Two denial-of-service vulnerabilities found in Core Lightning

By: rootdata|2026/07/31 18:52:47
  • The attack disrupted liquidity without the need to keep channels open with the victim.
  • Versions v26.04 and v26.06rc2 already include security patches for both vulnerabilities.

Two bugs that allowed a remote attacker to exhaust the memory of a Bitcoin Lightning Network node until it collapsed were recently discovered and patched.

The finding was made by developer Chandra Pratap during his internship in the Summer of Bitcoin program. According to a report published in Delving Bitcoin on July 19, 2026, the flaw directly affected the communication system of the nodes.

Specifically, the bug was located in the "gateway" of the software, that is, the component that receives external messages from other peers and transfers them to the central system responsible for mapping the network topology. By attacking this point, the system collapsed as it could not process the excess information.

The design flaw allowed a malicious actor to flood the node with channel update messages. With no mechanism to stop this flow, the internal message queue grew indefinitely.

This caused the system to consume all available RAM, leading the node to a total collapse.

This first vulnerability was fixed in version v26.04 of Core Lightning, where a strict limit was established that discards messages once the queue reaches 500,000 items.

While Pratap was verifying the effectiveness of this first solution, he discovered a second vulnerability.

In this scenario, the attacker could send a continuous burst of fake short channel identifiers (SCIDs). The system, in trying to register these unknown channels for later consultation, allocated memory in its internal map indefinitely, again causing the collapse of the node.

Fortunately, Core Lightning developer Rusty Russell was already working on a separate update to introduce an automatic cleanup mechanism in the memory map. This patch, included in version v26.06rc2, inadvertently but effectively mitigated this second attack vector.

The criticality of both vulnerabilities lay in their attack vector: they could be executed remotely, through peer interactions, without the attacker needing to compromise funds on the main chain or maintain an open channel relationship with the victim.

These resolutions underscore the importance of continuous audits in the internal communication layers of Bitcoin software.

While the resolution of these vulnerabilities ensures the technical stability and robustness of Core Lightning nodes, the economic topology of the network undergoes its own structural movements.

Alongside security improvements, a trend shift in the use of immobilized capital has been observed. As we recently reported in CriptoNoticias, the capacity of Bitcoin's Lightning is falling rapidly.

Public liquidity has dropped by 21.9% since last December, going from a peak of 5,637 BTC to about 4,400 BTC.

However, this reduction does not necessarily imply a massive outflow of money from bitcoin, but rather a reallocation of operators towards more efficient liquidity rental markets, such as Magma, while Lightning begins to compete with new protocols that operate without payment channels, such as Spark and Ark.

-- Price

--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]