Lightning Community releases emergency replace after important bug on LND nodes

Deal Score0
Deal Score0

An emergency replace was released to all of Lightning Community’s LND node operators on Nov. 1, after a important bug precipitated LND nodes to fall out of sync chain. This was the second important bug skilled by the community in lower than a month. 

In accordance with Lightning Labs, developer of the Bitcoin Lightning Community, some LND nodes stopped syncing as a consequence of a problem with the btcd wire parsing library. The new repair (v.015.4) was launched practically three hours after the break. The discharge acknowledged:

“That is an emergency scorching repair launch to repair a bug that may trigger lnd nodes to be unable to parse sure transactions which have a really giant variety of witness inputs.”

As per the issue on GitHub, non-updated nodes can be weak to malicious channel closings as soon as channel timelocks expire in two weeks. The bug impacted solely LND nodes, making the present chain state outdated, though funds transactions had been nonetheless out there. Some variations of electrs had been additionally impacted, in accordance with one other issue on GitHub.

The bug was triggered by a developer dubbed Burak on Twitter, with a message within the transaction saying: “you may run cln. and you will be pleased.”

Burak was additionally liable for triggering an analogous bug on Oct. 9, once they created a 998-of-999 multisig transaction that was rejected by btcd and LND nodes, resulting in the rejection of the entire block and all blocks following the transaction. On the identical day, Lightning Labs launched a patch to repair the difficulty.

Related: What is the Lightning Network in Bitcoin, and how does it work?

On Twitter, customers instructed that it was time for an LND bug bounty program:

Hacker Anthony Cities additionally claimed to have disclosed the vulnerability to LND builders two weeks in the past, noting, “The btcd repo does not appear to have a reporting coverage for safety bugs, so unsure if anybody else engaged on btcd came upon about it.”

The Lightning Community is a second layer added to Bitcoin’s (BTC) blockchain that permits off-chain transactions, i.e. transactions between events not on the blockchain community.