The Lightning Development Kit (LDK) library has patched a flaw that could let a malicious channel peer steal the value of a forwarded payment by lying after reconnecting. Security releases v0.2.7 and v0.1.13, dated October 1, address the vulnerability on the 0.2 and 0.1 branches respectively, with v0.2.7 also fixing an LSPS2 amount flaw that could make a liquidity service forward more Bitcoin than it received. Before the fix, the peer could cause the signing of a conflicting commitment transaction that LDK’s channel monitor did not record, leaving the forwarding node without its incoming funds. Developers must incorporate the patched library code into deployed applications and account for LSPS2 payment contracts queued by a prior version, whose amounts remain unvalidated. These fixes are distinct from the splice-fee diversion and saved-state loading bugs addressed in LDK v0.2.6.
Source: Read the original article

