• bitcoinBitcoin (BTC) $ 91,378.00
  • ethereumEthereum (ETH) $ 3,101.35
  • tetherTether (USDT) $ 0.998853
  • xrpXRP (XRP) $ 2.06
  • bnbBNB (BNB) $ 905.77
  • usd-coinUSDC (USDC) $ 0.999724
  • tronTRON (TRX) $ 0.299273
  • staked-etherLido Staked Ether (STETH) $ 3,100.55
  • dogecoinDogecoin (DOGE) $ 0.136770
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • cardanoCardano (ADA) $ 0.386379
  • bitcoin-cashBitcoin Cash (BCH) $ 621.58
  • wrapped-stethWrapped stETH (WSTETH) $ 3,794.15
  • whitebitWhiteBIT Coin (WBT) $ 54.93
  • moneroMonero (XMR) $ 626.65
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 91,076.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,373.63
  • wrapped-eethWrapped eETH (WEETH) $ 3,366.72
  • usdsUSDS (USDS) $ 0.999490
  • chainlinkChainlink (LINK) $ 13.09
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998738
  • leo-tokenLEO Token (LEO) $ 9.08
  • wethWETH (WETH) $ 3,101.27
  • stellarStellar (XLM) $ 0.219343
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 91,305.00
  • zcashZcash (ZEC) $ 406.98
  • suiSui (SUI) $ 1.77
  • ethena-usdeEthena USDe (USDE) $ 0.999193
  • avalanche-2Avalanche (AVAX) $ 13.52
  • litecoinLitecoin (LTC) $ 75.89
  • hyperliquidHyperliquid (HYPE) $ 24.08
  • canton-networkCanton (CC) $ 0.140142
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • hedera-hashgraphHedera (HBAR) $ 0.115050
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.170490
  • usdt0USDT0 (USDT0) $ 0.998604
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999631
  • the-open-networkToncoin (TON) $ 1.73
  • crypto-com-chainCronos (CRO) $ 0.099251
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • paypal-usdPayPal USD (PYUSD) $ 0.999766
  • usd1-wlfiUSD1 (USD1) $ 0.998917
  • uniswapUniswap (UNI) $ 5.37
  • polkadotPolkadot (DOT) $ 2.05
  • mantleMantle (MNT) $ 0.946066
  • rainRain (RAIN) $ 0.008678
  • memecoreMemeCore (M) $ 1.67
  • bittensorBittensor (TAO) $ 283.78
  • aaveAave (AAVE) $ 165.00
  • bitget-tokenBitget Token (BGB) $ 3.55
  • pepePepe (PEPE) $ 0.000006
  • tether-goldTether Gold (XAUT) $ 4,586.26
  • okbOKB (OKB) $ 111.38
  • falcon-financeFalcon USD (USDF) $ 0.996775
  • nearNEAR Protocol (NEAR) $ 1.68
  • jito-staked-solJito Staked SOL (JITOSOL) $ 174.33
  • ethereum-classicEthereum Classic (ETC) $ 12.27
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,100.73
  • pax-goldPAX Gold (PAXG) $ 4,599.12
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.206157
  • internet-computerInternet Computer (ICP) $ 3.12
  • ethenaEthena (ENA) $ 0.213954
  • aster-2Aster (ASTER) $ 0.688735
  • solanaSolana (SOL) $ 139.00
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.152140
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.78
  • htx-daoHTX DAO (HTX) $ 0.000002
  • binance-staked-solBinance Staked SOL (BNSOL) $ 151.93
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • global-dollarGlobal Dollar (USDG) $ 0.999810
  • worldcoin-wldWorldcoin (WLD) $ 0.557833
  • kucoin-sharesKuCoin (KCS) $ 11.18
  • pump-funPump.fun (PUMP) $ 0.002462
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • ripple-usdRipple USD (RLUSD) $ 0.999561
  • aptosAptos (APT) $ 1.77
  • wbnbWrapped BNB (WBNB) $ 905.60
  • bfusdBFUSD (BFUSD) $ 0.998579
  • hash-2Provenance Blockchain (HASH) $ 0.024634
  • skySky (SKY) $ 0.056301
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,581.54
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999595
  • kaspaKaspa (KAS) $ 0.046416
  • render-tokenRender (RENDER) $ 2.39
  • ondo-financeOndo (ONDO) $ 0.387387
  • cosmosCosmos Hub (ATOM) $ 2.49
  • gatechain-tokenGate (GT) $ 10.31
  • arbitrumArbitrum (ARB) $ 0.201411
  • algorandAlgorand (ALGO) $ 0.129241
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,291.58
  • myx-financeMYX Finance (MYX) $ 5.83
  • midnight-3Midnight (NIGHT) $ 0.066008
  • filecoinFilecoin (FIL) $ 1.47
  • official-trumpOfficial Trump (TRUMP) $ 5.36
  • bridged-wrapped-lido-staked-ether-scrollBridged Wrapped Lido Staked Ether (Scroll) (WSTETH) $ 3,785.80
  • story-2Story (IP) $ 2.86
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 91,579.00
  • ignition-fbtcFunction FBTC (FBTC) $ 90,660.00
  • vechainVeChain (VET) $ 0.011294
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 91,229.00
  • nexoNEXO (NEXO) $ 0.957562
  • flare-networksFlare (FLR) $ 0.011457
  • usddUSDD (USDD) $ 0.998282
  • bonkBonk (BONK) $ 0.000010
  • xdce-crowd-saleXDC Network (XDC) $ 0.046438
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • usdtbUSDtb (USDTB) $ 0.999153
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,297.78
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,360.81
  • ousgOUSG (OUSG) $ 113.94
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.95
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999777
  • sei-networkSei (SEI) $ 0.118594
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999608
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.011803
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 91,115.00
  • morphoMorpho (MORPHO) $ 1.29
  • clbtcclBTC (CLBTC) $ 90,288.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,311.03
  • blockstackStacks (STX) $ 0.377665
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 161.73
  • beldexBeldex (BDX) $ 0.090028
  • wrapped-flareWrapped Flare (WFLR) $ 0.011346
  • usdaiUSDai (USDAI) $ 0.999904
  • jupiter-exchange-solanaJupiter (JUP) $ 0.206963
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.95
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.281199
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.987830
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,292.80
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,100.60
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999735
  • optimismOptimism (OP) $ 0.309263
  • tezosTezos (XTZ) $ 0.554646
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • curve-dao-tokenCurve DAO (CRV) $ 0.391498
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,101.28
  • c8ntinuumc8ntinuum (CTM) $ 0.127013
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.30
  • usual-usdUsual USD (USD0) $ 0.986641
  • tbtctBTC (TBTC) $ 91,262.00
  • lighterLighter (LIT) $ 2.17
  • spx6900SPX6900 (SPX) $ 0.572842
  • chilizChiliz (CHZ) $ 0.050673
  • lido-daoLido DAO (LDO) $ 0.609737
  • aerodrome-financeAerodrome Finance (AERO) $ 0.560923
  • injective-protocolInjective (INJ) $ 5.03
  • dashDash (DASH) $ 39.68
  • gtethGTETH (GTETH) $ 3,102.14
  • ghoGHO (GHO) $ 0.998926
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998589
  • true-usdTrueUSD (TUSD) $ 0.998488
  • flokiFLOKI (FLOKI) $ 0.000050
  • msolMarinade Staked SOL (MSOL) $ 187.93
  • ether-fiEther.fi (ETHFI) $ 0.722782
  • fasttokenFasttoken (FTN) $ 1.09
  • celestiaCelestia (TIA) $ 0.531215
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,348.93
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • syrupMaple Finance (SYRUP) $ 0.388382
  • stader-ethxStader ETHx (ETHX) $ 3,343.48
  • the-graphThe Graph (GRT) $ 0.040643
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,476.38
  • newton-projectAB (AB) $ 0.004455
  • jasmycoinJasmyCoin (JASMY) $ 0.008531
  • sbtc-2sBTC (SBTC) $ 90,915.00
  • usdbUSDB (USDB) $ 1.01
  • starknetStarknet (STRK) $ 0.081071
  • bittorrentBitTorrent (BTT) $ 0.00000041
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.203268
  • staked-aaveStaked Aave (STKAAVE) $ 164.33
  • iotaIOTA (IOTA) $ 0.094974
  • doublezeroDoubleZero (2Z) $ 0.115723
  • justJUST (JST) $ 0.040564
  • sun-tokenSun Token (SUN) $ 0.020659
  • conflux-tokenConflux (CFX) $ 0.074952
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.11
  • bitcoin-svBitcoin SV (BSV) $ 19.12
  • riverRiver (RIVER) $ 19.44
  • wrapped-stx-velarWrapped STX (Velar) (WSTX) $ 0.381451
  • chain-2Onyxcoin (XCN) $ 0.008808
  • pyth-networkPyth Network (PYTH) $ 0.064571
  • gnosisGnosis (GNO) $ 140.27
  • dogwifcoindogwifhat (WIF) $ 0.369290
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.878836
  • fartcoinFartcoin (FARTCOIN) $ 0.365980
  • apenftAINFT (NFT) $ 0.00000037
  • crvusdcrvUSD (CRVUSD) $ 0.998762
  • cap-usdCap USD (CUSD) $ 1.00
  • kaiaKaia (KAIA) $ 0.061320
  • pendlePendle (PENDLE) $ 2.13
  • euro-coinEURC (EURC) $ 1.17
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 91,297.00
  • telcoinTelcoin (TEL) $ 0.003707
  • kinesis-goldKinesis Gold (KAU) $ 147.61
  • olympusOlympus (OHM) $ 21.46
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.136649

Bitcoin Lightning bug could jam and steal millions of dollars

0 84

Bitcoin Lightning bug could jam and steal millions of dollars

Bitcoin developer Antoine Riard has disclosed two new bugs that affect wealthy node operators within the Lightning Network, a payments protocol with over $500 million worth of BTC capacity.

The transaction jamming attack exploits Bitcoin Core software’s transaction selection, announcement, and propagation mechanisms of Lightning Network-connected Bitcoin full nodes.

Dubbed “transaction relay throughput overflow attacks,” the bugs allow an assailant to steal bitcoin (BTC) from the wealthiest Lightning nodes. Although there’s no evidence that a thief has actually exploited these bugs, Lightning implementation providers Éclair and Core Lightning are already working on software patches.

Specifically, the cost- and time-intensive attack is only worth the effort for victims with more than roughly $130,000 worth of BTC and is best suited for nodes holding above half a million dollars.

Bitcoin Lightning transaction relay throughput overflow attacks

The attack would enable a thief to steal funds from the victim’s Lightning channel by preventing time-sensitive transactions such as justice transactions from propagating through the network. After jamming the node for 32 Bitcoin blocks (Core Lightning defaults) or 140 blocks (Éclair defaults), the robber could make off with an irrevocable bounty.

In regular clock time, that would mean approximately 5.5 hours to steal from a default Core Lightning node or 24 hours for a node running Éclair default software.

By default, nodes limit the number of unconfirmed transactions they transmit or accept at any given time to reduce the chance of various denial-of-service (DoS) attacks. The attacker can conduct a high overflow jamming attack that blocks the victim from sending a justice transaction by continuously overwhelming the node with high fee rate transactions.

By default, a Bitcoin Core node will always choose to propagate the highest fee transactions first and queue lower fee transactions — even if one of those lower fee transactions is the nodes’ own Lightning Network justice transaction.

This is one bug that Core Lightning and Éclair are patching, thanks to Riard’s responsible disclosure.

Again, the high overflow jamming attack blocks the victim from sending an anti-theft transaction by continuously overbidding with higher fee transactions, hence the name “high overflow.”

For this reason, the attack is expensive — with initial estimates north of $130,000 throughout the hours of the attack.

In addition to this high overflow jamming attack, Riard explained another variation of the transaction jamming bug: low overflow.

A variation with thousands of low-fee transactions

The low overflow is a cheaper variant but less reliable for the attacker. Here, to save money, the attacker targets a victim trying to send a transaction to nodes with a maximum unrequested transactions queue of 5,000 per peer.

The attacker floods the victim with a large number of transactions using a minimum transaction fee rate. The victim then announces these transactions to its peers and the peers try to drain the queue by requesting those transactions. If the attacker can maintain a queue of over 5,000 transactions, the attack might be successful.

Technically speaking, the low overflow attack leverages Lightning nodes’ interaction with Bitcoin Core’s MAX_PEER_TX_ANNOUNCEMENTS default, causing inbound transactions to overflow this threshold.

Patching the bug

Riard proposed several mitigations for Lightning Network node software implementations. These providers are working on patches, including random transaction rebroadcasting, more aggressive fee-rebroadcasting, limitation of identical finality time-sensitive transactions, and over-provisioning of transaction relay throughput with peer nodes.

He also proposed changes to Bitcoin Core itself to assist Lightning Network operators. However, changes to Bitcoin Core typically take far longer and need more reviews than Lightning software implementations.

Riard’s Critical Vulnerability Error (CVE) request number 178025 is tracking bug patches of his high and low transaction relay throughput overflow attacks.

Source

Leave A Reply

Your email address will not be published.