Live Prices
Bitcoin

Eclair Bitcoin Lightning Nodes Vulnerable to Persistent Crash Loop Flaw

TheCryptoDesk Editorial · 2m read
Eclair Bitcoin Lightning Nodes Vulnerable to Persistent Crash Loop Flaw

A persistent database-flooding flaw in ACINQ’s Eclair Bitcoin Lightning implementation allows malicious peers to repeatedly crash unpatched nodes upon restart without spending BTC on-chain. Disclosed by researcher Erick Cestari, the vulnerability impacts nodes running v0.14.0 and earlier by filling memory heaps with fake channel records.

Unfunded Channel Requests Cause Repeated Crashes

The bug stems from inconsistent tracking of temporary and final channel identifiers in Eclair. While Eclair limits pending channel requests per peer, improper checks allowed attackers to bypass limits and stack unfunded channel records without broadcasting funding transactions or paying on-chain fees.

During a regtest benchmark, Cestari demonstrated that Eclair v0.14.0 exhausted a 4 GB Java virtual machine (JVM) heap in 47 minutes 43 seconds after accumulating 217,623 rows in its database. Because these records persist on disk, affected nodes crash again during startup when reloading channel data, leaving node operators unable to restore service by merely rebooting.

To recover an overloaded node, operators must manually increase JVM heap size or purge invalid channel records directly from the database. Similar to past infrastructure updates like Electrum patching its Lightning backup flaw, node software maintaining persistent state requires precise operator intervention during severe database corruptions.

Separate Bugs and Update Recommendations

Cestari published his persistent-crash research on Sept. 30 and detailed a separate denial-of-service issue on Oct. 1 via Delving Bitcoin. The second bug, disclosed as LNF-2026-0003 by Matt Morehouse of lnfuzz, involved a channel-opening race condition that spawned orphaned processes, though nodes automatically recovered upon disconnect or restart.

Both issues were resolved when ACINQ merged PR #3324 on July 17 and released v0.14.1 on July 29. However, ACINQ now strongly urges operators to upgrade to v0.14.3, released on Sept. 14, to protect against separate fund-loss vulnerabilities.

Key facts regarding the Eclair disclosures include:

  • v0.14.0 and earlier suffer from persistent crash loops caused by saved unfunded channel data.
  • 47 minutes 43 seconds was required in testing to fill a 4 GB JVM heap with 217,623 database rows.
  • v0.14.1 patched the database flood and race condition issues shipped in July.
  • v0.14.3 is the recommended security release to prevent critical fund-loss exploits.

Why It Matters

Node-level availability risks pose unique operational hurdles for the Lightning Network, as offline routing nodes reduce overall liquidity and payment reliability. Unlike standard denial-of-service attacks that dissipate after malicious traffic ceases, persistent database contamination forces manual technical remediation, increasing downtime for infrastructure providers. As payments protocols continue returning tethered assets to the Bitcoin network, maintaining robust, fault-tolerant Lightning node implementations remains vital for scaling layer-2 transaction volumes securely.

Terms in this article

Read next