%
superstate-short-duration-us-government-securities-fund-ustb
Invesco Short Duration US Government Securities Fund (USTB) $ 11.12 0.04%
blockchain-capital
Blockchain Capital (BCAP) $ 107.03 0.00%
kucoin-shares
KuCoin (KCS) $ 7.04 2.31%
eutbl
Spiko EU T-Bills Money Market Fund (EUTBL) $ 1.20 0.38%
jito-staked-sol
Jito Staked SOL (JITOSOL) $ 124.46 4.71%
usdtb
USDtb (USDTB) $ 0.999606 0.01%
cosmos
Cosmos Hub (ATOM) $ 1.72 4.37%
kelp-dao-restaked-eth
Kelp DAO Restaked ETH (RSETH) $ 2,404.69 3.37%
janus-henderson-anemoy-treasury-fund
Janus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11 0.01%
algorand
Algorand (ALGO) $ 0.094281 5.45%
binance-peg-weth
Binance-Peg WETH (WETH) $ 2,262.26 3.62%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.07759 1.77%
rocket-pool-eth
Rocket Pool ETH (RETH) $ 2,631.35 3.29%
render-token
Render (RENDER) $ 1.58 2.87%
stable-2
​​Stable (STABLE) $ 0.034227 4.67%
binance-bridged-usdc-bnb-smart-chain
Binance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945 0.02%
ethena
Ethena (ENA) $ 0.086322 5.08%
kaspa
Kaspa (KAS) $ 0.028861 1.80%
wbnb
Wrapped BNB (WBNB) $ 759.61 1.56%
Scroll to Top