• bitcoinBitcoin (BTC) $ 112,493.00
  • ethereumEthereum (ETH) $ 4,122.42
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,216.94
  • xrpXRP (XRP) $ 2.50
  • solanaSolana (SOL) $ 202.87
  • usd-coinUSDC (USDC) $ 0.999901
  • staked-etherLido Staked Ether (STETH) $ 4,124.23
  • dogecoinDogecoin (DOGE) $ 0.203529
  • tronTRON (TRX) $ 0.316315
  • cardanoCardano (ADA) $ 0.698854
  • wrapped-stethWrapped stETH (WSTETH) $ 5,019.11
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,444.75
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 112,701.00
  • chainlinkChainlink (LINK) $ 19.09
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • wrapped-eethWrapped eETH (WEETH) $ 4,452.25
  • hyperliquidHyperliquid (HYPE) $ 40.03
  • stellarStellar (XLM) $ 0.335630
  • bitcoin-cashBitcoin Cash (BCH) $ 534.04
  • suiSui (SUI) $ 2.83
  • avalanche-2Avalanche (AVAX) $ 22.91
  • wethWETH (WETH) $ 4,129.79
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • leo-tokenLEO Token (LEO) $ 9.63
  • usdsUSDS (USDS) $ 0.999146
  • hedera-hashgraphHedera (HBAR) $ 0.186682
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 112,726.00
  • usdt0USDT0 (USDT0) $ 1.00
  • litecoinLitecoin (LTC) $ 95.50
  • mantleMantle (MNT) $ 1.97
  • shiba-inuShiba Inu (SHIB) $ 0.000011
  • whitebitWhiteBIT Coin (WBT) $ 42.71
  • the-open-networkToncoin (TON) $ 2.30
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • crypto-com-chainCronos (CRO) $ 0.162328
  • moneroMonero (XMR) $ 307.04
  • polkadotPolkadot (DOT) $ 3.24
  • daiDai (DAI) $ 0.999226
  • bittensorBittensor (TAO) $ 465.54
  • zcashZcash (ZEC) $ 257.67
  • uniswapUniswap (UNI) $ 6.77
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.146187
  • aaveAave (AAVE) $ 252.19
  • okbOKB (OKB) $ 181.58
  • memecoreMemeCore (M) $ 2.10
  • bitget-tokenBitget Token (BGB) $ 4.82
  • pepePepe (PEPE) $ 0.000007
  • ethenaEthena (ENA) $ 0.437348
  • nearNEAR Protocol (NEAR) $ 2.47
  • jito-staked-solJito Staked SOL (JITOSOL) $ 251.32
  • aster-2Aster (ASTER) $ 1.46
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • aptosAptos (APT) $ 3.68
  • susdssUSDS (SUSDS) $ 1.07
  • ethereum-classicEthereum Classic (ETC) $ 16.92
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • c1usdCurrency One USD (C1USD) $ 1.00
  • ondo-financeOndo (ONDO) $ 0.796812
  • binance-peg-wethBinance-Peg WETH (WETH) $ 4,118.89
  • falcon-financeFalcon USD (USDF) $ 0.997397
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.61
  • story-2Story (IP) $ 6.81
  • worldcoin-wldWorldcoin (WLD) $ 0.964579
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.199402
  • binance-staked-solBinance Staked SOL (BNSOL) $ 218.52
  • gatechain-tokenGate (GT) $ 16.45
  • internet-computerInternet Computer (ICP) $ 3.56
  • htx-daoHTX DAO (HTX) $ 0.000002
  • kucoin-sharesKuCoin (KCS) $ 14.37
  • chainopera-aiChainOpera AI (COAI) $ 9.44
  • arbitrumArbitrum (ARB) $ 0.343777
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,724.16
  • hash-2Provenance Blockchain (HASH) $ 0.036554
  • usdtbUSDtb (USDTB) $ 1.00
  • algorandAlgorand (ALGO) $ 0.203786
  • pi-networkPi Network (PI) $ 0.216514
  • bfusdBFUSD (BFUSD) $ 1.00
  • wbnbWrapped BNB (WBNB) $ 1,217.48
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,358.37
  • kaspaKaspa (KAS) $ 0.061487
  • vechainVeChain (VET) $ 0.019166
  • cosmosCosmos Hub (ATOM) $ 3.46
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 40.03
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,353.12
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.024720
  • tether-goldTether Gold (XAUT) $ 4,135.38
  • render-tokenRender (RENDER) $ 2.86
  • skySky (SKY) $ 0.063070
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,457.57
  • flare-networksFlare (FLR) $ 0.019021
  • pump-funPump.fun (PUMP) $ 0.004059
  • sei-networkSei (SEI) $ 0.225339
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 112,696.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,379.31
  • quant-networkQuant (QNT) $ 89.51
  • pax-goldPAX Gold (PAXG) $ 4,152.86
  • official-trumpOfficial Trump (TRUMP) $ 6.32
  • bonkBonk (BONK) $ 0.000016
  • nexoNEXO (NEXO) $ 1.22
  • pancakeswap-tokenPancakeSwap (CAKE) $ 3.49
  • jupiter-exchange-solanaJupiter (JUP) $ 0.378122
  • filecoinFilecoin (FIL) $ 1.67
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • spx6900SPX6900 (SPX) $ 1.23
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999072
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 112,332.00
  • immutable-xImmutable (IMX) $ 0.567834
  • xdce-crowd-saleXDC Network (XDC) $ 0.060872
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998756
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,437.27
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 232.41
  • doublezeroDoubleZero (2Z) $ 0.289981
  • morphoMorpho (MORPHO) $ 1.91
  • injective-protocolInjective (INJ) $ 9.58
  • celestiaCelestia (TIA) $ 1.14
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 112,861.00
  • clbtcclBTC (CLBTC) $ 116,618.00
  • solmevSolMev (SN116) $ 2,398.72
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.334297
  • fasttokenFasttoken (FTN) $ 2.01
  • lido-daoLido DAO (LDO) $ 0.963737
  • curve-dao-tokenCurve DAO (CRV) $ 0.601769
  • optimismOptimism (OP) $ 0.478807
  • msolMarinade Staked SOL (MSOL) $ 270.46
  • blockstackStacks (STX) $ 0.469229
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • aerodrome-financeAerodrome Finance (AERO) $ 0.904949
  • plasmaPlasma (XPL) $ 0.453649
  • ousgOUSG (OUSG) $ 112.92
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,879.50
  • sonic-3Sonic (S) $ 0.202700
  • global-dollarGlobal Dollar (USDG) $ 0.999949
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 4,129.09
  • the-graphThe Graph (GRT) $ 0.069948
  • flokiFLOKI (FLOKI) $ 0.000074
  • pyth-networkPyth Network (PYTH) $ 0.124125
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.85
  • saros-financeSaros (SAROS) $ 0.260205
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998197
  • kaiaKaia (KAIA) $ 0.114298
  • havvenSynthetix (SNX) $ 1.93
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 4,128.95
  • tezosTezos (XTZ) $ 0.621510
  • tbtctBTC (TBTC) $ 112,300.00
  • ether-fiEther.fi (ETHFI) $ 1.25
  • aethirAethir (ATH) $ 0.045106
  • gtethGTETH (GTETH) $ 4,131.10
  • stader-ethxStader ETHx (ETHX) $ 4,423.94
  • pendlePendle (PENDLE) $ 3.68
  • newton-projectAB (AB) $ 0.007584
  • myx-financeMYX Finance (MYX) $ 3.24
  • iotaIOTA (IOTA) $ 0.151597
  • conflux-tokenConflux (CFX) $ 0.117331
  • usdaiUSDai (USDAI) $ 1.03
  • beldexBeldex (BDX) $ 0.079473
  • dashDash (DASH) $ 46.93
  • dogwifcoindogwifhat (WIF) $ 0.580134
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.38
  • theta-tokenTheta Network (THETA) $ 0.570212
  • ethereum-name-serviceEthereum Name Service (ENS) $ 16.92
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,541.32
  • galaGALA (GALA) $ 0.011965
  • swethSwell Ethereum (SWETH) $ 4,542.23
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 4,126.01
  • the-sandboxThe Sandbox (SAND) $ 0.224172
  • usual-usdUsual USD (USD0) $ 0.998347
  • raydiumRaydium (RAY) $ 2.04
  • starknetStarknet (STRK) $ 0.126867
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,430.83
  • swissborgSwissBorg (BORG) $ 0.550096
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.826278
  • jasmycoinJasmyCoin (JASMY) $ 0.011000
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 112,484.00
  • rna-2RNA (SN117) $ 4,708.96
  • decentralandDecentraland (MANA) $ 0.271223
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.202730
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.35
  • bittorrentBitTorrent (BTT) $ 0.00000052
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.999738
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,285.36
  • vaultaVaulta (A) $ 0.314327
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,448.09
  • true-usdTrueUSD (TUSD) $ 1.00
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.10
  • flowFlow (FLOW) $ 0.296846
  • usddUSDD (USDD) $ 1.00
  • zero-gravity0G (0G) $ 2.21
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999890
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999902
  • syrupMaple Finance (SYRUP) $ 0.420314
  • ai-companionsAI Companions (AIC) $ 0.465523
  • sun-tokenSun Token (SUN) $ 0.024262
  • jito-governance-tokenJito (JTO) $ 1.17
  • bitcoin-svBitcoin SV (BSV) $ 22.84
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 4,129.46
  • frax-etherFrax Ether (FRXETH) $ 4,095.11

Bitcoin Lightning bug could jam and steal millions of dollars

0 59

Bitcoin Lightning bug could jam and steal millions of dollars

Bitcoin developer Antoine Riard has disclosed two new bugs that affect wealthy node operators within the Lightning Network, a payments protocol with over $500 million worth of BTC capacity.

The transaction jamming attack exploits Bitcoin Core software’s transaction selection, announcement, and propagation mechanisms of Lightning Network-connected Bitcoin full nodes.

Dubbed “transaction relay throughput overflow attacks,” the bugs allow an assailant to steal bitcoin (BTC) from the wealthiest Lightning nodes. Although there’s no evidence that a thief has actually exploited these bugs, Lightning implementation providers Éclair and Core Lightning are already working on software patches.

Specifically, the cost- and time-intensive attack is only worth the effort for victims with more than roughly $130,000 worth of BTC and is best suited for nodes holding above half a million dollars.

Bitcoin Lightning transaction relay throughput overflow attacks

The attack would enable a thief to steal funds from the victim’s Lightning channel by preventing time-sensitive transactions such as justice transactions from propagating through the network. After jamming the node for 32 Bitcoin blocks (Core Lightning defaults) or 140 blocks (Éclair defaults), the robber could make off with an irrevocable bounty.

In regular clock time, that would mean approximately 5.5 hours to steal from a default Core Lightning node or 24 hours for a node running Éclair default software.

By default, nodes limit the number of unconfirmed transactions they transmit or accept at any given time to reduce the chance of various denial-of-service (DoS) attacks. The attacker can conduct a high overflow jamming attack that blocks the victim from sending a justice transaction by continuously overwhelming the node with high fee rate transactions.

By default, a Bitcoin Core node will always choose to propagate the highest fee transactions first and queue lower fee transactions — even if one of those lower fee transactions is the nodes’ own Lightning Network justice transaction.

This is one bug that Core Lightning and Éclair are patching, thanks to Riard’s responsible disclosure.

Again, the high overflow jamming attack blocks the victim from sending an anti-theft transaction by continuously overbidding with higher fee transactions, hence the name “high overflow.”

For this reason, the attack is expensive — with initial estimates north of $130,000 throughout the hours of the attack.

In addition to this high overflow jamming attack, Riard explained another variation of the transaction jamming bug: low overflow.

A variation with thousands of low-fee transactions

The low overflow is a cheaper variant but less reliable for the attacker. Here, to save money, the attacker targets a victim trying to send a transaction to nodes with a maximum unrequested transactions queue of 5,000 per peer.

The attacker floods the victim with a large number of transactions using a minimum transaction fee rate. The victim then announces these transactions to its peers and the peers try to drain the queue by requesting those transactions. If the attacker can maintain a queue of over 5,000 transactions, the attack might be successful.

Technically speaking, the low overflow attack leverages Lightning nodes’ interaction with Bitcoin Core’s MAX_PEER_TX_ANNOUNCEMENTS default, causing inbound transactions to overflow this threshold.

Patching the bug

Riard proposed several mitigations for Lightning Network node software implementations. These providers are working on patches, including random transaction rebroadcasting, more aggressive fee-rebroadcasting, limitation of identical finality time-sensitive transactions, and over-provisioning of transaction relay throughput with peer nodes.

He also proposed changes to Bitcoin Core itself to assist Lightning Network operators. However, changes to Bitcoin Core typically take far longer and need more reviews than Lightning software implementations.

Riard’s Critical Vulnerability Error (CVE) request number 178025 is tracking bug patches of his high and low transaction relay throughput overflow attacks.

Source

Leave A Reply

Your email address will not be published.