LND Channel-Close Flaw Exposes Lightning Nodes to Full-Channel Wipeout
The Lightning Network node implementation LND has disclosed a critical channel-close flaw that can put entire channel balances at risk. The vulnerability, described in an August 13 disclosure, allows a malicious peer to combine a one-block Bitcoin reorganization with an old, revoked commitment transaction after a cooperative close.
Bastien Teinturier, the author of the disclosure, noted that no affected users were known to have been targeted by this attack. However, operators using standard releases below 0.21.0 should treat their nodes as lacking the official fix unless they were independently patched.
The flaw is specific to LND and does not suggest that other Lightning implementations share the same channel-close issue. The official fix starts with LND 0.21.0, which was released on August 13. However, upstream repository history places the official fix in 0.21.0, not the 0.20.0 version cited by the public disclosure.
LND's security policy recommends the latest minor release of the newest major line an operator can support. As of August 25, the project's latest official package was lnd v0.21.2-beta.