Old Lightning nodes may be exposed to a full-channel wipeout after LND fix lands later than disclosed

LND, a Lightning Network node implementation, has disclosed a channel-close flaw that can put an entire channel balance at risk in the reproduced maximum-loss scenario. Operators using standard releases below 0.21.0 should treat their nodes as lacking the official fix unless they were independently patched.
The Aug. 13 disclosure describes how a malicious channel peer could combine a one-block Bitcoin reorganization with an old, revoked commitment transaction after a cooperative close. Bastien Teinturier, who published the disclosure, said no affected users were known.
Before the fix, LND could forget a cooperatively closed channel after the closing transaction received its first on-chain confirmation. That removed the channel state the node needed to respond safely if Bitcoin later reorganized that block out of the chain.
The attack requires more than an ordinary one-block reorganization. A malicious peer must first participate in the cooperative close, wait for one confirmation, and then take advantage of a reorganization that removes the closing transaction. The peer must also possess and publish an earlier revoked commitment, an outdated channel balance state that should trigger punishment.
… Continue reading the full article at the original source below.


