WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Bitcoin & Crypto SINGLE SOURCE

Lightning apps using unpatched LDK risk Bitcoin theft from a reconnect lie

A close-up view of a neoclassical building facade featuring detailed arches and columns.
Illustrative photo.Photo by Diogo Miranda on Pexels

What happened

Lightning Development Kit (LDK), a library for building Bitcoin Lightning wallets and payment applications, has patched (a fix the maker issues for a flaw in its software) a flaw that could let a malicious channel peer steal the value of a forwarded payment by lying after reconnecting. The October 1-dated v0.2.7 and v0.1.13 security releases address the LDK reconnect vulnerability on the 0.2 and 0.1 branches, respectively.

How the LDK reconnect flaw could cost Bitcoin The attack starts with a channel peer acknowledging an update, then reconnecting and pretending it never received it. The October 1-dated v0.2.7 and v0.1.13 patches close a reconnect theft path, while v0.2.7 also fixes an LSPS2 payment-amount flaw.

Affected application developers need to incorporate the fix into the software they deploy. Bitcoin Optech described the fixes in its Oct.

Sources & evidence