A Bitcoin Lightning flaw could send a node’s entire balance straight to miners
A flaw in Bitcoin Lightning software program Eclair could let malicious friends wipe out a node’s native channel balance by charges.
ACINQ released Eclair 0.14.3 on Sept. 14 to patch three peer-triggered vulnerabilities that could trigger operators to lose or lock funds throughout channel closures, splicing, and on-the-fly funding.
The Bitcoin expertise firm, a contributor to Lightning Network growth and maker of Eclair and Phoenix Wallet, strongly really useful operators improve as a result of malicious nodes could exploit these points.
Eclair’s patched vulnerabilities
The most direct assault concerned cooperative channel closures. When Eclair was chargeable for the closing payment, an adversarial peer could suggest a cost bigger than the sufferer’s native balance. Eclair’s fallback negotiation could settle for the proposal, eradicate the operator’s output and successfully send the entire native balance to Bitcoin miners as transaction charges.
The patch now rejects closing-fee proposals above an operator’s configured most. Bitcoin Optech described 0.14.3 as a safety launch addressing vulnerabilities involving channel closing, splicing and on-the-fly funding.
A second weak spot could strand funds throughout an unfinished splice, a course of that adjustments the transaction funding a Lightning channel with out closing it. If Eclair signed first and the peer withheld its signature, the newest channel state could rely upon a transaction the sufferer could not publish.

That setup additionally created a path for losses on funds nonetheless in flight. An attacker could permit the incoming aspect of a relayed fee to expire, publish an older channel state, and use the fee secret to acquire the outgoing leg. Eclair will now force-close utilizing the latest state backed by a totally signed funding transaction.
The third vulnerability affected Eclair’s on-the-fly funding characteristic, which may open a channel whereas forwarding a fee. A malicious wallet could manipulate payment-expiry timing to acquire the outgoing fee on-chain whereas the incoming fee expired, leaving the relay operator to take up the loss.
Eclair now checks relay charges and expiry buffers earlier than committing funds. The release additionally provides a default 50 satoshis-per-vByte ceiling for mechanically estimated channel-opening and splice charges, limiting publicity to unhealthy exterior payment information.
Bitcoin Lightning operators face widening safety strain
The fixes arrive as operators of different Lightning software program confront separate makes an attempt to compromise uncovered infrastructure.
Earlier this month, Bitcoin payment processor BTCPay Server mentioned that it had noticed bots repeatedly probing servers the place directors had manually re-enabled exterior entry to LND, one other Lightning implementation.
The attackers focused an unauthenticated password-change endpoint throughout a transient window when an LND pockets was locked. If profitable, they could substitute the pockets password and request an administrator macaroon that could management the node.
BTCPay responded by introducing distinctive passwords for LND wallets and blocking unauthenticated wallet-management routes at its community edge. It additionally suggested operators not to manually expose the LND API.
The incidents level to mounting safety strain throughout Bitcoin’s Lightning ecosystem as attackers seek for software program weaknesses they could use to seize or redirect funds.
The publish A Bitcoin Lightning flaw could send a node’s entire balance straight to miners appeared first on CryptoSlate.
