Loading prices…
🩸BEARISH

Bitcoin Lightning flaw risks funds in unpatched LDK versions

The fix covers two theft paths, including a reconnect attack that could make a forwarding node pay a recipient without recovering the incoming funds.

Lightning Development Kit versions before v0.2.7 and v0.1.13 exposed some Bitcoin Lightning applications to a reconnect attack that could turn a forwarded payment into a loss. A malicious channel peer could acknowledge an update, reconnect, and falsely claim it had never received it. Before the fix, LDK could sign a conflicting commitment transaction without recording it in the channel monitor.

Why it matters

The attack targeted the state-management process behind Lightning channels. After the false reconnect claim, the malicious peer could confirm the conflicting transaction on Bitcoin's blockchain and allow the payment to settle with the next recipient. It could then reclaim the incoming payment contract when it expired, leaving the forwarding application out of pocket even though it knew the payment secret normally used to claim the funds.

The patched behavior allows retransmission only while the peer's acknowledgment remains outstanding. If a peer claims that an already-acknowledged update was missed, LDK now force-closes the channel instead.

LDK developers also patched a separate theft path in v0.2.7 involving LSPS2 just-in-time payments. An intercepted payment could misstate its amount, causing a liquidity service to open a channel and forward more Bitcoin than the incoming payment funded. Developers must also account for pending payment contracts created by older versions because their amounts may not have been validated.

Market impact

The immediate exposure is operational rather than a Bitcoin protocol failure. LDK is compiled into the applications that use it, so wallet and payment developers must integrate the relevant patched library code into their deployed software. The v0.2.7 release addresses the reconnect issue on the 0.2 branch and the LSPS2 amount check, while v0.1.13 carries the shared reconnect fix for the 0.1 branch.

Teams operating Lightning infrastructure should review deployed LDK versions, open channels, and pending LSPS2 contracts. Core Lightning is a separate implementation and is not the affected library in this report.

Related tokens
$BTC

Frequently asked questions

  1. What Lightning vulnerability did the patched LDK releases address?

    A malicious channel peer could reconnect and falsely claim it had missed an acknowledged update. Before the fix, LDK could sign a conflicting commitment transaction that was not recorded by the channel monitor.

  2. Which LDK versions fix the reconnect vulnerability?

    LDK v0.2.7 fixes the issue on the 0.2 branch, while v0.1.13 carries the shared reconnect fix for the 0.1 branch.

  3. How could the reconnect attack cause a Bitcoin loss?

    The attacker could confirm a conflicting transaction on Bitcoin, let the forwarded payment settle with the next recipient, and later reclaim the incoming payment contract when it expired.

  4. What additional issue does LDK v0.2.7 address?

    Version 0.2.7 also fixes an LSPS2 just-in-time payment issue in which a misrepresented payment amount could make a liquidity service forward more Bitcoin than it received.

  5. What should Lightning application developers do next?

    Developers should integrate the relevant patched LDK code into deployed applications and review pending LSPS2 payment contracts created by older versions for unvalidated amounts.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 40m ago
Open original →