Vulnerability in Core Lightning Experimental Feature May Put User Funds at Risk
PANews, September 16 - According to SlowMist's disclosure, a vulnerability exists in an experimental feature of Core Lightning (CLN) that may put user funds at risk. Core Lightning…
PANews, September 16 - According to SlowMist's disclosure, a vulnerability exists in an experimental feature of Core Lightning (CLN) that may put user funds at risk. Core Lightning officially stated on September 15 that it is investigating the vulnerability and recommends that all nodes with experimental features enabled immediately disable them and wait for a patch. High-risk options include --experimental-dual-fund, --experimental-splicing, and --experimental-peer-storage.
SlowMist stated that a similar issue was fixed in August, where a remote peer could specify arbitrary or even zero fees in channel opening or fund adjustment protocols, and the local node would sign and write to the database without additional verification, potentially forcing the node to pay abnormal fees or even triggering a crash loop, causing the node to be offline for an extended period. It is recommended that node operators immediately disable or remove all experimental parameters; do not completely shut down the node, but use offline mode to retain on-chain monitoring capabilities to prevent peers from forcibly closing channels while the node is offline; wait for the official patch, verify the signature before upgrading, and be wary of fake patch links shared by accounts impersonating official accounts.
insigtX content is informational and educational, not investment advice.