Connect with us

Noticias

Details of vulnerability

Blockstream developer Rusty Russell has revealed more details about the Lightning Network vulnerability, which first became known in late August. ICYMI: Here are all the details of the recent Lightning bug. https://t.co/NVzKmGW5I6 – TheRustyTwit (@rusty_twit) September 27, 2019 As Russell wrote, the vulnerability arose during the creation and replenishment of Lightning Network channels. In particular, […]

Published

on

discovered in Lightning Network became known

Blockstream developer Rusty Russell has revealed more details about the Lightning Network vulnerability, which first became known in late August.

As Russell wrote, the vulnerability arose during the creation and replenishment of Lightning Network channels. In particular, when creating a channel, the recipient did not need to verify the transaction output amount used to replenish the channel, or use the scriptpubkey script, which allows you to verify that certain conditions are met before spending the output.

The Lightning Network at the protocol level does not require such verification, and for this reason the attack organizer was able to inform about the opening of the channel without transferring payment to the recipient or transferring an incomplete amount.

As a result, the attacker could spend the funds in the channel without notifying the other side. Only after closing the channel did the latter discover that the transactions transmitted through it were invalid.

In mid-September, the developers recognized that the vulnerability was used in real conditions, without specifying the extent of the possible damage.

Earlier in September, the technical director of Lightning Labs and ACINQ, Olaoluwa Osuntokun, confirmed the cases of practical exploitation of the discovered vulnerability.

The following releases are still considered vulnerable:

LND version 0.7 and below;
c-lightning version 0.7 and below;
eclair version 0.3 and below.

In this regard, developers of the main Lightning Network clients again remind about the need to upgrade to the latest versions. Special tools ( Lightning Labs and Acinq ) were also released to determine if the attack affected users.

Recall that earlier this week the number of active Lightning nodes in the bitcoin network exceeded 10,000 .

Follow BlockchainJournal on Twitter !

<< aside id = "unisender_subscribe_form-10" class = "widget unisender_form">

BlockchainJournal.news

BlockchainJournal.news

Compañías

ARK Invest Deshace Acciones de Coinbase y GBTC por Millones en Medio del Auge del Mercado

Published

on

ARK Invest: $33 Millones en Acciones de Coinbase y $5.9 Millones en GBTC

ARK Invest, liderada por Cathie Wood, continúa navegando sus movimientos estratégicos de acciones en el mercado, realizando ventas destacadas de acciones de Coinbase y Grayscale Bitcoin Trust (GBTC) en medio del continuo aumento de los precios del mercado.

(más…)

Continue Reading

Compañías

El Descuento de GBTC se Reduce a Medida que Aumenta el Precio de Bitcoin

Published

on

By

El Descuento de GBTC se Reduce a Medida que Aumenta el Precio de Bitcoin

Grayscale Bitcoin Trust (GBTC), uno de los vehículos de inversión en criptomonedas más grandes y populares, ha visto su descuento reducirse significativamente en los últimos días a medida que los alcistas continúan elevando su precio. Según datos de Kaiko, una plataforma de inteligencia blockchain, el descuento del GBTC, que mide la diferencia entre el precio de mercado y el valor liquidativo (NAV) del fideicomiso, está en su nivel más estrecho en años, con solo el 8% hasta ayer. (más…)

Continue Reading

Compañías

IBM Presenta OSO, Diseñada Para el Almacenamiento en Frío de Activos Digitales

Published

on

By

ibm featured

IBM presentó una nueva tecnología denominada «IBM Hyper Protect Offline Signing Orchestrator» (OSO), diseñada para gestionar activos digitales en almacenamiento en frío. Esta innovación surge como respuesta a los riesgos asociados con los procedimientos manuales y tiene como objetivo mantener los activos a una distancia segura de las conexiones a Internet. (más…)

Continue Reading

Trending