|

Core Lightning patches flaw that could let revoked channel state escape penalty

Flow diagram of a Core Lightning revoked commitment misclassified as a mutual close, and the v26.06.7 locktime-and-sequence fix

Core Lightning, a Lightning Network node implementation, mounted a channel-close flaw in v26.06.7 that could let a peer broadcast an previous, revoked channel state with out triggering the penalty for dishonest. Bitcoin Optech’s Sept. 25 explanation of the now-public patch makes the chance concrete for operators nonetheless operating older builds.

Related Reading

Onslaught of AI-found bugs forces Bitcoin’s Core Lightning into a secret 14-day emergency lockdown


Lightning friends substitute earlier channel commitments as balances change. If one broadcasts a revoked dedication, the counterparty ought to be capable to declare a penalty. Before the repair, Core Lightning could as an alternative deal with that funding spend as a cooperative shut when its outputs matched shutdown scripts already on file.

That trusted a selected channel setup. A peer that had not specified an upfront shutdown script when the channel opened could later identify the output script of its revoked dedication in a shutdown message. It could then abandon the cooperative shut and broadcast the previous dedication. Matching the outputs alone made the transaction look respectable, bypassing the penalty path, in response to the maintainers’ patch notes and regression test.

Flow diagram of a Core Lightning revoked commitment misclassified as a mutual close, and the v26.06.7 locktime-and-sequence fix

The restore checks a transaction’s locktime and sequence encoding to acknowledge a dedication earlier than taking a look at its outputs as a attainable mutual shut. The supplies describe a possible method to evade the penalty, not a confirmed theft. This is a Core Lightning channel-handling subject, not a change to Bitcoin’s base-chain guidelines.

Related Reading

How a quiet flaw in Bitcoin’s top scaling network left user funds open to total wipeouts – and the fix arrived later than disclosed


What operators ought to verify

A Core Lightning construct older than the mounted v26.06.7 launch wants an replace. The venture strongly recommends v26.06.8, a later safety launch with extra fixes. The revoked-close path requires the shutdown-script situation above, so a susceptible software program model doesn’t imply each channel could be exploited that means.

Operators who used Docker photos throughout the earlier rollout must also confirm the picture digest. The venture’s v26.06.7 release notes say that photos served below v26.06.7 and associated tags from Aug. 28 to Sept. 1 reported the brand new model on startup however lacked its fixes. The venture lists the corrected digests and instructs customers with a mismatch to re-pull the picture.

Related Reading

Bitcoin Core Lightning Docker bug leaves node operators exposed despite showing updated version


The model historical past separates the 2 patches. Core Lightning shipped v26.06.7 on Aug. 28, then printed its initially embargoed launch supply code on Sept. 11. Pull request 9509, merged into the primary improvement department Sept. 15, carried these adjustments ahead. V26.06.8 adopted Sept. 22 with different safety fixes and instantly accessible supply, although a number of exams remained withheld. Optech’s Sept. 25 report defined the already-shipped revoked-close restore.

The submit Core Lightning patches flaw that could let revoked channel state escape penalty appeared first on CryptoSlate.

Similar Posts