
LDK releases v0.2.6 patch fixing two critical Lightning Network vulnerabilities
- —A Splice vulnerability allows a counterparty to inflate fees and steal the difference
- —A repeated Payment Hash causes a ChannelManager failure and node hang after restart
- —Patch v0.2.6 was released on September 9 but requires updates on the application side
- —No cases of actual damage or attacks have been recorded
Why it matters: The vulnerabilities affect wallets and infrastructure on LDK; delays in updating increase the risk to user funds.
Source: Siam Blockchain