Bitcoin Lightning Patches Critical Flaw Exposing Nodes to Fund Losses
A recent patch from ACINQ has fixed three vulnerabilities in Bitcoin Lightning software Eclair that could have allowed malicious peers to drain, lock, or redirect node funds.
The most severe flaw, if exploited, could cause a node's entire local channel balance to disappear into miner fees during a cooperative close.
Eclair 0.14.3 was released on September 14 to patch the peer-triggered vulnerabilities that could cause operators to lose or lock funds during channel closures, splicing, and on-the-fly funding.
The Bitcoin technology company strongly recommended operators upgrade due to the potential for malicious nodes to exploit these issues.