Lightning apps using unpatched LDK risk Bitcoin theft from a reconnect lie

2 hours ago 1



Lightning Development Kit (LDK), a library for building Bitcoin Lightning wallets and payment applications, has patched a flaw that could let a malicious channel peer steal the value of a forwarded payment by lying after reconnecting. Affected application developers need to incorporate the fix into the software they deploy.The October 1-dated v0.2.7 and v0.1.13 security releases address the LDK reconnect vulnerability on the 0.2 and 0.1 branches, respectively. Bitcoin Optech described the fixes in its Oct. 9 newsletter.How the LDK reconnect flaw could cost BitcoinThe attack starts with a channel peer acknowledging an update, then reconnecting and pretending it never received it. Before the fix, that false claim could cause LDK to sign a conflicting commitment transaction.A commitment transaction represents a channel's agreed state and can be used to settle it on Bitcoin's blockchain. In the scenario described in PR 5057, the newly signed transaction was not recorded by LDK's channel monitor, the component tracking the channel's on-chain claims.That gap could turn a forwarded payment into a loss. The malicious sender could confirm the transaction on-chain and let the payment settle ...

Read Entire Article