• bitcoinBitcoin (BTC) $ 94,689.00
  • ethereumEthereum (ETH) $ 1,795.92
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.30
  • bnbBNB (BNB) $ 605.41
  • solanaSolana (SOL) $ 147.69
  • usd-coinUSDC (USDC) $ 0.999900
  • dogecoinDogecoin (DOGE) $ 0.178223
  • cardanoCardano (ADA) $ 0.701996
  • tronTRON (TRX) $ 0.247896
  • staked-etherLido Staked Ether (STETH) $ 1,794.21
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 94,503.00
  • suiSui (SUI) $ 3.55
  • chainlinkChainlink (LINK) $ 14.99
  • avalanche-2Avalanche (AVAX) $ 21.79
  • stellarStellar (XLM) $ 0.282727
  • leo-tokenLEO Token (LEO) $ 8.98
  • the-open-networkToncoin (TON) $ 3.26
  • hedera-hashgraphHedera (HBAR) $ 0.191130
  • shiba-inuShiba Inu (SHIB) $ 0.000014
  • usdsUSDS (USDS) $ 0.999835
  • wrapped-stethWrapped stETH (WSTETH) $ 2,155.61
  • bitcoin-cashBitcoin Cash (BCH) $ 353.27
  • litecoinLitecoin (LTC) $ 85.44
  • polkadotPolkadot (DOT) $ 4.25
  • hyperliquidHyperliquid (HYPE) $ 17.88
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999987
  • bitget-tokenBitget Token (BGB) $ 4.40
  • wethWETH (WETH) $ 1,793.39
  • ethena-usdeEthena USDe (USDE) $ 0.999482
  • moneroMonero (XMR) $ 255.13
  • pi-networkPi Network (PI) $ 0.616007
  • whitebitWhiteBIT Coin (WBT) $ 29.36
  • wrapped-eethWrapped eETH (WEETH) $ 1,912.36
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 94,682.00
  • pepePepe (PEPE) $ 0.000009
  • aptosAptos (APT) $ 5.55
  • uniswapUniswap (UNI) $ 5.42
  • bittensorBittensor (TAO) $ 374.92
  • daiDai (DAI) $ 1.00
  • nearNEAR Protocol (NEAR) $ 2.62
  • okbOKB (OKB) $ 52.00
  • ondo-financeOndo (ONDO) $ 0.976059
  • official-trumpOfficial Trump (TRUMP) $ 14.53
  • susdssUSDS (SUSDS) $ 1.05
  • gatechain-tokenGate (GT) $ 22.23
  • internet-computerInternet Computer (ICP) $ 5.11
  • ethereum-classicEthereum Classic (ETC) $ 16.95
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • crypto-com-chainCronos (CRO) $ 0.090732
  • aaveAave (AAVE) $ 165.36
  • tokenize-xchangeTokenize Xchange (TKX) $ 31.06
  • kaspaKaspa (KAS) $ 0.095247
  • mantleMantle (MNT) $ 0.730970
  • vechainVeChain (VET) $ 0.027330
  • render-tokenRender (RENDER) $ 4.47
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.17
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.239313
  • cosmosCosmos Hub (ATOM) $ 4.49
  • algorandAlgorand (ALGO) $ 0.231247
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 94,432.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.716253
  • ethenaEthena (ENA) $ 0.334057
  • fasttokenFasttoken (FTN) $ 4.29
  • filecoinFilecoin (FIL) $ 2.77
  • celestiaCelestia (TIA) $ 2.92
  • sonic-3Sonic (prev. FTM) (S) $ 0.520980
  • bonkBonk (BONK) $ 0.000021
  • arbitrumArbitrum (ARB) $ 0.336307
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.10
  • worldcoin-wldWorldcoin (WLD) $ 1.14
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999095
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 94,536.00
  • kucoin-sharesKuCoin (KCS) $ 10.66
  • jupiter-exchange-solanaJupiter (JUP) $ 0.466351
  • optimismOptimism (OP) $ 0.787118
  • blockstackStacks (STX) $ 0.845670
  • makerMaker (MKR) $ 1,508.97
  • xdce-crowd-saleXDC Network (XDC) $ 0.079974
  • binance-staked-solBinance Staked SOL (BNSOL) $ 154.85
  • nexoNEXO (NEXO) $ 1.21
  • flare-networksFlare (FLR) $ 0.018388
  • fartcoinFartcoin (FARTCOIN) $ 1.11
  • sei-networkSei (SEI) $ 0.215237
  • story-2Story (IP) $ 4.04
  • binance-peg-wethBinance-Peg WETH (WETH) $ 1,795.62
  • immutable-xImmutable (IMX) $ 0.589210
  • eosEOS (EOS) $ 0.693470
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 1,868.98
  • injective-protocolInjective (INJ) $ 10.03
  • usdt0USDT0 (USDT0) $ 1.00
  • the-graphThe Graph (GRT) $ 0.098661
  • wbnbWrapped BNB (WBNB) $ 605.42
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.39
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • curve-dao-tokenCurve DAO (CRV) $ 0.647471
  • flokiFLOKI (FLOKI) $ 0.000088
  • raydiumRaydium (RAY) $ 2.93
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,035.36
  • iotaIOTA (IOTA) $ 0.222910
  • tether-goldTether Gold (XAUT) $ 3,337.14
  • jasmycoinJasmyCoin (JASMY) $ 0.016751
  • solv-protocol-solvbtc-bbnSolv Protocol xSolvBTC (XSOLVBTC) $ 93,258.00
  • coredaoorgCore (CORE) $ 0.797224
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 1.00
  • bitcoin-svBitcoin SV (BSV) $ 39.92
  • pax-goldPAX Gold (PAXG) $ 3,339.77
  • walrus-2Walrus (WAL) $ 0.622768
  • galaGALA (GALA) $ 0.017318
  • theta-tokenTheta Network (THETA) $ 0.758007
  • lido-daoLido DAO (LDO) $ 0.842820
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.012006
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 94,694.00
  • dexeDeXe (DEXE) $ 13.16
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 163.05
  • heliumHelium (HNT) $ 4.07
  • the-sandboxThe Sandbox (SAND) $ 0.300574
  • clbtcclBTC (CLBTC) $ 95,036.00
  • msolMarinade Staked SOL (MSOL) $ 190.28
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • bittorrentBitTorrent (BTT) $ 0.00000073
  • mantle-staked-etherMantle Staked Ether (METH) $ 1,910.62
  • kaiaKaia (KAIA) $ 0.115189
  • usual-usdUsual USD (USD0) $ 0.997869
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.08
  • flowFlow (FLOW) $ 0.406751
  • based-brettBrett (BRETT) $ 0.063927
  • chain-2Onyxcoin (XCN) $ 0.018875
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.999421
  • dogwifcoindogwifhat (WIF) $ 0.623042
  • solayerSolayer (LAYER) $ 2.92
  • ethereum-name-serviceEthereum Name Service (ENS) $ 18.10
  • decentralandDecentraland (MANA) $ 0.319926
  • movementMovement (MOVE) $ 0.241607
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • jito-governance-tokenJito (JTO) $ 1.82
  • pyth-networkPyth Network (PYTH) $ 0.160330
  • tezosTezos (XTZ) $ 0.552647
  • zcashZcash (ZEC) $ 35.75
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 1,877.81
  • deepDeepBook (DEEP) $ 0.221648
  • pendlePendle (PENDLE) $ 3.38
  • spx6900SPX6900 (SPX) $ 0.582585
  • reserve-rights-tokenReserve Rights (RSR) $ 0.009334
  • mantra-daoMANTRA (OM) $ 0.532306
  • dydx-chaindYdX (DYDX) $ 0.657323
  • kavaKava (KAVA) $ 0.458973
  • true-usdTrueUSD (TUSD) $ 0.999370
  • telcoinTelcoin (TEL) $ 0.005396
  • aerodrome-financeAerodrome Finance (AERO) $ 0.610474
  • elrond-erd-2MultiversX (EGLD) $ 17.45
  • sonic-bridged-usdc-e-sonicSonic Bridged USDC.e (Sonic) (USDC.E) $ 0.999897
  • thorchainTHORChain (RUNE) $ 1.39
  • ubtcuBTC (UBTC) $ 94,865.00
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 94,636.00
  • beldexBeldex (BDX) $ 0.067085
  • pumpbtcpumpBTC (PUMPBTC) $ 92,419.00
  • aioz-networkAIOZ Network (AIOZ) $ 0.401089
  • bridged-usdc-polygon-pos-bridgeBridged USDC (Polygon PoS Bridge) (USDC.E) $ 0.999898
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 1,883.97
  • arweaveArweave (AR) $ 7.11
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.178137
  • grassGrass (GRASS) $ 1.64
  • ecasheCash (XEC) $ 0.000023
  • neoNEO (NEO) $ 6.32
  • starknetStarknet (STRK) $ 0.151911
  • apecoinApeCoin (APE) $ 0.544257
  • tbtctBTC (TBTC) $ 94,412.00
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 1,795.82
  • ousgOUSG (OUSG) $ 110.86
  • apenftAPENFT (NFT) $ 0.00000042
  • conflux-tokenConflux (CFX) $ 0.081298
  • axie-infinityAxie Infinity (AXS) $ 2.59
  • matic-networkPolygon (MATIC) $ 0.239466
  • wormholeWormhole (W) $ 0.089670
  • hashnote-usycHashnote USYC (USYC) $ 1.09
  • usdbUSDB (USDB) $ 0.999686
  • chilizChiliz (CHZ) $ 0.042352
  • berachain-beraBerachain (BERA) $ 3.66
  • justJUST (JST) $ 0.039963
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 1,911.86
  • super-oethSuper OETH (SUPEROETHB) $ 1,793.93
  • beam-2Beam (BEAM) $ 0.007286
  • compound-governance-tokenCompound (COMP) $ 42.48
  • popcatPopcat (POPCAT) $ 0.386199
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 1,796.41
  • olympusOlympus (OHM) $ 21.62
  • turboTurbo (TURBO) $ 0.005074
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.999924
  • amp-tokenAmp (AMP) $ 0.004130
  • roninRonin (RON) $ 0.560220
  • axelarAxelar (AXL) $ 0.366591
  • saros-financeSaros (SAROS) $ 0.131760
  • sun-tokenSun Token (SUN) $ 0.017938
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000063
  • usddUSDD (USDD) $ 1.00
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.816768
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 1,777.24
  • plumePlume (PLUME) $ 0.168635

Bitcoin Lightning bug allows remote theft of bitcoin via LND nodes

0 17

Bitcoin Lightning bug allows remote theft of bitcoin via LND nodes

A major bug panicked Bitcoin Lightning users today. Senior Bitcoin developer “Calle” alerted node operators running software older than Lightning Network Daemon (LND) Version 0.18.5 or LITD Version 0.14.1.

The vulnerability relates to how LND checks description fields for the settlement of Lightning invoices. Clever hackers figured out a way to manipulate the payment state of such invoices to remotely drain funds.

Satoshi Labs co-founder Pavol Rusnak rang a similar alarm bell. As posts gained tens of thousands of impressions, users of the Lightning network spread the message about the imminent threat of theft.

Lightning is a mesh network of approximately 5,000 BTC that move faster and cheaper than regular, on-chain BTC. By routing payments through 44,000 public channels connecting over 16,000 nodes, Lightning users sacrifice the full security and decentralization of BTC for speed, thrift, and extra functions.

They also expose themselves to Lightning-specific bugs that don’t affect the base layer.

Patching Bitcoin Lightning nodes to LND 18.5

Newly released node softwares LND 0.18.5 and LITD 0.14.1 patch this remote threat vector. Disturbingly, LND 18.5 was just released last week, so many LND nodes are still out of date and vulnerable.

Out-of-date LND nodes number in the hundreds or low-single-digit thousands as of publication time. LND has historically been the preferred software for most Lightning node operators.

The bug involves an inability to cancel AMP invoices if they have a settled sub-invoice. Lightning developer known as ziggie1984 posted a patch request that suggested allowing AMP invoices to expire even if they have a settled sub-invoice.

Effet Cantillon posted some reassurance that merchants using Lightning Labs’ software might be fine if they don’t have their LND node interact with invoices generated by services like BTCPay.

BTCPay Server apparently upgraded its LND node to 0.18.5 just recently.

A quick review of comments to popular posts on X revealed a few real-world instances of actual theft of funds, although the vulnerability is very much live as of publication time and theft details were sparse.

All major Lightning developers recommended upgrading to the latest version of LND, which fixes the exploit.

Lightning Labs personnel, the leaders of LND, have not issued an official statement yet. A pull request on GitHub indicates that its development team was aware of the issue three weeks ago.

Source

Leave A Reply

Your email address will not be published.

Verified by MonsterInsights