Live Prices
Bitcoin

Core Lightning Patches Flaw Allowing Revoked Channel States to Bypass Penalties

TheCryptoDesk Editorial · 2m read
Core Lightning Patches Flaw Allowing Revoked Channel States to Bypass Penalties

Core Lightning has resolved a channel-close flaw in version v26.06.7 that permitted malicious peers to broadcast old, revoked channel states without triggering penalty mechanisms. Detailed by Bitcoin Optech in a Sept. 25 report, the bug allowed specific channel configurations to misidentify revoked commitments as cooperative closes.

Mechanics of the Core Lightning Channel Flaw

In the Lightning Network, peers update balance commitments as transactions occur, revoking older state updates. If a node broadcasts a revoked commitment, the counterparty is meant to claim all channel funds as a penalty. However, prior to the patch, Core Lightning could misinterpret a revoked commitment funding spend as a mutual close if the transaction outputs matched recorded shutdown scripts.

To exploit this, a peer that omitted an upfront shutdown script at channel opening could later specify the output script of its revoked commitment inside a shutdown message. The peer could then abandon the cooperative close and broadcast the old commitment. Because Core Lightning inspected only transaction outputs, it bypassed the penalty path. The fix modifies Core Lightning to check a transaction's locktime and sequence encoding prior to inspecting outputs. Maintainers clarified the bug represented a potential vector to evade penalties rather than a confirmed loss of funds.

Key Takeaways

  • Version Release: Core Lightning fixed the flaw in v26.06.7 on Aug. 28, followed by v26.06.8 on Sept. 22.
  • Code Merges: Source code was un-embargoed on Sept. 11, and Pull Request 9509 was merged into the main development branch on Sept. 15.
  • Docker Issue: Docker images built between Aug. 28 and Sept. 1 falsely reported version v26.06.7 on startup while lacking the actual fix.
  • Action Required: Operators running Docker builds must verify image digests or re-pull updated images.

Docker Packaging Errors and Release Timeline

The resolution timeline involved multiple stages. Core Lightning initially released v26.06.7 on Aug. 28, publishing its embargoed source code on Sept. 11. Subsequently, Pull Request 9509 was merged on Sept. 15, and v26.06.8 was released on Sept. 22 containing additional security patches.

Node operators face a specific hurdle due to a Docker distribution error. Docker images served under the v26.06.7 tag between Aug. 28 and Sept. 1 displayed updated version strings on startup despite omitting the security patch. Maintainers instruct node runners to verify their image digests against corrected project listings. While developers continue exploring technical enhancements like research into shielded Bitcoin architecture, maintaining node software remains critical for second-layer security.

Why It Matters

Second-layer protocols rely heavily on economic game theory, where the certainty of penalty claims deters fraudulent state broadcasts. Vulnerabilities that allow nodes to evade penalty paths undermine the fundamental trustlessness of off-chain payment channels. As Lightning adoption grows alongside broader protocol developments like multisig wallet recovery proposals, rapid patching by node operators is essential to prevent edge-case state exploits across the network.

Terms in this article

Read next