A Bitcoin Lightning flaw could send a node’s entire balance straight to miners
A flaw in Bitcoin Lightning software Eclair could let malicious peers wipe out a node’s local channel balance through fees. ACINQ released Eclair 0.14.3 on Sept. 14 to patch three peer-triggered vulnerabilities that coul...
Watchlist
Published in the last two hours. A tracked entity is involved.
A flaw in Bitcoin Lightning software Eclair could let malicious peers wipe out a node’s local channel balance through fees.
ACINQ released Eclair 0.14.3 on Sept. 14 to patch three peer-triggered vulnerabilities that could cause operators to lose or lock funds during channel closures, splicing, and on-the-fly funding.
The Bitcoin technology company, a contributor to Lightning Network development and maker of Eclair and Phoenix Wallet, strongly recommended operators upgrade because malicious nodes could exploit these issues.
Eclair's patched vulnerabilitiesThe most direct attack involved cooperative channel closures. When Eclair was responsible for the closing fee, an adversarial peer could propose a charge larger than the victim’s local balance. Eclair’s fallback negotiation could accept the proposal, eliminate the operator’s output and effectively send the entire local balance to Bitcoin miners as transaction fees.
The patch now rejects closing-fee proposals above an operator’s configured maximum. Bitcoin Optech described 0.14.3 as a security release addressing vulnerabilities involving channel closing, splicing and on-the-fly funding.
A second weakness could strand funds during an unfinished splice, a process that changes the transaction funding a Lightning channel without closing it. If Eclair signed first and the peer withheld its signature, the latest channel state could depend on a transaction the victim could not publish.
That setup also created a path for losses on payments still in flight. An attacker could allow the incoming side of a relayed payment to expire, publish an older channel state, and use the payment secret to collect the outgoing leg. Eclair will now force-close using the newest state backed by a fully signed funding transaction.
The third vulnerability affected Eclair’s on-the-fly funding feature, which can open a channel while forwarding a payment. A malicious wallet could manipulate payment-expiry timing to collect the outgoing payment on-chain while the incoming payment expired, leaving the relay operator to absorb the loss.
Eclair now checks relay fees and expiry buffers before committing funds. The release also adds a default 50 satoshis-per-vByte ceiling for automatically estimated channel-opening and splice fees, limiting exposure to bad external fee data.
Bitcoin Lightning operators face widening security pressureThe fixes arrive as operators of other Lightning software confront separate attempts to compromise exposed infrastructure.
Related Reading Critical Bitcoin Lightning bugs exposed nodes to fund theft and restart failureEarlier this month, Bitcoin payment processor BTCPay Server said that it had observed bots repeatedly probing servers where administrators had manually re-enabled external access to LND, another Lightning implementation.
The attackers targeted an unauthenticated password-change endpoint during a brief window when an LND wallet was locked. If successful, they could replace the wallet password and request an administrator macaroon that could control the node.
BTCPay responded by introducing unique passwords for LND wallets and blocking unauthenticated wallet-management routes at its network edge. It also advised operators not to manually expose the LND API.
The incidents point to mounting security pressure across Bitcoin’s Lightning ecosystem as attackers search for software weaknesses they could use to seize or redirect funds.
The post A Bitcoin Lightning flaw could send a node’s entire balance straight to miners appeared first on CryptoSlate.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoSlateRelated market context
Arc Launches Agentic Payments with USDC Across 3 Chains, Removing Gas Wallet Hassles
Key Takeaways: Arc has also created agentic payments, allowing Circle agents and developers to receive USDC payments via the x402...
EU staking review threatens crypto yields and network security could pay the price
Some of the most consequential financial rules begin with surprisingly little text. For example, on page 36 of the European Commis...
WaterPlum Targets 30,000 Devices and Steals 7,000+ Crypto Wallet Records Worldwide
Key Takeaways: WaterPlum hacked over 30,000 devices in 100+ countries and accessed information from 7,000+ crypto wallets. Fake jo...
WisdomTree And MoonPay Expand US Access To Tokenized Funds
TL;DR WisdomTree is integrating MoonPay into its tokenized-fund platform. MoonPay says its ecosystem reaches more than 30 million...
Why keeping your private keys safe won’t always stop crypto theft
Almost 4,000 Bitcoin left Liquid's reserve on Sept. 6 through a withdrawal the network approved, even though the private keys used...
XRP News: AI Payments Integration With Stripe Driving Ripple Toward $1.50
In XRP news, the asset is moving faster than it has since August. The token passed $1.38 on CoinGecko after a +2% gain over the pa...