Lightning apps using unpatched LDK risk Bitcoin theft from a reconnect lie
What happened
Lightning Development Kit (LDK), a library for building Bitcoin Lightning wallets and payment applications, has patched (a fix the maker issues for a flaw in its software) a flaw that could let a malicious channel peer steal the value of a forwarded payment by lying after reconnecting. The October 1-dated v0.2.7 and v0.1.13 security releases address the LDK reconnect vulnerability on the 0.2 and 0.1 branches, respectively.
How the LDK reconnect flaw could cost Bitcoin The attack starts with a channel peer acknowledging an update, then reconnecting and pretending it never received it. The October 1-dated v0.2.7 and v0.1.13 patches close a reconnect theft path, while v0.2.7 also fixes an LSPS2 payment-amount flaw.
Affected application developers need to incorporate the fix into the software they deploy. Bitcoin Optech described the fixes in its Oct.
Sources & evidence
- CryptoSlate Reporting source
Lightning apps using unpatched LDK risk Bitcoin theft from a reconnect lie ↗
https://cryptoslate.com/unpatched-ldk-apps-can-lose-bitcoin-when-a-lightning-peer-lies-after-reconnecting/