Litecoin miners coordinated a 13-block chain reorganization on April 25, 2026 after an attempt to exploit the network’s Mimblewimble Extension Block system disrupted upgraded mining nodes while unupgraded miners continued building an invalid chain.

The valid chain eventually overtook the invalid branch, removing its transactions from Litecoin’s accepted ledger. Developers released Litecoin Core 0.21.5.4 on April 25 and urged node operators and wallet users to upgrade immediately. Its public notes identified an MWEB consensus correction, additional input-validation checks, protection against a kernel-fee overflow and a change intended to prevent mutated block data from causing a denial of service against miners.

The event mattered because it combined two risks that proof-of-work networks are designed to contain: inconsistent validation across miners and an interruption of block production among operators running defensive code. Litecoin recovered without permanently accepting the invalid branch, but the incident demonstrated that a security fix is only as effective as its deployment across the network participants responsible for extending the chain.

How the chain divided

MWEB is Litecoin’s optional extension-block system for confidential transactions. According to the project’s later technical reconstruction, an actor began attempting to reuse a previously identified MWEB exploit path at block height 3,095,931 on April 25.

Nodes containing an earlier private fix rejected the malformed MWEB data. The rejection path nevertheless exposed another problem: certain remote-procedure calls used by miners could hang after receiving mutated block data. Some upgraded mining nodes consequently became stuck or could not submit new valid blocks normally.

Miners that had not received the earlier fix continued accepting and extending the bad branch. That branch reached height 3,095,943—13 invalid blocks including the first bad block—before upgraded pools coordinated around the valid chain and accumulated enough proof of work to overtake it.

A reorganization does not literally edit blocks already observed by nodes. Competing branches exist temporarily, and nodes ultimately follow the valid branch selected under the protocol’s consensus and accumulated-work rules. Transactions confined to the displaced branch lose their confirmations and may return to the transaction pool, conflict with accepted transactions or disappear if they were invalid.

What was established on April 25

The event-day record established that Litecoin Core 0.21.5.4 was available, contained important security updates and was considered an urgent upgrade. Its notes specifically described a consensus fix for an MWEB input-validation problem that could unbalance the kernel sum and a change that erased stored data for mutated blocks to avoid miner denial of service.

Contemporaneous reporting published during the following hours documented the 13-block reorganization and approximately 32 minutes of displaced block history. That duration is an observation about the timestamps and blocks involved, not a claim that the disruption lasted only 32 minutes in wall-clock time. Litecoin targets blocks approximately every 2.5 minutes, but actual intervals vary, especially during a mining disruption.

The available event-day evidence did not establish a complete loss figure, every affected transaction or the final exposure of external services. It also did not justify labeling the incident a conventional majority-hash-power attack. The immediate failure involved divergent software behavior and an exploit attempt against MWEB, followed by coordinated recovery by miners using the valid rules.

Why deployment was part of the failure

The incident exposed the operational difficulty of privately distributing a consensus-sensitive fix. Limited disclosure can reduce the chance that attackers learn a vulnerability before miners patch it. The same approach can leave the network divided when adoption is incomplete: patched miners reject what unpatched miners still accept.

Core 0.21.5.4 addressed both the underlying MWEB accounting issue and the mutated-block handling behavior that could prevent valid block submission. The release reduced the known failure modes, but publication alone could not prove that every miner, exchange, wallet or service had upgraded.

Later context

Litecoin’s April 28 postmortem confirmed the April 25 heights, the 13-block invalid branch and the coordinated recovery. It also said some THORChain and NEAR/SwapKit-related infrastructure was affected, while exact third-party transaction identifiers and final losses were still being collected. Those details clarify the incident but were not fully established on April 25. The unresolved questions remained the completeness of miner upgrades, the full third-party impact and whether independent review would confirm the project’s technical account.

Primary sourceLitecoin Core — Version 0.21.5.4 release-notes commit

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.