1 min read
Add as a preferred source on Google

LDK Patches Fix Lightning Reconnect Flaw That Risked Bitcoin Theft

Versions 0.2.7 and 0.1.13 address a vulnerability affecting both LDK branches. Version 0.2.7 also fixes a separate LSPS2 payment-amount flaw.

Mentioned assets
Metal lock beside copper cable and Bitcoin-colored coin / TokenPost.ai
Metal lock beside copper cable and Bitcoin-colored coin / TokenPost.ai

Lightning Development Kit (LDK) has patched a vulnerability that could let a malicious channel peer create a conflicting channel state and potentially steal Bitcoin (BTC) from affected Lightning applications.

LDK released versions 0.2.7 and 0.1.13 on Oct. 1 to address the issue, which affects both the 0.2 and 0.1 branches. The attack involved a peer acknowledging a channel update, disconnecting and then falsely claiming after reconnecting that it had never received the update.

That behavior could cause an application to sign a conflicting commitment transaction at the same index. The peer could potentially publish that transaction and reclaim funds after an incoming HTLC, or hashed time-lock contract, expired.

Version 0.2.7 also fixes a separate vulnerability in LSPS2, a just-in-time channel-opening process. The flaw could allow a client to request an amount larger than the incoming HTLC, causing a liquidity service to open a channel and forward more Bitcoin than it received.

LDK is a software development kit used to build Bitcoin Lightning wallets, payment applications and nodes. The number of affected applications or channels, and whether either vulnerability was exploited, remain unknown.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…