Funds On the Lightning Network Could be Drained by Attackers


Some nodes on the Lightning Network can potentially be “drained” by attackers, causing users to lose their BTC funds, which could put the security and stability of Bitcoin’s second layer at risk. Allegedly, there is already one victim of this exploit, who would have lost his money.

This is what some users on social networks are reporting, who claim that users running LND (Lightning Network Daemon) version 0.18.5 or earlier, and LITD (Lightning Terminal Daemon, the client's graphical interface) in its version 0.14.1 or older, could be in severe danger

LND (Lightning Network Daemon) is a Lightning Network implementation developed by Lightning Labs, which allows for the creation and management of payment channels. It is one of the most popular and widely used node clients on the Lightning Network. LITD (Lightning Terminal Daemon), on the other hand, is a graphical interface that facilitates interaction with the Daemon client, also developed by Lightning Labs.

The user who spread the word on social media about the vulnerability said it is better to update the client as quickly as possible rather than regret it, and that he received a testimony via email from someone affected by the Lightning node vulnerability. The user claims that “the victim was running Umbrel. God knows what else they were running on the same machine as their Lightning node.” Umbrel is a platform that allows you to run both Bitcoin and Lightning nodes.

So far, Lightning Labs, the core development team behind the Lightning Network, has not commented on the potential vulnerability affecting the nodes of the second layer. One of the users who reported the fact, whose pseudonym on the X network is callebtc, an open source developer, says the following:

Personally, I hate spreading rumors, but the exploit looks extremely scary. Until we know more, just update your stack and maybe stop using LITD in the meantime if it's not strictly necessary.

callebtc, user of the social network X.

Additionally, some users concerned about the vulnerability, of which only one victim has been reported, have demanded Umbrel update to the new version of Lightning clients. Currently, Umbrel is running LND 0.18.3.

How do you rate this article?

3



Blockchain Development
Blockchain Development

A blog that covers everything that's happening in crypto world.

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.