A Bitcoin Lightning flaw could send a nodes entire balance straight to miners

요약:A new ACINQ security patch closes three attack paths affecting Bitcoin Lightning channel closures, splicing, and payment forwarding.

A flaw in Bitcoin Lightning software Eclair could let malicious peers wipe out a nodes local channel balance through fees.

Related Asset Bitcoin #1 BTC · $86,078.14 24-hour change: up 6.46% Loading price history… 24H Up 6.46% 7D Up 9.87% 30D Up 11.73%

ACINQ released Eclair 0.14.3 on Sept. 14 to patch three peer-triggered vulnerabilities that could cause operators to lose or lock funds during channel closures, splicing, and on-the-fly funding.

The Bitcoin technology company, a contributor to Lightning Network development and maker of Eclair and Phoenix Wallet, strongly recommended operators upgrade because malicious nodes could exploit these issues.

Eclair's patched vulnerabilities

The most direct attack involved cooperative channel closures. When Eclair was responsible for the closing fee, an adversarial peer could propose a charge larger than the victim‘s local balance. Eclair’s fallback negotiation could accept the proposal, eliminate the operators output and effectively send the entire local balance to Bitcoin miners as transaction fees.

The patch now rejects closing-fee proposals above an operators configured maximum. Bitcoin Optech described 0.14.3 as a security release addressing vulnerabilities involving channel closing, splicing and on-the-fly funding.

A second weakness could strand funds during an unfinished splice, a process that changes the transaction funding a Lightning channel without closing it. If Eclair signed first and the peer withheld its signature, the latest channel state could depend on a transaction the victim could not publish.

That setup also created a path for losses on payments still in flight. An attacker could allow the incoming side of a relayed payment to expire, publish an older channel state, and use the payment secret to collect the outgoing leg. Eclair will now force-close using the newest state backed by a fully signed funding transaction.

The third vulnerability affected Eclairs on-the-fly funding feature, which can open a channel while forwarding a payment. A malicious wallet could manipulate payment-expiry timing to collect the outgoing payment on-chain while the incoming payment expired, leaving the relay operator to absorb the loss.

Eclair now checks relay fees and expiry buffers before committing funds. The release also adds a default 50 satoshis-per-vByte ceiling for automatically estimated channel-opening and splice fees, limiting exposure to bad external fee data.

Bitcoin Lightning operators face widening security pressure

The fixes arrive as operators of other Lightning software confront separate attempts to compromise exposed infrastructure.

Earlier this month, Bitcoin payment processor BTCPay Server said that it had observed bots repeatedly probing servers where administrators had manually re-enabled external access to LND, another Lightning implementation.

The attackers targeted an unauthenticated password-change endpoint during a brief window when an LND wallet was locked. If successful, they could replace the wallet password and request an administrator macaroon that could control the node.

BTCPay responded by introducing unique passwords for LND wallets and blocking unauthenticated wallet-management routes at its network edge. It also advised operators not to manually expose the LND API.

The incidents point to mounting security pressure across Bitcoins Lightning ecosystem as attackers search for software weaknesses they could use to seize or redirect funds.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

유니스왑 창업자, SBF 유니스왑닷컴 7자리 달러 지불…도메인 소유권 잃어

다음

코인스비, 트론 USDT 온체인 결제 1위…스테이블코인 사용 증가