Electrum Patches Lightning Flaw, But Older Bitcoin Backups Break
Electrum, a popular Bitcoin wallet, has released an update to address a security flaw in its Lightning backup exports. The patch, Electrum 4.8.2, fixes a defect that affected anchor channels and non-deterministic Lightning keys, making it difficult for users to reclaim funds from closed channels.
The issue arose when older backups were created with the faulty export feature, which deleted a randomly generated Lightning private key necessary for recovering channel funds. This meant that even if a user had a backup, they couldn't recover their coins without the lost key material.
According to Electrum's release notes, wallets based on BIP39 seeds or imported extended private keys (xprvs) have non-deterministic Lightning keys and are affected by this issue. Users who created their wallet files in version 4.0.x may also be impacted, even if they've since upgraded to a newer version.
While the latest update fixes future backup exports, users with older backups will still need to replace them. To do so, they'll require retaining the original wallet data needed for fresh export, and installing newer software doesn't guarantee recovery of lost key material.