Emergency Hotfix Deployed to Prevent Disruption to the Lightning Network

0

[ad_1]

After the recent v0.15.3. update to the Lightning Network, a critical security vulnerability was discovered by independent cybersecurity researchers that would potentially allow bad actors to stop lnd nodes from parsing transactions.

A Lightning Network Daemon (lnd) is a full implementation of a Lightning Network Node, along with the services and plug-ins that allow it to connect to the rest of the Lightning network, a Layer-2 blockchain for Bitcoin that enables smart contracts to be run on the BTC network.

Update Released Mere Hours After Discovery

Thanks to watchful community member Burak’s work and responsive devs, hotfix v0.15.4-beta was released about three hours after the bug was discovered.

If left unattended, the bug could have stopped transactions going through if the nodes responsible for parsing them had been attacked by bad actors.

“This is an emergency hot fix release to fix a bug that can cause lnd nodes to be unable to parse certain transactions that have a very large number of witness inputs.”

Devs using the Lightning Network now have two weeks to apply the update. Afterward, channel timelocks currently in place will expire and leave the nodes vulnerable again.

Second Critical Bug in a Month, Discovered by Burak

The most recent bug, which affected the btcd wire parsing library of the Lightning Network, was discovered and announced by Burak on Twitter.

In the blockchain transaction used to demonstrate the bug, the developer left a tongue-in-cheek message indicating the root cause of the problem: “you’ll run cln. And you’ll be happy.”

The developer was also responsible for uncovering a similar bug on the 9th of October. In that instance, Burak created a 998-out-of-999 multisig transaction that was promptly rejected by both LND and btcd nodes. This resulted in the entirety of the block the transaction was recorded in being rejected, leading to a measly transaction fee of only $5.16.

Although this bug may have made many in the Bitcoin community happy, it was still technically an exploit of the system and was patched shortly after.

This vulnerability had also allegedly been reported by white hat hacker Anthony Towns, who forwarded the info to a lead Lightning Network dev.

In spite of the speedy resolution to these two bugs, they led to calls for a bug bounty program for the Lightning Network – as these were reported due to nothing more than good faith. Without incentives for ethical hackers to discover and report similar bugs, there’s no telling who may discover future issues first.

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 90,873.35
ethereum
Ethereum (ETH) $ 2,993.81
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.20
bnb
BNB (BNB) $ 874.34
usd-coin
USDC (USDC) $ 0.999973
solana
Wrapped SOL (SOL) $ 136.17
tron
TRON (TRX) $ 0.281013
staked-ether
Lido Staked Ether (STETH) $ 2,992.49
dogecoin
Dogecoin (DOGE) $ 0.148611
cardano
Cardano (ADA) $ 0.415861
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
whitebit
WhiteBIT Coin (WBT) $ 58.59
wrapped-steth
Wrapped stETH (WSTETH) $ 3,652.53
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 90,619.28
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,242.35
bitcoin-cash
Bitcoin Cash (BCH) $ 521.49
usds
USDS (USDS) $ 0.999915
hyperliquid
Hyperliquid (HYPE) $ 34.43
chainlink
Chainlink (LINK) $ 13.00
leo-token
LEO Token (LEO) $ 9.82
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
stellar
Stellar (XLM) $ 0.254148
weth
WETH (WETH) $ 2,993.51
wrapped-eeth
Wrapped eETH (WEETH) $ 3,239.82
monero
Monero (XMR) $ 414.18
zcash
Zcash (ZEC) $ 459.43
ethena-usde
Ethena USDe (USDE) $ 0.999663
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 90,854.34
litecoin
Litecoin (LTC) $ 84.19
avalanche-2
Avalanche (AVAX) $ 14.25
hedera-hashgraph
Hedera (HBAR) $ 0.143442
sui
Sui (SUI) $ 1.50
shiba-inu
Shiba Inu (SHIB) $ 0.000009
dai
Dai (DAI) $ 0.999697
world-liberty-financial
World Liberty Financial (WLFI) $ 0.160169
susds
sUSDS (SUSDS) $ 1.08
crypto-com-chain
Cronos (CRO) $ 0.107209
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
the-open-network
Toncoin (TON) $ 1.58
paypal-usd
PayPal USD (PYUSD) $ 0.999926
uniswap
Uniswap (UNI) $ 6.08
polkadot
Polkadot (DOT) $ 2.26
usdt0
USDT0 (USDT0) $ 1.00
mantle
Mantle (MNT) $ 1.09
canton-network
Canton (CC) $ 0.085621
bittensor
Bittensor (TAO) $ 296.59
aave
Aave (AAVE) $ 182.43
usd1-wlfi
USD1 (USD1) $ 0.999747
bitget-token
Bitget Token (BGB) $ 3.62
Shares