Loading prices…
🩸BEARISH

Eclair Flaw Puts Lightning Node Balances at Risk

The Sept. 14 patch closes three peer-triggered attack paths, including one that could turn a node's entire local channel balance into miner fees.

ACINQ released Eclair 0.14.3 on Sept. 14 to fix three peer-triggered vulnerabilities that could cause Bitcoin Lightning operators to lose or lock funds during channel closures, splicing and on-the-fly funding. The most severe flaw could let a malicious peer propose a closing fee larger than the operator's local balance, causing Eclair to accept a transaction that sends the entire balance to Bitcoin miners.

Why it matters

The first vulnerability affected cooperative channel closures, where Eclair was responsible for setting the closing fee. Its fallback negotiation could accept an adversarial proposal above the operator's configured limit. Version 0.14.3 now rejects closing-fee proposals above that maximum.

A second flaw could strand funds during an unfinished splice if Eclair signed first and a peer withheld its signature. Attackers could also let an incoming relayed payment expire, publish an older channel state and use the payment secret to collect the outgoing leg. Eclair now forces closure using the newest state backed by a fully signed funding transaction.

The third issue involved on-the-fly funding, which opens a channel while forwarding a payment. A malicious wallet could manipulate expiry timing so the outgoing payment settled on-chain while the incoming payment expired, leaving the relay operator with the loss. Eclair now checks relay fees and expiry buffers before committing funds.

Market impact

The release adds a default ceiling of 50 satoshis-per-vByte for automatically estimated channel-opening and splice fees, limiting exposure to faulty external fee data. ACINQ strongly recommended that operators upgrade.

The fixes arrive as BTCPay Server reports repeated probing of LND infrastructure with manually re-enabled external access. That separate incident targeted an unauthenticated password-change route, underscoring the widening security pressure across Bitcoin's Lightning ecosystem. Operators are facing both implementation bugs and exposed administrative surfaces as attackers seek routes to control or redirect funds.

Related tokens
$BTC

Frequently asked questions

  1. What was the most serious Eclair vulnerability?

    A malicious peer could propose a closing fee larger than an operator's local channel balance. Eclair could accept the proposal and send the balance to Bitcoin miners as fees.

  2. Which Eclair release fixes the Lightning vulnerabilities?

    ACINQ released Eclair 0.14.3 on Sept. 14. The release addresses vulnerabilities in channel closing, splicing and on-the-fly funding.

  3. How could the splice vulnerability cause losses?

    If Eclair signed first and a peer withheld its signature, the latest channel state could depend on an unpublished transaction. An attacker could also exploit an expired incoming payment while collecting the outgoing leg.

  4. What protection did Eclair add for on-the-fly funding?

    Eclair now checks relay fees and expiry buffers before committing funds. This limits the ability of a malicious wallet to create a timing gap between outgoing and incoming payments.

  5. What other Lightning security issue affected LND operators?

    BTCPay Server reported bots probing LND servers with manually re-enabled external access. The attackers targeted an unauthenticated password-change route that could expose wallet-control credentials.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →