Eclair v0.14.2 Hardens Node Edges, ACINQ Urges Upgrade
ACINQ published **Eclair v0.14.2** on August 26 and says it "highly recommends" upgrading because malicious nodes can exploit some of the fixed issues ([ACINQ release](https://github.com/ACINQ/eclair/releases/tag/v0.14.2)). The project does not say those issues are being actively exploited. The release caps pending unauthenticated connections, limits gossip queries that can consume routing-table resources, and makes `safecookie` the default for Tor control authentication. Its notes also describe fixes affecting channel reserves and on-the-fly funding. ACINQ says `bitcoind` should run on the same machine as Eclair or connect through an encrypted, authenticated tunnel. The patch is compatible with previous Eclair versions: operators do not need to close channels; they can stop Eclair, upgrade, and restart.
Primary record: github.com