Critical Bitcoin Lightning bugs exposed nodes to fund theft and restart failure
Lightning Development Kit (LDK) released v0.2.6 on Sept. 9 to address two security vulnerabilities. One flaw in the splice mechanism could allow a malicious peer to misallocate fees, potentially leading to fund theft. The second issue involves payment contracts sharing the same hash, which could cause the ChannelManager to reject state data and prevent nodes from restarting. The update provides necessary fixes for these financial and operational risks.
Summaries are written by AI from the original article. Not investment advice.