• bitcoinBitcoin (BTC) $ 118,022.00
  • ethereumEthereum (ETH) $ 3,812.50
  • xrpXRP (XRP) $ 3.14
  • tetherTether (USDT) $ 0.999828
  • bnbBNB (BNB) $ 807.89
  • solanaSolana (SOL) $ 181.80
  • usd-coinUSDC (USDC) $ 0.999803
  • staked-etherLido Staked Ether (STETH) $ 3,809.20
  • dogecoinDogecoin (DOGE) $ 0.224660
  • tronTRON (TRX) $ 0.338488
  • cardanoCardano (ADA) $ 0.786382
  • wrapped-stethWrapped stETH (WSTETH) $ 4,605.38
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 117,902.00
  • hyperliquidHyperliquid (HYPE) $ 43.43
  • stellarStellar (XLM) $ 0.421895
  • suiSui (SUI) $ 3.81
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,096.46
  • chainlinkChainlink (LINK) $ 17.88
  • bitcoin-cashBitcoin Cash (BCH) $ 570.42
  • hedera-hashgraphHedera (HBAR) $ 0.260270
  • wrapped-eethWrapped eETH (WEETH) $ 4,084.56
  • avalanche-2Avalanche (AVAX) $ 24.38
  • wethWETH (WETH) $ 3,814.07
  • litecoinLitecoin (LTC) $ 109.08
  • leo-tokenLEO Token (LEO) $ 8.96
  • the-open-networkToncoin (TON) $ 3.40
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • usdsUSDS (USDS) $ 0.999731
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999488
  • whitebitWhiteBIT Coin (WBT) $ 44.12
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 118,003.00
  • uniswapUniswap (UNI) $ 10.45
  • polkadotPolkadot (DOT) $ 3.90
  • moneroMonero (XMR) $ 316.52
  • bitget-tokenBitget Token (BGB) $ 4.57
  • pepePepe (PEPE) $ 0.000012
  • crypto-com-chainCronos (CRO) $ 0.144550
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.19
  • aaveAave (AAVE) $ 283.66
  • daiDai (DAI) $ 0.999845
  • ethenaEthena (ENA) $ 0.583961
  • bittensorBittensor (TAO) $ 383.38
  • nearNEAR Protocol (NEAR) $ 2.73
  • ethereum-classicEthereum Classic (ETC) $ 21.84
  • pi-networkPi Network (PI) $ 0.426875
  • aptosAptos (APT) $ 4.57
  • ondo-financeOndo (ONDO) $ 0.959789
  • internet-computerInternet Computer (ICP) $ 5.46
  • jito-staked-solJito Staked SOL (JITOSOL) $ 221.87
  • okbOKB (OKB) $ 48.08
  • mantleMantle (MNT) $ 0.767239
  • kaspaKaspa (KAS) $ 0.095682
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.037739
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,811.89
  • algorandAlgorand (ALGO) $ 0.261322
  • bonkBonk (BONK) $ 0.000029
  • usd1-wlfiUSD1 (USD1) $ 0.998854
  • arbitrumArbitrum (ARB) $ 0.425073
  • vechainVeChain (VET) $ 0.025252
  • cosmosCosmos Hub (ATOM) $ 4.58
  • gatechain-tokenGate (GT) $ 17.65
  • render-tokenRender (RENDER) $ 3.91
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.221925
  • fasttokenFasttoken (FTN) $ 4.59
  • worldcoin-wldWorldcoin (WLD) $ 1.08
  • official-trumpOfficial Trump (TRUMP) $ 9.48
  • spx6900SPX6900 (SPX) $ 2.03
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.710228
  • skySky (SKY) $ 0.086499
  • sei-networkSei (SEI) $ 0.317739
  • binance-staked-solBinance Staked SOL (BNSOL) $ 193.65
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,343.36
  • susdssUSDS (SUSDS) $ 1.06
  • filecoinFilecoin (FIL) $ 2.57
  • flare-networksFlare (FLR) $ 0.024778
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,999.92
  • story-2Story (IP) $ 5.63
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 117,888.00
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.06
  • xdce-crowd-saleXDC Network (XDC) $ 0.099955
  • jupiter-exchange-solanaJupiter (JUP) $ 0.536150
  • kucoin-sharesKuCoin (KCS) $ 11.37
  • usdtbUSDtb (USDTB) $ 0.999688
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,024.52
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,078.24
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,118.25
  • injective-protocolInjective (INJ) $ 14.17
  • curve-dao-tokenCurve DAO (CRV) $ 0.998338
  • usdt0USDT0 (USDT0) $ 1.00
  • celestiaCelestia (TIA) $ 1.86
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998018
  • nexoNEXO (NEXO) $ 1.32
  • optimismOptimism (OP) $ 0.723619
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,014.21
  • blockstackStacks (STX) $ 0.776510
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 0.999545
  • falcon-financeFalcon USD (USDF) $ 0.999726
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 118,041.00
  • flokiFLOKI (FLOKI) $ 0.000116
  • fartcoinFartcoin (FARTCOIN) $ 1.10
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 204.71
  • wbnbWrapped BNB (WBNB) $ 807.52
  • immutable-xImmutable (IMX) $ 0.553360
  • conflux-tokenConflux (CFX) $ 0.204260
  • the-graphThe Graph (GRT) $ 0.101614
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999788
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.87
  • sonic-3Sonic (S) $ 0.307034
  • dogwifcoindogwifhat (WIF) $ 0.990426
  • pump-funPump.fun (PUMP) $ 0.002760
  • ethereum-name-serviceEthereum Name Service (ENS) $ 28.79
  • paypal-usdPayPal USD (PYUSD) $ 0.999703
  • pax-goldPAX Gold (PAXG) $ 3,337.01
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 117,934.00
  • msolMarinade Staked SOL (MSOL) $ 238.72
  • lido-daoLido DAO (LDO) $ 1.05
  • kaiaKaia (KAIA) $ 0.159459
  • saros-financeSaros (SAROS) $ 0.355096
  • clbtcclBTC (CLBTC) $ 120,697.00
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.11
  • tezosTezos (XTZ) $ 0.856016
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.37
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,802.36
  • vaultaVaulta (A) $ 0.544066
  • theta-tokenTheta Network (THETA) $ 0.850561
  • tether-goldTether Gold (XAUT) $ 3,331.55
  • super-oethSuper OETH (SUPEROETH) $ 3,812.31
  • raydiumRaydium (RAY) $ 3.05
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,076.44
  • iotaIOTA (IOTA) $ 0.202470
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,916.04
  • jasmycoinJasmyCoin (JASMY) $ 0.016108
  • galaGALA (GALA) $ 0.016752
  • pendlePendle (PENDLE) $ 4.45
  • pyth-networkPyth Network (PYTH) $ 0.126298
  • the-sandboxThe Sandbox (SAND) $ 0.294036
  • aerodrome-financeAerodrome Finance (AERO) $ 0.827257
  • ousgOUSG (OUSG) $ 111.98
  • bittorrentBitTorrent (BTT) $ 0.00000070
  • jito-governance-tokenJito (JTO) $ 1.90
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.08
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.997303
  • tbtctBTC (TBTC) $ 117,783.00
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,814.60
  • zcashZcash (ZEC) $ 40.07
  • flowFlow (FLOW) $ 0.394766
  • newton-projectAB (AB) $ 0.008567
  • heliumHelium (HNT) $ 3.21
  • stader-ethxStader ETHx (ETHX) $ 4,056.78
  • walrus-2Walrus (WAL) $ 0.425372
  • usual-usdUsual USD (USD0) $ 0.997669
  • morphoMorpho (MORPHO) $ 1.80
  • ripple-usdRipple USD (RLUSD) $ 0.999553
  • decentralandDecentraland (MANA) $ 0.300994
  • memecoreMemeCore (M) $ 0.346105
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.224559
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 117,950.00
  • usddUSDD (USDD) $ 0.999660
  • mog-coinMog Coin (MOG) $ 0.000001
  • syrupMaple Finance (SYRUP) $ 0.466057
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,814.08
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 116,831.00
  • bitcoin-svBitcoin SV (BSV) $ 27.87
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,204.09
  • beldexBeldex (BDX) $ 0.076034
  • chain-2Onyxcoin (XCN) $ 0.015736
  • coredaoorgCore (CORE) $ 0.536579
  • build-onBUILDon (B) $ 0.531970
  • based-brettBrett (BRETT) $ 0.052677
  • keetaKeeta (KTA) $ 1.25
  • swethSwell Ethereum (SWETH) $ 4,173.62
  • reserve-rights-tokenReserve Rights (RSR) $ 0.008525
  • ether-fiEther.fi (ETHFI) $ 1.19
  • thorchainTHORChain (RUNE) $ 1.41
  • true-usdTrueUSD (TUSD) $ 0.997322
  • telcoinTelcoin (TEL) $ 0.005361
  • arweaveArweave (AR) $ 7.51
  • apecoinApeCoin (APE) $ 0.613273
  • apenftAPENFT (NFT) $ 0.00000049
  • starknetStarknet (STRK) $ 0.127397
  • neoNEO (NEO) $ 6.48
  • savings-daiSavings Dai (SDAI) $ 1.16
  • wrapped-hypeWrapped HYPE (WHYPE) $ 43.48
  • frax-etherFrax Ether (FRXETH) $ 3,796.84
  • compound-governance-tokenCompound (COMP) $ 47.74
  • aioz-networkAIOZ Network (AIOZ) $ 0.377821
  • dydx-chaindYdX (DYDX) $ 0.593532
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,809.12
  • zebec-networkZebec Network (ZBCN) $ 0.005117
  • ecasheCash (XEC) $ 0.000022
  • elrond-erd-2MultiversX (EGLD) $ 15.17
  • sun-tokenSun Token (SUN) $ 0.022481
  • wemix-tokenWEMIX (WEMIX) $ 0.942191
  • treehouse-ethTreehouse ETH (TETH) $ 4,617.30
  • dexeDeXe (DEXE) $ 7.34
  • kavaKava (KAVA) $ 0.386543
  • deepDeepBook (DEEP) $ 0.166381
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.31

Bitcoin Lightning bug allows remote theft of bitcoin via LND nodes

0 34

Bitcoin Lightning bug allows remote theft of bitcoin via LND nodes

A major bug panicked Bitcoin Lightning users today. Senior Bitcoin developer “Calle” alerted node operators running software older than Lightning Network Daemon (LND) Version 0.18.5 or LITD Version 0.14.1.

The vulnerability relates to how LND checks description fields for the settlement of Lightning invoices. Clever hackers figured out a way to manipulate the payment state of such invoices to remotely drain funds.

Satoshi Labs co-founder Pavol Rusnak rang a similar alarm bell. As posts gained tens of thousands of impressions, users of the Lightning network spread the message about the imminent threat of theft.

Lightning is a mesh network of approximately 5,000 BTC that move faster and cheaper than regular, on-chain BTC. By routing payments through 44,000 public channels connecting over 16,000 nodes, Lightning users sacrifice the full security and decentralization of BTC for speed, thrift, and extra functions.

They also expose themselves to Lightning-specific bugs that don’t affect the base layer.

Patching Bitcoin Lightning nodes to LND 18.5

Newly released node softwares LND 0.18.5 and LITD 0.14.1 patch this remote threat vector. Disturbingly, LND 18.5 was just released last week, so many LND nodes are still out of date and vulnerable.

Out-of-date LND nodes number in the hundreds or low-single-digit thousands as of publication time. LND has historically been the preferred software for most Lightning node operators.

The bug involves an inability to cancel AMP invoices if they have a settled sub-invoice. Lightning developer known as ziggie1984 posted a patch request that suggested allowing AMP invoices to expire even if they have a settled sub-invoice.

Effet Cantillon posted some reassurance that merchants using Lightning Labs’ software might be fine if they don’t have their LND node interact with invoices generated by services like BTCPay.

BTCPay Server apparently upgraded its LND node to 0.18.5 just recently.

A quick review of comments to popular posts on X revealed a few real-world instances of actual theft of funds, although the vulnerability is very much live as of publication time and theft details were sparse.

All major Lightning developers recommended upgrading to the latest version of LND, which fixes the exploit.

Lightning Labs personnel, the leaders of LND, have not issued an official statement yet. A pull request on GitHub indicates that its development team was aware of the issue three weeks ago.

Source

Leave A Reply

Your email address will not be published.

Verified by MonsterInsights