LDK Patches Fix Lightning Reconnect Flaw That Risked Bitcoin Theft
Versions 0.2.7 and 0.1.13 address a vulnerability affecting both LDK branches. Version 0.2.7 also fixes a separate LSPS2 payment-amount flaw.

Lightning Development Kit (LDK) has patched a vulnerability that could let a malicious channel peer create a conflicting channel state and potentially steal Bitcoin (BTC) from affected Lightning applications.
LDK released versions 0.2.7 and 0.1.13 on Oct. 1 to address the issue, which affects both the 0.2 and 0.1 branches. The attack involved a peer acknowledging a channel update, disconnecting and then falsely claiming after reconnecting that it had never received the update.
That behavior could cause an application to sign a conflicting commitment transaction at the same index. The peer could potentially publish that transaction and reclaim funds after an incoming HTLC, or hashed time-lock contract, expired.
Version 0.2.7 also fixes a separate vulnerability in LSPS2, a just-in-time channel-opening process. The flaw could allow a client to request an amount larger than the incoming HTLC, causing a liquidity service to open a channel and forward more Bitcoin than it received.
LDK is a software development kit used to build Bitcoin Lightning wallets, payment applications and nodes. The number of affected applications or channels, and whether either vulnerability was exploited, remain unknown.