Unpatched Eclair Lightning nodes may crash repeatedly on restart
How older Eclair nodes can enter a crash loop
A newly disclosed flaw in Eclair, a Bitcoin Lightning implementation, can cause older nodes to crash repeatedly when restarted. The problem does not require an attacker to spend Bitcoin on-chain. It affects nodes running version v0.14.0 and earlier.
Eclair counts how many pending channels a peer may open, but inconsistent checks let the counter undercount unfunded channels. A malicious peer can accumulate saved channel requests without broadcasting the funding transaction or paying an on-chain fee. The vulnerable node still incurs memory and database costs from those records.
When the node first crashes, the fake channel records remain on disk. On restart, Eclair reloads them and exhausts memory again. The cycle can repeat unless the operator increases the memory limit or manually removes the records.
Proof of concept results
Researcher Erick Cestari tested the flaw in Eclair v0.14.0 on Bitcoin's local regtest environment. He reported that the node filled a 4 GB Java virtual machine heap after about 47 minutes and 43 seconds, accumulating 217,623 rows in the channel database. He described this as one laboratory benchmark, not a universal attack duration. The demonstration concerns one node's availability and does not establish live exploitation or the number of unpatched nodes in the wild.
Fixes and current recommendations
Cestari published his finding on September 30. A separate denial-of-service bug was disclosed by Matt Morehouse on October 1. Both issues were fixed in Eclair v0.14.1, which shipped on July 29, before the public disclosures.
The second bug, identified as LNF-2026-0003, was a channel-opening race condition that left orphaned processes consuming memory or CPU. Morehouse's advisory says the tested node recovered on disconnect or restart without loss.
ACINQ, the company behind Eclair, now recommends upgrading to v0.14.3, released on September 14, because it addresses additional vulnerabilities that could be exploited by malicious nodes. The July minimum fix should not be read as a complete current security recommendation.
Key numbers
- Affected versions: v0.14.0 and earlier
- Proof-of-concept heap exhaustion: 4 GB after approximately 47 minutes 43 seconds
- Database rows accumulated in test: 217,623
- Original fix: v0.14.1, released July 29, 2026
- Current recommended version: v0.14.3, released September 14, 2026
Why upgrading matters
Preventing new unfunded-channel floods and recovering an already overloaded database are separate operator concerns. Node operators running Eclair v0.14.0 or earlier should upgrade to v0.14.3 to address both the original denial-of-service flaws and the separate vulnerabilities fixed in the later release.
What is still unclear
It is not confirmed whether the unfunded-channel flaw has been exploited in the wild. The article does not provide data on how many Eclair nodes remain on affected versions.