LND Nodes Running Below v0.21.0 Vulnerable to Full-Channel Wipeout
A vulnerability in the Lightning Network node implementation LND has been disclosed, allowing a malicious peer to potentially wipe out an entire channel balance. According to repository history, the official fix for this issue was included in version 0.21.0 of LND.
The attack requires a one-block Bitcoin reorganization and an old revoked commitment transaction after a cooperative close. The affected node can fail to broadcast penalty transactions designed to punish the publication of the revoked state, leading to a maximum loss condition that could reach the channel's full balance.
Operators using standard releases below 0.21.0 should treat their nodes as lacking the official fix unless they were independently patched. LND's security policy recommends running the latest minor release of the newest major line an operator can support.