Eclair Bitcoin Lightning Nodes Vulnerable to Persistent Crashes
A Bitcoin Lightning implementation called Eclair has been found to have an unpatched vulnerability that could cause it to crash repeatedly when restarted, even after a fix was released in July.
The issue, discovered by researcher Erick Cestari, affects nodes running version v0.14.0 and earlier of Eclair's software.
Cestari found that malicious peers can accumulate saved channel requests without broadcasting the funding transaction or paying an on-chain fee, which would normally be required to fund a channel.
This distinction matters because it means the vulnerable node incurs memory and database costs even before the funding transaction is committed.