ACINQ Patches Three Bitcoin Lightning Network Vulnerabilities in Eclair

ACINQ Patches Three Bitcoin Lightning Network Vulnerabilities in Eclair

ACINQ patches Eclair to stop fund-draining attacks

ACINQ released version 0.14.3 of its Bitcoin Lightning software Eclair on Sept. 14 to fix three vulnerabilities that malicious peers could exploit to drain, lock, or redirect node funds. The company, which develops Eclair and Phoenix Wallet and contributes to the Lightning Network, strongly urged operators to upgrade.

What the patched vulnerabilities did

  • Cooperative channel closures: A malicious peer could propose a closing fee larger than the victim's local balance. Eclair's fallback negotiation could accept this, eliminating the operator's output and effectively sending the entire local balance to Bitcoin miners as transaction fees.
  • Unfinished splices: If Eclair signed a state change first and the peer withheld its signature, the latest channel state could depend on a transaction the victim could not publish. An attacker could also let the incoming side of a relayed payment expire, publish an older state, and use the payment secret to collect the outgoing leg.
  • On-the-fly funding: A malicious wallet could manipulate payment-expiry timing during channel opening while forwarding a payment, collecting the outgoing payment on-chain while the incoming one expired.

How Eclair 0.14.3 fixes the problems

The update now rejects closing-fee proposals above an operator's configured maximum. It forces a close using the newest channel state backed by a fully signed funding transaction to prevent losses from unfinished splices. The on-the-fly funding feature now checks relay fees and expiry buffers before committing funds. The release also adds a default 50 satoshis-per-vByte ceiling for automatically estimated channel-opening and splice fees.

Separate bots probe other Lightning software

Bitcoin payment processor BTCPay Server reported earlier in September that bots repeatedly probed servers where administrators had manually re-enabled external access to LND, another Lightning implementation. The attackers targeted an unauthenticated password-change endpoint during a brief window when an LND wallet was locked. If successful, they could replace the wallet password and request an administrator macaroon to control the node. BTCPay responded by introducing unique passwords for LND wallets, blocking unauthenticated wallet-management routes, and advising operators not to manually expose the LND API.

Why this matters

The incidents show mounting security pressure across Bitcoin's Lightning ecosystem. Attackers are actively searching for software weaknesses they could exploit to seize or redirect funds from nodes running the Lightning Network.

What remains unclear

The sources do not specify whether any operators were actually affected by the Eclair vulnerabilities or the LND probing attempts. The full scope of the bot activity targeting Lightning infrastructure is also not detailed.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!