News linked to both this project and an event.
Odaily News, January 10 - A Bitcoin and Litecoin holder provided a 12-word recovery phrase to attackers impersonating Trezor support personnel, resulting in the theft of approximately $282 million in assets, including about $139 million in Bitcoin and $153 million in Litecoin. Blockchain forensics firm ZeroShadow stated that the incident stemmed from a social engineering attack, not a compromise of wallet software or private key infrastructure. The stolen funds were split via the THORChain cross-chain bridge within minutes and converted into Monero through instant exchange services. ZeroShadow's monitoring team flagged and froze approximately $700,000 in funds within 20 minutes. Under the BIP39 standard, a 12-word recovery phrase contains approximately 128 bits of entropy, while a 24-word phrase contains 256 bits of entropy. Chainalysis estimates that up to 23% of all mined Bitcoin is permanently inaccessible due to lost keys, involving millions of BTC, with causes including forgotten recovery phrases, damaged backups, and a lack of inheritance planning.
Litecoin disclosed on X platform that a recent zero-day vulnerability once led to a DoS attack, affecting the operation of major mining pools. Mining nodes that were not updated in time allowed an invalid MWEB (MimbleWimble Extension Block) transaction to be executed, enabling the relevant tokens to be withdrawn to a third-party DEX. The Litecoin network rolled back these invalid transactions through a 13-block reorganization (reorg), confirming they would not be included in the main chain. All valid transactions during this period were unaffected. The vulnerability has now been completely fixed, and the network has resumed normal operation.