A Bitcoin Lightning flaw could send a node’s entire balance straight to miners
A flaw in Bitcoin Lightning software Eclair could let malicious peers wipe out a node’s local channel balance through fees. ACINQ released Eclair 0.14.3 on Sept. 14 to patch three peer-triggered vulnerabilities that coul...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
A flaw in Bitcoin Lightning software Eclair could let malicious peers wipe out a node’s local channel balance through fees.
ACINQ released Eclair 0.14.3 on Sept. 14 to patch three peer-triggered vulnerabilities that could cause operators to lose or lock funds during channel closures, splicing, and on-the-fly funding.
The Bitcoin technology company, a contributor to Lightning Network development and maker of Eclair and Phoenix Wallet, strongly recommended operators upgrade because malicious nodes could exploit these issues.
Eclair's patched vulnerabilitiesThe most direct attack involved cooperative channel closures. When Eclair was responsible for the closing fee, an adversarial peer could propose a charge larger than the victim’s local balance. Eclair’s fallback negotiation could accept the proposal, eliminate the operator’s output and effectively send the entire local balance to Bitcoin miners as transaction fees.
The patch now rejects closing-fee proposals above an operator’s configured maximum. Bitcoin Optech described 0.14.3 as a security release addressing vulnerabilities involving channel closing, splicing and on-the-fly funding.
A second weakness could strand funds during an unfinished splice, a process that changes the transaction funding a Lightning channel without closing it. If Eclair signed first and the peer withheld its signature, the latest channel state could depend on a transaction the victim could not publish.
That setup also created a path for losses on payments still in flight. An attacker could allow the incoming side of a relayed payment to expire, publish an older channel state, and use the payment secret to collect the outgoing leg. Eclair will now force-close using the newest state backed by a fully signed funding transaction.
The third vulnerability affected Eclair’s on-the-fly funding feature, which can open a channel while forwarding a payment. A malicious wallet could manipulate payment-expiry timing to collect the outgoing payment on-chain while the incoming payment expired, leaving the relay operator to absorb the loss.
Eclair now checks relay fees and expiry buffers before committing funds. The release also adds a default 50 satoshis-per-vByte ceiling for automatically estimated channel-opening and splice fees, limiting exposure to bad external fee data.
Bitcoin Lightning operators face widening security pressureThe fixes arrive as operators of other Lightning software confront separate attempts to compromise exposed infrastructure.
Related Reading Critical Bitcoin Lightning bugs exposed nodes to fund theft and restart failureEarlier this month, Bitcoin payment processor BTCPay Server said that it had observed bots repeatedly probing servers where administrators had manually re-enabled external access to LND, another Lightning implementation.
The attackers targeted an unauthenticated password-change endpoint during a brief window when an LND wallet was locked. If successful, they could replace the wallet password and request an administrator macaroon that could control the node.
BTCPay responded by introducing unique passwords for LND wallets and blocking unauthenticated wallet-management routes at its network edge. It also advised operators not to manually expose the LND API.
The incidents point to mounting security pressure across Bitcoin’s Lightning ecosystem as attackers search for software weaknesses they could use to seize or redirect funds.
The post A Bitcoin Lightning flaw could send a node’s entire balance straight to miners appeared first on CryptoSlate.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoSlateRelated market context
THORChain Co-Founder Will Ask Its Treasury About Refunding Fees From Stolen Crypto
THORChain co-founder Chad Barraford said he will ask the protocol’s Treasury about sending part of what its developer fund earned...
Stablecoin payments startup Noah hits $38 million in seed funding
Noah's funding boost signals a strategic expansion into the US market, potentially reshaping stablecoin integration with tradition...
Solana x402 Lets AI Agents Batch USDC Payments, Slashing Fees
Solana has rolled out batch payments for the x402 standard with PayAI Network and BlockRunAI, allowing AI agents to make many USDC...
Payments Firm Says Tether Froze $2.76 Million Brazilian Police Didn’t Flag, Forcing Layoffs
Tether froze $2.76 million of a payments company’s working capital though the Brazilian police investigation behind the freeze nev...
The Quantum Issue: Bitcoin Quantum Exposure at Block 950,000
Bitcoin Magazine The Quantum Issue: Bitcoin Quantum Exposure at Block 950,000 At block 950,000, 6.90 million BTC are cryptographic...
Robinhood adds $25 million of Bitcoin to its own balance sheet
Robinhood is adding $25 million of Bitcoin to its balance sheet after executives previously debated whether corporate crypto holdi...