Lightning apps using unpatched LDK risk Bitcoin theft from a reconnect lie

Lightning apps using unpatched LDK risk Bitcoin theft from a reconnect lie

Summary

LDK released security fixes in versions 0.2.7 and 0.1.13 for a reconnect flaw that could let a malicious Lightning channel peer cause a forwarding application to pay a recipient without recovering the incoming funds. The fix limits retransmission to updates awaiting acknowledgment and force-closes channels when peers deny receiving acknowledged updates. Version 0.2.7 also fixes an LSPS2 just-in-time payment amount-check bug that could make liquidity services forward more bitcoin than they received. Developers must integrate patched library code into deployed applications; LSPS2 teams should also review pending payment contracts created by earlier versions.