|

Critical Bitcoin Lightning bugs exposed nodes to fund theft and restart failure

LDK v0.2.6, released September 9, 2026, fixes small splice-related fund diversion and a payment sequence that can prevent saved ChannelManager state from loading.

Lightning Development Kit, a toolkit for constructing Bitcoin Lightning purposes, launched v0.2.6 on Sept. 9 with fixes for bugs that would divert small quantities of a node’s funds or stop saved channel state from loading.

LDK packages a Lightning implementation as a software program improvement package for makes use of together with cellular wallets and payment-service infrastructure. The update provides builders sustaining affected purposes fixes for each a monetary danger and a situation that may disrupt regular node restarts.

Related Reading

Onslaught of AI-found bugs forces Bitcoin’s Core Lightning into a secret 14-day emergency lockdown


A splice lets a node add funds to or take away funds from an present cost channel. LDK’s API documentation describes this as spending the channel’s funding output and changing it with a brand new one. In sensible phrases, it modifications the cash dedicated to the channel by way of a alternative funding transaction.

That transaction has prices shared between the members. The initiating node pays charges for specified frequent components, together with its personal contributed inputs and outputs. The payment calculation subsequently impacts how a lot of the node’s cash pays for the operation.

The splice flaw may let a malicious peer trigger extra payment allocation, with the surplus going to that peer’s output. The launch describes a small quantity of funds in danger when a node initiates a splice, with out specifying a numerical ceiling.

The separate safety flaw concerned two cost contracts sharing the identical cost hash. After one had been efficiently forwarded, receiving and instantly rejecting a bogus one may go away ChannelManager state unable to load.

ChannelManager is LDK’s element for managing channels and funds. Restarting an present node includes studying its saved state again into reminiscence, a course of referred to as deserialization. If that saved state is rejected throughout loading, the applying can’t full its regular restart. Rejecting the bogus cost doesn’t, by itself, keep away from this specific failure.

LDK v0.2.6, released September 9, 2026, fixes small splice-related fund diversion and a payment sequence that can prevent saved ChannelManager state from loading.

For pockets builders, the 2 fixes handle completely different components of conserving a cost service working: allocating funds accurately when a channel modifications and retaining state that may be loaded after a shutdown.

Related Reading

Boltz’s shutdown shows the real danger of AI hacking is pushing crypto back into the hands of giant custodians


LDK’s architecture documentation explains that its core implementation is compiled into purposes. Developers select the encircling storage, pockets, networking and blockchain-monitoring elements. Incorporating the patched toolkit into these purposes is subsequently the related upkeep step for affected integrations.

The launch discover reviews no noticed losses or exploited purposes. Its description establishes the vulnerabilities and fixes, quite than a measured toll on customers. With v0.2.6 out there, the fast activity for affected software groups is to convey these fixes into the software program they function.

Related Reading

Bitcoin Core Lightning Docker bug leaves node operators exposed despite showing updated version


The submit Critical Bitcoin Lightning bugs exposed nodes to fund theft and restart failure appeared first on CryptoSlate.

Similar Posts