Bitcoin Optech Newsletter #425
What happened
Both were fixed in Eclair v0.14.0 , released in May, and users still running an older version should upgrade. Each attack requires only a completed BOLT8 handshake, not a channel.
News ● Disclosure of two DoS vulnerabilities in Eclair : Matt Morehouse posted to Delving Bitcoin the responsible disclosure of two denial-of-service (DoS) vulnerabilities affecting Eclair v0.13.1 and earlier. The first vulnerability is in feature bit parsing.
Eclair parsed the feature bits in an init message one at a time, allocating several objects per bit, so a single maximum-length init message allocated and discarded about 300 MB of memory and occupied a parsing thread for up to 300 ms. In Morehouse’s tests, an attacker with a few dozen connections repeating that message disconnected all of the node’s peers within a minute and exhausted its memory within five.
Key facts
- Both were fixed in Eclair v0.14.0 , — released: in May, and users still running an older version should upgrade
- Each attack — requires: only a completed BOLT8 handshake, not a channel
Sources & evidence
- Bitcoin Optech Reporting source
Bitcoin Optech Newsletter #425 ↗
https://bitcoinops.org/en/newsletters/2026/10/02/