|

Old Lightning nodes may be exposed to a full-channel wipeout after LND fix lands later than disclosed

Six-step LND channel-close exploit sequence showing the one-block reorganization prerequisite, full-channel maximum loss, and upgrade cutoff at version 0.21.0.

LND, a Lightning Network node implementation, has disclosed a channel-close flaw that may put a complete channel steadiness in danger within the reproduced maximum-loss situation. Operators utilizing commonplace releases under 0.21.0 ought to deal with their nodes as missing the official fix until they have been independently patched.

The Aug. 13 disclosure describes how a malicious channel peer may mix a one-block Bitcoin reorganization with an previous, revoked dedication transaction after a cooperative shut. Bastien Teinturier, who revealed the disclosure, mentioned no affected customers have been identified.

Related Reading

Researchers discover vulnerabilities in Bitcoin layer-2 Lightning Network


Before the fix, LND may neglect a cooperatively closed channel after the closing transaction acquired its first on-chain affirmation. That eliminated the channel state the node wanted to reply safely if Bitcoin later reorganized that block out of the chain.

The assault requires extra than an unusual one-block reorganization. A malicious peer should first take part within the cooperative shut, look forward to one affirmation, after which make the most of a reorganization that removes the closing transaction. The peer should additionally possess and publish an earlier revoked dedication, an outdated channel steadiness state that ought to set off punishment.

Related Reading

Inside Bitcoin’s 24 hour race to survive a global internet blackout


An affected LND node can then fail to broadcast the penalty transactions designed to punish publication of that revoked state. Under the reproduced situation, the loss can attain the channel’s full steadiness. That determine is a most loss situation, not proof that the vulnerability was exploited within the wild.

Six-step LND channel-close exploit sequence showing the one-block reorganization prerequisite, full-channel maximum loss, and upgrade cutoff at version 0.21.0.

The disclosure and fix are particular to LND. They don’t recommend that different Lightning implementations share the identical channel-close flaw.

Related Reading

Exchange BTC Lightning channels break our favorite Bitcoin metric


The official fix begins with LND 0.21.0

Upstream repository historical past locations the official fix in 0.21.0, not the 0.20.0 model cited by the general public disclosure.

Pull request #10331 merged into the challenge’s grasp department on Jan. 16, 2026. A backport to the 0.20.x department was later reverted, and a subsequent documentation change mentioned the improved cooperative-close affirmation logic had really landed in 0.21.0. The challenge’s 0.21.0 release notes additionally affiliate the reorganization-safe shut logic with that launch line.

Operators due to this fact mustn’t depend on the disclosure’s 0.20.0 cutoff. Standard releases under 0.21.0 ought to be handled as missing the official fix until independently patched.

LND’s security policy recommends the newest minor launch of the latest main line an operator can assist. As of Aug. 25, the challenge’s newest official bundle was lnd v0.21.2-beta, launched Aug. 13.

The fix makes LND retain shut state whereas ready for a number of confirmations and react to reorganization notifications as an alternative of contemplating the channel resolved after one block.

The publish Old Lightning nodes may be exposed to a full-channel wipeout after LND fix lands later than disclosed appeared first on CryptoSlate.

Similar Posts