WirePolicy
LND Flaw Put Pre-0.20.0 Channel Funds at Risk After Reorg
Crossed the Wire · 00:12 UTC · at block 964,364Source published · 00:00 UTC
An LND vulnerability fixed in v0.20.0 could let a malicious channel peer take up to the full channel balance if a collaborative close received one confirmation, that block was reorganized out and the attacker then broadcast a revoked commitment. Before the fix, LND forgot the closed channel after the first confirmation and would not publish the penalty transaction; merged PR #10331 now waits for multiple confirmations and tracks replacement spends through reorgs. Discloser Bastien Teinturier says no affected users are known; operators running pre-0.20.0 should upgrade to a maintained release.
Primary record: delvingbitcoin.org