Lightning apps using unpatched LDK risk Bitcoin theft from a reconnect lie

Share

The Lightning Development Kit (LDK) library has patched a flaw that could let a malicious channel peer steal the value of a forwarded payment by lying after reconnecting. Security releases v0.2.7 and v0.1.13, dated October 1, address the vulnerability on the 0.2 and 0.1 branches respectively, with v0.2.7 also fixing an LSPS2 amount flaw that could make a liquidity service forward more Bitcoin than it received. Before the fix, the peer could cause the signing of a conflicting commitment transaction that LDK’s channel monitor did not record, leaving the forwarding node without its incoming funds. Developers must incorporate the patched library code into deployed applications and account for LSPS2 payment contracts queued by a prior version, whose amounts remain unvalidated. These fixes are distinct from the splice-fee diversion and saved-state loading bugs addressed in LDK v0.2.6.

Source: Read the original article

Disclaimer: this content is for information purposes only and is not financial advice. Cryptocurrencies are highly volatile: you may lose all of your capital. Always do your own research. Legal notice
Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Read More

Items