Eclair Patch Secures Bitcoin Lightning Against Critical Node Drain Vulnerability
A critical vulnerability in Bitcoin's Lightning software Eclair has been patched by its developer ACINQ. The flaw, which could have allowed malicious nodes to drain a node's entire balance, was discovered and addressed in version 0.14.3, released on September 14.
The most direct attack involved cooperative channel closures, where an adversarial peer could propose a charge larger than the victim's local balance. Eclair's fallback negotiation could accept the proposal, effectively sending the entire local balance to Bitcoin miners as transaction fees.
ACINQ strongly recommended operators upgrade immediately, as malicious nodes could exploit these issues.