Lightning Network releases emergency update after critical bug on LND nodes

Join Camnang24h to see why “Lightning Network releases emergency update after critical bug on LND nodes” through the article below. The bug led LND nodes to fail to sync chain in the second critical bug in less than a month.

Related: South African grocery giant ‘Pick n Pay’ intends to accept Bitcoin in all stores nationwide

Lightning Network releases emergency update after critical bug on LND nodes

An emergency update was released to all of Lightning Network’s LND node operators on Nov. 1, after a critical bug caused LND nodes to fall out of sync chain. This was the second critical bug experienced by the network in less than a month.

According to Lightning Labs, developer of the Bitcoin Lightning Network, some LND nodes stopped syncing due to an issue with the btcd wire parsing library. The hot fix (v.015.4) was released nearly three hours after the break. The release stated:

“This is an emergency hot fix release to fix a bug that can cause lnd nodes to be unable to parse certain transactions that have a very large number of witness inputs.”

As per the issue on GitHub, non-updated nodes will be vulnerable to malicious channel closings once channel timelocks expire in two weeks. The bug impacted only LND nodes, making the current chain state outdated, although payments transactions were still available. Some versions of electrs were also impacted, according to another issue on GitHub.

The bug was triggered by a developer dubbed Burak on Twitter, with a message in the transaction saying: “you’ll run cln. and you’ll be happy.”

Sometimes to find the light, we must first touch the darkness.

— Burak (@brqgoo) November 1, 2022

Burak was also responsible for triggering a similar bug on Oct. 9, when they created a 998-of-999 multisig transaction that was rejected by btcd and LND nodes, leading to the rejection of the whole block and all blocks following the transaction. On the same day, Lightning Labs released a patch to fix the issue.

I just did a 998-of-999 tapscript multisig, and it only cost $4.90 in transaction fees.

— Burak (@brqgoo) October 9, 2022

On Twitter, users suggested that it was time for an LND bug bounty program:

Savage takedown of LND lightning nodes by exploiting a consensus discrepancy between Bitcoin Core and btcd with a single Bitcoin transaction.

Encoded message:
“you’ll run cln. and you’ll be happy.”

Probably not a “responsible disclosure”. Time for an LND bug bounty program?

— Stadicus (@Stadicus3000) November 1, 2022

Hacker Anthony Towns also claimed to have disclosed the vulnerability to LND developers two weeks ago, noting, “The btcd repo doesn’t seem to have a reporting policy for security bugs, so not sure if anyone else working on btcd found out about it.”

The Lightning Network is a second layer added to Bitcoin’s BTC $20,518 blockchain that allows off-chain transactions, i.e. transactions between parties not on the blockchain network.


Ads Blocker Image Powered by Code Help Pro

Ads Blocker Detected!!!

Chúng tôi đã phát hiện ra rằng bạn đang sử dụng tiện ích mở rộng để chặn quảng cáo. Hãy hỗ trợ chúng tôi bằng cách tắt các trình chặn quảng cáo này.