Bitcoin wallet Electrum has released version 4.8.2 to resolve a backup defect impacting Lightning Network anchor channels, though users must manually export fresh backup files to secure old wallets. As of Oct. 1, version 4.8.2—originally released on Sept. 11—remains the software's latest official release. ### Key Takeaways * Electrum 4.8.2 fixes a backup defect that prevented users from claiming funds from remotely closed Lightning anchor channels. * Affected wallets involve non-deterministic keys, including setups built on BIP39 seeds, imported xprvs, or Electrum seeds created in version 4.0.x. * Software update PR 10851 preserves randomly generated Lightning private keys previously removed during file exports. * Installing the update does not retroactively fix old backup files, requiring users to perform fresh backup exports manually. ## Vulnerability Details and Affected Wallet Types The flaw centers on backups for Lightning anchor channels created using non-deterministic Lightning keys, which cannot be recreated solely from a wallet's recovery seed. When an anchor channel is force-closed by a peer, affected backups lack the necessary payment-key details required to sweep and reclaim output coins on the main Bitcoin blockchain. Two specific conditions trigger the issue: the wallet must utilize non-deterministic Lightning keys, and the backup must involve an anchor channel. Wallets configured with BIP39 seeds or imported extended private keys (xprvs) always utilize non-deterministic Lightning keys. For native Electrum-seed wallets, keys are deterministic if created in version 4.1 or later, but files originally created in version 4.0.x remain vulnerable even when opened in newer software. On desktop platforms, wallet information flags affected Lightning channels as non-recoverable from seed, while Android versions display a warning in the channel-opening dialog box. ## PR 10851 Fixes Export Processing To resolve the defect, developer pull request PR 10851 stops Electrum from deleting randomly generated Lightning private keys during wallet-file exports. Maintainer SomberNight explained that enabling Lightning on a restored backup without these stored keys causes the software to generate entirely new keys. Consequently, older channel-backup records lack sufficient key material to spend anchor-channel balances. Additionally, version 4.8.2 hides the option to request a remote force-close whenever a backup cannot sweep the resulting output, preventing users from executing actions that could permanently freeze funds. As developers advance Bitcoin infrastructure capabilities, ensuring robust key storage remains critical for self-custody users. Affected software now displays a startup warning instructing users to generate new backups. ## Why It Matters This security update highlights the technical complexity of maintaining stateful off-chain scaling solutions like the Lightning Network. While non-custodial wallets offer financial sovereignty, non-deterministic keys introduce edge-case vulnerabilities during emergency channel recoveries. Wallet maintainers and self-custody users must remain vigilant, as updating client software alone is insufficient without refreshing exported backup files.
Electrum Patches Lightning Backup Flaw in Version 4.8.2 But Users Must Export New Files
TheCryptoDesk Editorial · 2m read



