Eclair Bitcoin Lightning Nodes Vulnerable to Persistent Crashes
Researchers have discovered an unfunded-channel flaw in Eclair, a Bitcoin Lightning implementation, that could leave nodes crashing repeatedly without an attacker spending BTC on-chain.
The issue affected reachable nodes running v0.14.0 and earlier, with saved channel records making a restart insufficient to restore service.
Erick Cestari published the persistent-crash finding Sept. 30 and explained it alongside a separate denial-of-service bug in an Oct. 1 developer post.
ACINQ now recommends the later v0.14.3 security release for separate vulnerabilities.
The flaw occurred because Eclair limited the number of pending channels a peer could open, but inconsistent checks of temporary and final channel identifiers let its counter undercount unfunded channels.