A Bitcoin Lightning flaw could send a node’s entire balance straight to miners

A Bitcoin Lightning flaw could send a node’s entire balance straight to miners

Summary

ACINQ released Eclair 0.14.3 to fix three peer-triggered Lightning Network vulnerabilities that could cost operators funds during channel closures, splicing and on-the-fly funding. One flaw could let a malicious peer negotiate a closing fee that consumed the victim’s entire channel balance. Others could strand funds or exploit payment expiry to make relay operators lose money. The update rejects excessive closing fees, uses the latest fully signed channel state when force-closing, checks relay fees and expiry buffers, and caps automatically estimated channel-opening and splice fees. Separately, BTCPay Server reported bots probing exposed LND servers through a vulnerable wallet-management route and introduced protections.