Eclair Update Patches Vulnerabilities Exposing Nodes to Malicious Attacks
ACINQ has released an update for its Bitcoin Lightning software Eclair to patch three peer-triggered vulnerabilities that could allow malicious nodes to wipe out a node's local channel balance through fees.
The most direct attack involved cooperative channel closures, where an adversarial peer could propose a charge larger than the victim's local balance. If accepted, this would eliminate the operator's output and send the entire local balance to Bitcoin miners as transaction fees.
The update, version 0.14.3, now rejects closing-fee proposals above an operator's configured maximum. It also addresses vulnerabilities in channel splicing and on-the-fly funding, which could strand funds during an unfinished splice or allow attackers to collect payments while the incoming side of a relayed payment expires.
ACINQ strongly recommends operators upgrade to the latest version, citing the potential for malicious nodes to exploit these issues. The company has been working closely with the Bitcoin community to address security concerns and ensure the integrity of the Lightning Network.