LND's Channel-Close Flaw Exposes Nodes to Maximum Loss
The Lightning Network node implementation LND has disclosed a channel-close flaw that could put an entire channel balance at risk in a maximum-loss scenario.
Operators using standard releases below version 0.21.0 should treat their nodes as lacking the official fix unless they were independently patched, according to LND's security policy.
The flaw allows a malicious peer to combine a one-block Bitcoin reorganization with an old, revoked commitment transaction after a cooperative close.
Bastien Teinturier, who published the disclosure, stated that no affected users were known.
The official fix starts with LND 0.21.0, and operators should not rely on the disclosure's 0.20.0 cutoff, as this would have made it seem like the patch landed earlier than it actually did.
LND's security policy recommends upgrading to the latest minor release of the newest major line an operator can support, with the project's latest official package being lnd v0.21.2-beta, released August 13.