• bitcoinBitcoin (BTC) $ 104,843.00
  • ethereumEthereum (ETH) $ 2,518.60
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.14
  • bnbBNB (BNB) $ 645.42
  • solanaSolana (SOL) $ 144.49
  • usd-coinUSDC (USDC) $ 0.999712
  • dogecoinDogecoin (DOGE) $ 0.176593
  • tronTRON (TRX) $ 0.269548
  • staked-etherLido Staked Ether (STETH) $ 2,516.86
  • cardanoCardano (ADA) $ 0.627843
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 104,933.00
  • hyperliquidHyperliquid (HYPE) $ 40.46
  • wrapped-stethWrapped stETH (WSTETH) $ 3,031.96
  • suiSui (SUI) $ 2.91
  • bitcoin-cashBitcoin Cash (BCH) $ 431.36
  • chainlinkChainlink (LINK) $ 12.99
  • leo-tokenLEO Token (LEO) $ 9.06
  • stellarStellar (XLM) $ 0.256327
  • avalanche-2Avalanche (AVAX) $ 18.96
  • the-open-networkToncoin (TON) $ 2.94
  • usdsUSDS (USDS) $ 0.999663
  • shiba-inuShiba Inu (SHIB) $ 0.000012
  • wethWETH (WETH) $ 2,517.46
  • hedera-hashgraphHedera (HBAR) $ 0.156472
  • wrapped-eethWrapped eETH (WEETH) $ 2,693.70
  • litecoinLitecoin (LTC) $ 85.23
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • moneroMonero (XMR) $ 312.44
  • polkadotPolkadot (DOT) $ 3.76
  • whitebitWhiteBIT Coin (WBT) $ 39.06
  • bitget-tokenBitget Token (BGB) $ 4.54
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 105,146.00
  • pepePepe (PEPE) $ 0.000011
  • pi-networkPi Network (PI) $ 0.611321
  • uniswapUniswap (UNI) $ 7.21
  • aaveAave (AAVE) $ 272.38
  • daiDai (DAI) $ 0.999595
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
  • bittensorBittensor (TAO) $ 363.31
  • okbOKB (OKB) $ 51.57
  • internet-computerInternet Computer (ICP) $ 5.50
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • aptosAptos (APT) $ 4.48
  • crypto-com-chainCronos (CRO) $ 0.090893
  • nearNEAR Protocol (NEAR) $ 2.20
  • ethereum-classicEthereum Classic (ETC) $ 16.64
  • jito-staked-solJito Staked SOL (JITOSOL) $ 174.57
  • ondo-financeOndo (ONDO) $ 0.783008
  • susdssUSDS (SUSDS) $ 1.06
  • tokenize-xchangeTokenize Xchange (TKX) $ 29.40
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • mantleMantle (MNT) $ 0.637024
  • gatechain-tokenGate (GT) $ 16.97
  • official-trumpOfficial Trump (TRUMP) $ 10.17
  • kaspaKaspa (KAS) $ 0.073845
  • fasttokenFasttoken (FTN) $ 4.44
  • vechainVeChain (VET) $ 0.022029
  • cosmosCosmos Hub (ATOM) $ 4.10
  • skySky (SKY) $ 0.086325
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 104,258.00
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.199358
  • ethenaEthena (ENA) $ 0.291978
  • render-tokenRender (RENDER) $ 3.38
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.665790
  • filecoinFilecoin (FIL) $ 2.41
  • arbitrumArbitrum (ARB) $ 0.334161
  • worldcoin-wldWorldcoin (WLD) $ 0.972090
  • algorandAlgorand (ALGO) $ 0.177604
  • quant-networkQuant (QNT) $ 104.98
  • usdt0USDT0 (USDT0) $ 1.00
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,515.48
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998345
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.36
  • usdtbUSDtb (USDTB) $ 1.00
  • kucoin-sharesKuCoin (KCS) $ 11.19
  • spx6900SPX6900 (SPX) $ 1.38
  • binance-staked-solBinance Staked SOL (BNSOL) $ 153.05
  • flare-networksFlare (FLR) $ 0.018277
  • celestiaCelestia (TIA) $ 1.80
  • nexoNEXO (NEXO) $ 1.21
  • jupiter-exchange-solanaJupiter (JUP) $ 0.408718
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,865.11
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.81
  • fartcoinFartcoin (FARTCOIN) $ 1.18
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,635.26
  • bonkBonk (BONK) $ 0.000015
  • injective-protocolInjective (INJ) $ 11.50
  • sonic-3Sonic (S) $ 0.336915
  • story-2Story (IP) $ 3.62
  • optimismOptimism (OP) $ 0.594675
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 1.00
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999894
  • xdce-crowd-saleXDC Network (XDC) $ 0.059963
  • paypal-usdPayPal USD (PYUSD) $ 0.999649
  • blockstackStacks (STX) $ 0.627084
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,691.84
  • sei-networkSei (SEI) $ 0.175412
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,638.78
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 104,594.00
  • kaiaKaia (KAIA) $ 0.147421
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 104,621.00
  • wbnbWrapped BNB (WBNB) $ 645.26
  • immutable-xImmutable (IMX) $ 0.458341
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,652.13
  • tether-goldTether Gold (XAUT) $ 3,440.89
  • dogwifcoindogwifhat (WIF) $ 0.837789
  • pax-goldPAX Gold (PAXG) $ 3,465.78
  • the-graphThe Graph (GRT) $ 0.086875
  • vaultaVaulta (A) $ 0.526316
  • clbtcclBTC (CLBTC) $ 107,123.00
  • newton-projectAB (AB) $ 0.013090
  • curve-dao-tokenCurve DAO (CRV) $ 0.591793
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.40
  • flokiFLOKI (FLOKI) $ 0.000077
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 161.22
  • lido-daoLido DAO (LDO) $ 0.800722
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,718.22
  • zcashZcash (ZEC) $ 44.12
  • ousgOUSG (OUSG) $ 111.43
  • msolMarinade Staked SOL (MSOL) $ 187.93
  • theta-tokenTheta Network (THETA) $ 0.698092
  • galaGALA (GALA) $ 0.014959
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.999809
  • ethereum-name-serviceEthereum Name Service (ENS) $ 20.13
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.11
  • bittorrentBitTorrent (BTT) $ 0.00000067
  • jito-governance-tokenJito (JTO) $ 1.95
  • iotaIOTA (IOTA) $ 0.168132
  • the-sandboxThe Sandbox (SAND) $ 0.263308
  • jasmycoinJasmyCoin (JASMY) $ 0.013007
  • walrus-2Walrus (WAL) $ 0.455181
  • bitcoin-svBitcoin SV (BSV) $ 30.96
  • usual-usdUsual USD (USD0) $ 0.997594
  • polyhedra-networkPolyhedra Network (ZKJ) $ 1.99
  • pyth-networkPyth Network (PYTH) $ 0.105274
  • wrapped-hypeWrapped HYPE (WHYPE) $ 40.30
  • pendlePendle (PENDLE) $ 3.70
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.009527
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 104,498.00
  • raydiumRaydium (RAY) $ 2.05
  • tezosTezos (XTZ) $ 0.561438
  • aerodrome-financeAerodrome Finance (AERO) $ 0.707727
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • coredaoorgCore (CORE) $ 0.576009
  • falcon-financeFalcon USD (USDF) $ 0.998456
  • saros-financeSaros (SAROS) $ 0.214429
  • flowFlow (FLOW) $ 0.350550
  • super-oethSuper OETH (SUPEROETH) $ 2,516.14
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,515.95
  • tbtctBTC (TBTC) $ 104,794.00
  • apecoinApeCoin (APE) $ 0.683485
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,680.80
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 2,686.96
  • thorchainTHORChain (RUNE) $ 1.47
  • syrupMaple Finance (SYRUP) $ 0.474586
  • dexeDeXe (DEXE) $ 8.87
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,518.38
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 104,839.00
  • decentralandDecentraland (MANA) $ 0.262204
  • true-usdTrueUSD (TUSD) $ 0.997486
  • compound-governance-tokenCompound (COMP) $ 52.06
  • grassGrass (GRASS) $ 1.62
  • staked-hypeStaked HYPE (STHYPE) $ 40.31
  • heliumHelium (HNT) $ 2.48
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.176314
  • kavaKava (KAVA) $ 0.415517
  • chain-2Onyxcoin (XCN) $ 0.013229
  • usddUSDD (USDD) $ 0.999141
  • based-brettBrett (BRETT) $ 0.043866
  • beldexBeldex (BDX) $ 0.060572
  • morphoMorpho (MORPHO) $ 1.40
  • bridged-usdc-polygon-pos-bridgeBridged USDC (Polygon PoS Bridge) (USDC.E) $ 0.999712
  • eosEOS (EOS) $ 0.579061
  • axelarAxelar (AXL) $ 0.425731
  • ecasheCash (XEC) $ 0.000021
  • hashnote-usycCircle USYC (USYC) $ 1.09
  • aioz-networkAIOZ Network (AIOZ) $ 0.344572
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • mimblewimblecoinMimbleWimbleCoin (MWC) $ 36.93
  • apenftAPENFT (NFT) $ 0.00000041
  • dydx-chaindYdX (DYDX) $ 0.513458
  • ketKet (KET) $ 0.403703
  • usdbUSDB (USDB) $ 0.994026
  • keetaKeeta (KTA) $ 0.995740
  • aethirAethir (ATH) $ 0.039902
  • starknetStarknet (STRK) $ 0.117743
  • arweaveArweave (AR) $ 6.02
  • elrond-erd-2MultiversX (EGLD) $ 13.87
  • neoNEO (NEO) $ 5.56
  • stader-ethxStader ETHx (ETHX) $ 2,673.89
  • eigenlayerEigenlayer (EIGEN) $ 1.24
  • movementMovement (MOVE) $ 0.145864
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,517.18
  • axie-infinityAxie Infinity (AXS) $ 2.32
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • conflux-tokenConflux (CFX) $ 0.073998
  • telcoinTelcoin (TEL) $ 0.003993
  • dog-go-to-the-moon-runeDog (Bitcoin) (DOG) $ 0.003626

Bitcoin Lightning bug allows remote theft of bitcoin via LND nodes

0 26

Bitcoin Lightning bug allows remote theft of bitcoin via LND nodes

A major bug panicked Bitcoin Lightning users today. Senior Bitcoin developer “Calle” alerted node operators running software older than Lightning Network Daemon (LND) Version 0.18.5 or LITD Version 0.14.1.

The vulnerability relates to how LND checks description fields for the settlement of Lightning invoices. Clever hackers figured out a way to manipulate the payment state of such invoices to remotely drain funds.

Satoshi Labs co-founder Pavol Rusnak rang a similar alarm bell. As posts gained tens of thousands of impressions, users of the Lightning network spread the message about the imminent threat of theft.

Lightning is a mesh network of approximately 5,000 BTC that move faster and cheaper than regular, on-chain BTC. By routing payments through 44,000 public channels connecting over 16,000 nodes, Lightning users sacrifice the full security and decentralization of BTC for speed, thrift, and extra functions.

They also expose themselves to Lightning-specific bugs that don’t affect the base layer.

Patching Bitcoin Lightning nodes to LND 18.5

Newly released node softwares LND 0.18.5 and LITD 0.14.1 patch this remote threat vector. Disturbingly, LND 18.5 was just released last week, so many LND nodes are still out of date and vulnerable.

Out-of-date LND nodes number in the hundreds or low-single-digit thousands as of publication time. LND has historically been the preferred software for most Lightning node operators.

The bug involves an inability to cancel AMP invoices if they have a settled sub-invoice. Lightning developer known as ziggie1984 posted a patch request that suggested allowing AMP invoices to expire even if they have a settled sub-invoice.

Effet Cantillon posted some reassurance that merchants using Lightning Labs’ software might be fine if they don’t have their LND node interact with invoices generated by services like BTCPay.

BTCPay Server apparently upgraded its LND node to 0.18.5 just recently.

A quick review of comments to popular posts on X revealed a few real-world instances of actual theft of funds, although the vulnerability is very much live as of publication time and theft details were sparse.

All major Lightning developers recommended upgrading to the latest version of LND, which fixes the exploit.

Lightning Labs personnel, the leaders of LND, have not issued an official statement yet. A pull request on GitHub indicates that its development team was aware of the issue three weeks ago.

Source

Leave A Reply

Your email address will not be published.

Verified by MonsterInsights