{"id":33865,"date":"2022-11-02T04:20:15","date_gmt":"2022-11-02T04:20:15","guid":{"rendered":"https:\/\/egrowonline.com\/?p=33865"},"modified":"2022-11-02T04:20:15","modified_gmt":"2022-11-02T04:20:15","slug":"lightning-network-releases-emergency-update-after-critical-bug-on-lnd-nodes","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=33865","title":{"rendered":"Lightning Network releases emergency update after critical bug on LND nodes"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjItMTEvYTlkYjdlNDktZWRmMS00ZTA2LTgwZWMtY2ZhMjMwNmIwY2I4LmpwZw==.jpg\" \/><\/p>\n<div data-v-4b69a2fe=\"\">\n<p>An emergency update was\u00a0<a target=\"_blank\" href=\"https:\/\/github.com\/lightningnetwork\/lnd\/releases\/tag\/v0.15.4-beta\" rel=\"noopener nofollow\">released<\/a> to all of Lightning Network&#8217;s LND node operators on Nov. 1, after a critical bug caused LND nodes to fall out of sync chain. This was the second critical bug experienced by the network in less than a month.\u00a0<\/p>\n<p>According to Lightning Labs, developer of the Bitcoin Lightning Network, some LND nodes stopped syncing due to an issue with the btcd wire parsing library. The hot fix (v.015.4) was released nearly three hours after the break. The release stated:<\/p>\n<blockquote><p>\u201cThis is an emergency hot fix release to fix a bug that can cause lnd nodes to be unable to parse certain transactions that have a very large number of witness inputs.\u201d<\/p><\/blockquote>\n<p>As per the\u00a0<a target=\"_blank\" href=\"https:\/\/github.com\/lightningnetwork\/lnd\/issues\/7096\" rel=\"noopener nofollow\">issue<\/a> on GitHub, non-updated nodes will be vulnerable to malicious channel closings once channel timelocks expire in two weeks. The bug impacted only LND nodes, making the current chain state outdated, although payments transactions were still available. Some versions of electrs were also impacted, according to another\u00a0<a target=\"_blank\" href=\"https:\/\/github.com\/romanz\/electrs\/issues\/783\" rel=\"noopener nofollow\">issue<\/a> on GitHub. <\/p>\n<p>The bug was triggered by a developer dubbed Burak on Twitter, with a message in the transaction saying: \u201cyou&#8217;ll run cln. and you&#8217;ll be happy.\u201d <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Sometimes to find the light, we must first touch the darkness.<a target=\"_blank\" href=\"https:\/\/t.co\/dhCwF0DxpE\" rel=\"noopener\">https:\/\/t.co\/dhCwF0DxpE<\/a><\/p>\n<p>\u2014 Burak (@brqgoo) <a target=\"_blank\" href=\"https:\/\/twitter.com\/brqgoo\/status\/1587397646125260802?ref_src=twsrc%5Etfw\" rel=\"noopener\">November 1, 2022<\/a><\/p><\/blockquote>\n<p>Burak was also responsible for triggering a similar bug on Oct. 9, when they\u00a0created a 998-of-999 multisig transaction that was rejected by btcd and LND nodes, leading to the rejection of the whole block and all blocks following the transaction. On the same day, Lightning Labs released a patch to fix the issue.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">I just did a 998-of-999 tapscript multisig, and it only cost $4.90 in transaction fees.<a target=\"_blank\" href=\"https:\/\/t.co\/CvBHaRAqPu\" rel=\"noopener\">https:\/\/t.co\/CvBHaRAqPu<\/a><\/p>\n<p>\u2014 Burak (@brqgoo) <a target=\"_blank\" href=\"https:\/\/twitter.com\/brqgoo\/status\/1579216353780957185?ref_src=twsrc%5Etfw\" rel=\"noopener\">October 9, 2022<\/a><\/p><\/blockquote>\n<p><strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/bitcoin-for-beginners\/what-is-the-lightning-network-in-bitcoin-and-how-does-it-work\" rel=\"noopener\">Related:\u00a0What is the Lightning Network in Bitcoin, and how does it work?<\/a><\/strong><\/p>\n<p>On Twitter, users suggested that it was time for an LND bug bounty program:<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Savage takedown of LND lightning nodes by exploiting a consensus discrepancy between Bitcoin Core and btcd with a single Bitcoin transaction.<\/p>\n<p>Encoded message: <br \/>&#8220;you&#8217;ll run cln. and you&#8217;ll be happy.&#8221;<\/p>\n<p>Probably not a &#8220;responsible disclosure&#8221;. Time for an LND bug bounty program? <a target=\"_blank\" href=\"https:\/\/t.co\/sLZQIsS4Zt\" rel=\"noopener\">https:\/\/t.co\/sLZQIsS4Zt<\/a> <a target=\"_blank\" href=\"https:\/\/t.co\/S8HwKXdoip\" rel=\"noopener\">pic.twitter.com\/S8HwKXdoip<\/a><\/p>\n<p>\u2014 Stadicus (@Stadicus3000) <a target=\"_blank\" href=\"https:\/\/twitter.com\/Stadicus3000\/status\/1587414903324819456?ref_src=twsrc%5Etfw\" rel=\"noopener\">November 1, 2022<\/a><\/p><\/blockquote>\n<p>Hacker Anthony Towns also\u00a0<a target=\"_blank\" href=\"https:\/\/twitter.com\/ajtowns\/status\/1587414992961216512\" rel=\"noopener nofollow\">claimed<\/a> to have disclosed the vulnerability to LND developers two weeks ago, noting, \u201cThe btcd repo doesn&#8217;t seem to have a reporting policy for security bugs, so not sure if anyone else working on btcd found out about it.\u201d<\/p>\n<p>The Lightning Network is a second layer added to Bitcoin\u2019s (<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/bitcoin-price\" rel=\"noopener\">BTC<\/a>) blockchain that allows off-chain transactions, i.e. transactions between parties not on the blockchain network.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/lightning-network-releases-emergency-update-after-critical-bug-on-lnd-nodes\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An emergency update was\u00a0released to all of Lightning Network&#8217;s LND node operators on Nov. 1, after a critical bug caused LND nodes to fall out of sync chain. This was the second critical bug experienced by the network in less than a month.\u00a0 According to Lightning Labs, developer of the Bitcoin Lightning Network, some LND [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":33866,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[37],"tags":[2731,215,5117,1062,12113,175,9224,160,886],"class_list":["post-33865","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bitcoin","tag-bug","tag-critical","tag-emergency","tag-lightning","tag-lnd","tag-network","tag-nodes","tag-releases","tag-update"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2022\/11\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjItMTEvYTlkYjdlNDktZWRmMS00ZTA2LTgwZWMtY2ZhMjMwNmIwY2I4LmpwZw.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/33865","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=33865"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/33865\/revisions"}],"predecessor-version":[{"id":33867,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/33865\/revisions\/33867"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/33866"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=33865"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=33865"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=33865"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}