
If a node accepts an invalid channel, loss of funds could occur if the node forwarded any payments that originated from that channel. If this happened, the victim node (that accepted the channel) would have lost an amount roughly equal to the amount of the forwarded HTLC(s). It loses this money as it cannot close the invalid channel.”According to developer and Bitcoin advocate Udi Wertheimer, few people were likely impacted by the potential vulnerability.
The Lightning Labs blog post also suggests that there have been no successful exploits of the vulnerability. However, its authors do provide a tool for node operators to test if their node had been targeted. The authors also take the opportunity to remind Lightning Network users that the software is still very much in its infancy. They stress the importance of sticking to the recommended limits on channels and updating the software to the latest version frequently. As part of its commitment to constantly improving the security and functionality of the Lightning Network, the developers have also announced the creation of a formal bug bounty program. However, more details on this are still pending. Are you surprised to see the Lightning Network suffering such teething problems? Do you think we’ll see more in the future? Leave your thoughts in the comments below.lightning vulnerability disclosed today. Make sure you upgrade
— Udi | BIP-420 🐱 (@udiWertheimer) September 27, 2019
While very few if any were likely affected, I’d say it’s pretty severe. LN implementations are still early and could use a lot of ❤️ in the form of reviews
Thanks to the 3 teams for handling this quickly and safely! https://t.co/AET8F7lwK3
Disclaimer
In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated.