Developers of Bitcoin Lightning applications must update their software after the Lightning Development Kit (LDK) issued security releases v0.2.7 and v0.1.13 on October 1 to fix a flaw that allowed channel peers to steal forwarded payments.
Details of the security patches were subsequently summarized in the Bitcoin Optech newsletter published on Oct. 9.
- LDK versions 0.2.7 and v0.1.13 resolve a channel reconnect flaw tracked in PR 5057.
- LDK v0.2.7 additionally patches an LSPS2 just-in-time payment bug tracked in PR 5042.
- The vulnerability allowed malicious peers to trigger unrecorded commitment transactions after reconnecting.
How the LDK Reconnect Flaw Enables Theft
The exploit scenario detailed in PR 5057 begins when a channel peer acknowledges a state update, disconnects, and then reconnects while falsely claiming the update was never received. Prior to the patch, this false claim caused LDK to sign a conflicting commitment transaction.
Crucially, LDK's channel monitor—the component responsible for tracking on-chain claims—did not record this newly signed commitment transaction. A malicious peer could exploit this gap by broadcasting and confirming the commitment transaction on-chain, allowing the downstream payment to settle with the recipient. The attacker could then reclaim the incoming payment contract after it expired, even though the forwarding node already possessed the secret to claim the funds. As a result, the forwarding node paid out funds downstream without recovering the incoming transfer.
To prevent this, the updated code permits retransmission only while the peer's acknowledgment remains outstanding. If a peer claims an already-acknowledged update was missed, LDK will force-close the channel immediately.
LSPS2 Vulnerability and Developer Action
Alongside the reconnect patch, LDK v0.2.7 includes PR 5042, which fixes a separate flaw involving LSPS2 just-in-time payments. In that flow, liquidity services open channels on demand during payment processing. An intercepted payment could spoof its value, causing the service to open a channel and route more Bitcoin than supplied by the incoming payment, forcing the service to cover the deficit.
Because LDK functions as a library embedded directly into third-party software, application developers must manually integrate the patched code into their builds. Developer guidance notes that teams handling LSPS2 flows must account for pending payment contracts queued under previous releases, as unvalidated amounts remain in legacy state queues.
This update follows earlier security fixes detailed in LDK v0.2.6 on Sept. 13, which resolved splice-fee diversion and saved-state loading bugs. Similar to other protocol maintenance like BTCPay Server version 2.4.5 deployment guidelines or guarding against mobile wallet security threats, timely software updates remain essential for node operators.
Why It Matters
This vulnerability underscores the complex challenge of managing off-chain channel states across disconnected network sessions in Layer-2 protocols. Because LDK is compiled directly inside end-user wallets and node software rather than running as an independent daemon, patches require active intervention from application developers before end-users are protected. Until client software updates to versions 0.2.7 or 0.1.13, active routing nodes remain exposed to potential financial loss from dishonest channel partners.



