Eclair 0.14.3 displayed on a secured node as broken chains, timing risks, and fund-loss threats are blocked around the Lightning Network.
Image by CryptoSlate

A Bitcoin Lightning flaw could send a node’s entire balance straight to miners

The bug was one of three vulnerabilities ACINQ patched after finding ways malicious peers could trigger fund losses.

Quick Take

  1. ACINQ patched three Bitcoin Lightning vulnerabilities that malicious peers could exploit to drain, lock or redirect node funds.
  2. The most severe flaw could make a node’s entire local channel balance disappear into miner fees during a cooperative close.
  3. This comes as separate bots probe exposed Lightning infrastructure, raising fresh questions about the security of Bitcoin’s surrounding software stack.

A flaw in Bitcoin Lightning software Eclair could let malicious peers wipe out a node’s local channel balance through fees.

ACINQ released Eclair 0.14.3 on Sept. 14 to patch three peer-triggered vulnerabilities that could cause operators to lose or lock funds during channel closures, splicing, and on-the-fly funding.

The Bitcoin technology company, a contributor to Lightning Network development and maker of Eclair and Phoenix Wallet, strongly recommended operators upgrade because malicious nodes could exploit these issues.

Eclair's patched vulnerabilities

The most direct attack involved cooperative channel closures. When Eclair was responsible for the closing fee, an adversarial peer could propose a charge larger than the victim’s local balance. Eclair’s fallback negotiation could accept the proposal, eliminate the operator’s output and effectively send the entire local balance to Bitcoin miners as transaction fees.

The patch now rejects closing-fee proposals above an operator’s configured maximum. Bitcoin Optech described 0.14.3 as a security release addressing vulnerabilities involving channel closing, splicing and on-the-fly funding.

A second weakness could strand funds during an unfinished splice, a process that changes the transaction funding a Lightning channel without closing it. If Eclair signed first and the peer withheld its signature, the latest channel state could depend on a transaction the victim could not publish.

Infographic showing three Eclair 0.14.3 peer-triggered risks: excessive cooperative-close fees, withheld splice signatures, and a zero expiry buffer in on-the-fly funding.

That setup also created a path for losses on payments still in flight. An attacker could allow the incoming side of a relayed payment to expire, publish an older channel state, and use the payment secret to collect the outgoing leg. Eclair will now force-close using the newest state backed by a fully signed funding transaction.

The third vulnerability affected Eclair’s on-the-fly funding feature, which can open a channel while forwarding a payment. A malicious wallet could manipulate payment-expiry timing to collect the outgoing payment on-chain while the incoming payment expired, leaving the relay operator to absorb the loss.

Eclair now checks relay fees and expiry buffers before committing funds. The release also adds a default 50 satoshis-per-vByte ceiling for automatically estimated channel-opening and splice fees, limiting exposure to bad external fee data.

Bitcoin Lightning operators face widening security pressure

The fixes arrive as operators of other Lightning software confront separate attempts to compromise exposed infrastructure.

Related Reading

Critical Bitcoin Lightning bugs exposed nodes to fund theft and restart failure

Earlier this month, Bitcoin payment processor BTCPay Server said that it had observed bots repeatedly probing servers where administrators had manually re-enabled external access to LND, another Lightning implementation.

The attackers targeted an unauthenticated password-change endpoint during a brief window when an LND wallet was locked. If successful, they could replace the wallet password and request an administrator macaroon that could control the node.

BTCPay responded by introducing unique passwords for LND wallets and blocking unauthenticated wallet-management routes at its network edge. It also advised operators not to manually expose the LND API.

The incidents point to mounting security pressure across Bitcoin’s Lightning ecosystem as attackers search for software weaknesses they could use to seize or redirect funds.

Article context

Mentioned in this article

Related Asset Bitcoin #1 BTC $84,738.32 24-hour change: up 5.38% Loading price history… 24H Up 5.38% 7D Up 9.03% 30D Up 9.86%