Unpatched Eclair Lightning nodes may crash repeatedly on restart

Unpatched Eclair Lightning nodes may crash repeatedly on restart

How older Eclair nodes can enter a crash loop

A newly disclosed flaw in Eclair, a Bitcoin Lightning implementation, can cause older nodes to crash repeatedly when restarted. The problem does not require an attacker to spend Bitcoin on-chain. It affects nodes running version v0.14.0 and earlier.

Eclair counts how many pending channels a peer may open, but inconsistent checks let the counter undercount unfunded channels. A malicious peer can accumulate saved channel requests without broadcasting the funding transaction or paying an on-chain fee. The vulnerable node still incurs memory and database costs from those records.

When the node first crashes, the fake channel records remain on disk. On restart, Eclair reloads them and exhausts memory again. The cycle can repeat unless the operator increases the memory limit or manually removes the records.

Proof of concept results

Researcher Erick Cestari tested the flaw in Eclair v0.14.0 on Bitcoin's local regtest environment. He reported that the node filled a 4 GB Java virtual machine heap after about 47 minutes and 43 seconds, accumulating 217,623 rows in the channel database. He described this as one laboratory benchmark, not a universal attack duration. The demonstration concerns one node's availability and does not establish live exploitation or the number of unpatched nodes in the wild.

Fixes and current recommendations

Cestari published his finding on September 30. A separate denial-of-service bug was disclosed by Matt Morehouse on October 1. Both issues were fixed in Eclair v0.14.1, which shipped on July 29, before the public disclosures.

The second bug, identified as LNF-2026-0003, was a channel-opening race condition that left orphaned processes consuming memory or CPU. Morehouse's advisory says the tested node recovered on disconnect or restart without loss.

ACINQ, the company behind Eclair, now recommends upgrading to v0.14.3, released on September 14, because it addresses additional vulnerabilities that could be exploited by malicious nodes. The July minimum fix should not be read as a complete current security recommendation.

Key numbers

  • Affected versions: v0.14.0 and earlier
  • Proof-of-concept heap exhaustion: 4 GB after approximately 47 minutes 43 seconds
  • Database rows accumulated in test: 217,623
  • Original fix: v0.14.1, released July 29, 2026
  • Current recommended version: v0.14.3, released September 14, 2026

Why upgrading matters

Preventing new unfunded-channel floods and recovering an already overloaded database are separate operator concerns. Node operators running Eclair v0.14.0 or earlier should upgrade to v0.14.3 to address both the original denial-of-service flaws and the separate vulnerabilities fixed in the later release.

What is still unclear

It is not confirmed whether the unfunded-channel flaw has been exploited in the wild. The article does not provide data on how many Eclair nodes remain on affected versions.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!