Breaking
ITPescara, man injured in the throat: 40-year-old arrestedITA young man in the Treviso area falls seriously from the roof of a moving carITLandslide in a cave in Sardinia, speleologist stuck ten meters undergroundRUVessel traffic in the Bosphorus was suspended after a chemical vessel broke downRUMore than 20 drones shot down near MoscowTRTerrible accident in Bolu! Jeep rolled into a cliff: 4 injuredBRVIDEO: Church catches fire after mass and its structure is damaged in southern SCRUIn the Lviv region, a man wounded a military registration and enlistment office employee with a knifeITUn'auto travolge un gruppo di ciclisti nel Fiorentino, sette feritiRUAll Moscow airports have stopped operatingITPescara, man injured in the throat: 40-year-old arrestedITA young man in the Treviso area falls seriously from the roof of a moving carITLandslide in a cave in Sardinia, speleologist stuck ten meters undergroundRUVessel traffic in the Bosphorus was suspended after a chemical vessel broke downRUMore than 20 drones shot down near MoscowTRTerrible accident in Bolu! Jeep rolled into a cliff: 4 injuredBRVIDEO: Church catches fire after mass and its structure is damaged in southern SCRUIn the Lviv region, a man wounded a military registration and enlistment office employee with a knifeITUn'auto travolge un gruppo di ciclisti nel Fiorentino, sette feritiRUAll Moscow airports have stopped operating
NewsgatherNewsgather
All StoriesWorldSportsFinanceTechScience
Sign In
All StoriesWorldSportsFinanceTechScienceHealthCultureClimatePoliticsSpace
NewsgatherNewsgather

Real-time global news intelligence. Curated by humans, powered by data.

Sections

All StoriesWorldSportsFinanceTechScience

More

HealthCultureClimatePoliticsSpace

Company

AboutEditorial StandardsAdvertisingCareersPressContact

©️ 2026 Newsgather. A product by All Software 24. All rights reserved.

Privacy PolicyCookie PolicyImprintTerms of UseContent and Editorial PolicyRemoval RequestDelete Your AccountAdvertising PolicyContact
Back|Lightning apps using unpatched LDK risk Bitcoin theft from a reconnect lie
Lightning apps using unpatched LDK risk Bitcoin theft from a reconnect lie
Urgent
CryptoSlate·42 minutes ago·Crypto·2 min read

Lightning apps using unpatched LDK risk Bitcoin theft from a reconnect lie

Quick Look

  • Lightning Development Kit (LDK) released versions 0.2.7 and 0.1.13 to fix a reconnect vulnerability allowing malicious peers to steal forwarded payments by falsely claiming missed updates.
  • The patch ensures retransmission only occurs while acknowledgments are outstanding and force-closes channels on false claims.
  • A separate LSPS2 just-in-time payment amount-check flaw was also addressed in v0.2.7.

AI-generated summary

Why It Matters

LDK is a library used to build Bitcoin Lightning Network wallets and payment applications. Prior versions contained a reconnect vulnerability where a malicious peer could lie about receiving an update to steal forwarded payments. The flaw was disclosed in LDK's v0.2.7 and v0.1.13 security releases dated October 1.

Font size

Lightning Development Kit (LDK), a library for building Bitcoin Lightning wallets and payment applications, has patched a flaw that could let a malicious channel peer steal the value of a forwarded payment by lying after reconnecting. Affected application developers need to incorporate the fix into the software they deploy.

The October 1-dated v0.2.7 and v0.1.13 security releases address the LDK reconnect vulnerability on the 0.2 and 0.1 branches, respectively. Bitcoin Optech described the fixes in its Oct. 9 newsletter.

How the LDK reconnect flaw could cost Bitcoin

The attack starts with a channel peer acknowledging an update, then reconnecting and pretending it never received it. Before the fix, that false claim could cause LDK to sign a conflicting commitment transaction.

A commitment transaction represents a channel's agreed state and can be used to settle it on Bitcoin's blockchain. In the scenario described in PR 5057, the newly signed transaction was not recorded by LDK's channel monitor, the component tracking the channel's on-chain claims.

That gap could turn a forwarded payment into a loss. The malicious sender could confirm the transaction on-chain and let the payment settle with the next recipient. It could then reclaim the incoming payment contract when it expired, even though the forwarding node knew the secret normally used to claim payment.

The forwarding application would have paid downstream without recovering the corresponding incoming funds. The fix permits retransmission only while the peer's acknowledgment remains outstanding and force-closes the channel when the peer claims an already-acknowledged update was missed.

Alongside the LDK reconnect fix, version 0.2.7 addresses a different theft path involving LSPS2 just-in-time payments, where a liquidity service opens a channel as part of handling a payment.

An intercepted payment could misrepresent its amount, causing the service to open a channel and forward more Bitcoin than the incoming payment supplied. The service would cover the difference from its own funds. PR 5042 addresses that amount check.

That exposure concerns the LSPS2 service flow. The v0.1.13 notes list the shared reconnect fix without listing the LSPS2 fix.

These defects differ from the splice-fee diversion and saved-state loading bugs covered in CryptoSlate's Sept. 13 LDK v0.2.6 report. Core Lightning is a separate implementation, as described in the update below.

Open Questions

  • ?How many applications or wallets are affected by the LDK versions containing the flaw?
  • ?Are there any known instances of this vulnerability being exploited in the wild?
  • ?What percentage of Lightning Network nodes use LDK versus other implementations like Core Lightning?

Related Topics

Organizations
Topics
This article was originally published by CryptoSlate.

Quick Look

  • Lightning Development Kit (LDK) released versions 0.2.7 and 0.1.13 to fix a reconnect vulnerability allowing malicious peers to steal forwarded payments by falsely claiming missed updates.
  • The patch ensures retransmission only occurs while acknowledgments are outstanding and force-closes channels on false claims.
  • A separate LSPS2 just-in-time payment amount-check flaw was also addressed in v0.2.7.

AI-generated summary

Story signals

News tone
Neutral
News value
Low
Global impact
Global
Urgency
Urgent
Follow-up likelihood
Likely
Relevance window
Weeks

Source & Reliability

Source
CryptoSlate
Source quality
Full
Published
42 minutes ago

Related Stories

More on this topic
Tokenized stocks can carry the same rights without the same trading protections
Developing·3 hours ago

Tokenized stocks can carry the same rights without the same trading protections

The SEC has granted conditional relief for venues trading tokenized NMS stocks, requiring transparency on external price data and oracle use. While venues operate outside certain Regulation NMS rules, brokers remain bound by best-execution duties for customer orders.

CryptoSlate
5 min read
AI discovers XRP Ledger flaw that could mint 18 trillion tokens and put $94 billion market at risk
Developing·8 hours ago

AI discovers XRP Ledger flaw that could mint 18 trillion tokens and put $94 billion market at risk

An AI agent uncovered a decade-old vulnerability in the XRP Ledger that could have created 18 trillion XRP. RippleX and validators deployed an emergency fix, bypassing standard governance procedures to prevent exploitation.

CryptoSlate
4 min read
Ledger confirms unauthorized hardware implant; losses may exceed $86M
Urgent·9 hours ago

Ledger confirms unauthorized hardware implant; losses may exceed $86M

Ledger confirmed an unauthorized hardware implant in a device linked to Southeast Asian reseller CryptoBilis during an ongoing investigation into crypto losses.

Cointelegraph
1 min read
Stealing $1.5B in crypto is easy, cashing out is the trap
Developing·yesterday

Stealing $1.5B in crypto is easy, cashing out is the trap

Blockchain investigator ZachXBT infiltrated a Chinese laundering network to trace $12M in funds stolen from Bybit by North Korean hackers. The case highlights the reliance of cybercriminals on illicit marketplaces like Xinbi Guarantee to convert stolen crypto into fiat.

CryptoSlate
7 min read
French Committee Backs Stablecoin Swap Tax and Crypto Exit Tax, Then Rejects the Budget
Developing·yesterday

French Committee Backs Stablecoin Swap Tax and Crypto Exit Tax, Then Rejects the Budget

France's National Assembly Finance Committee voted to tax stablecoin swaps and implement a crypto exit tax for wealthy residents. The measures, which would take effect in 2027, must be reintroduced during the upcoming floor debate after the committee rejected the budget.

Decrypt
3 min read
Celsius founder faces lifetime ban, but can trade his own crypto
Developing·yesterday

Celsius founder faces lifetime ban, but can trade his own crypto

Bankrupt crypto lender Celsius founder Alex Mashinsky has agreed to a permanent ban from securities, commodities, and crypto businesses under a New York settlement announced Oct. 9, which includes conditional state payment obligations of up to $35 million tied to federal forfeiture payments and prison term completion, without creating new payouts to Celsius creditors.

CryptoSlate
2 min read
More on this topic
lightning network
bitcoin
ldk
lightning network
Lightning Development Kit
Bitcoin Optech
Core Lightning
bitcoin
ldk
security patch
reconnect vulnerability
lsps2
commitment transaction
lightning network
lightning network