Decade-old LND Lightning bug finally patched by devs – fixed

LND patches decade-old reorg vulnerability — scales channel-close confirmations to 1–6 blocks and adds real-time competing-close detection

  • Olaoluwa “Roasbeef” Osuntokun merged a fix this month addressing a Lightning node issue first reported in 2016.
  • The patch changes channel-close confirmation rules from one block to a scale up to six blocks based on channel size.
  • The update also adds real-time detection of competing close transactions and monitors negative confirmations to reduce blockchain reorganization (reorg) risk.
  • The problem was tracked as issue 53, the oldest open issue in the LND repository, and had been described as *“unresolved for a decade.”*
  • LND is a leading Lightning implementation; the change arrived after years of contributions and follows the project’s early days when at-risk funds were small.

Olaoluwa “Roasbeef” Osuntokun merged a code change this month that addresses a long-standing vulnerability in the LND Bitcoin Lightning node implementation first raised in October 2016. The fix targets the risk that on-chain channel close transactions could be affected by Bitcoin blockchain reorganizations, which can alter transaction confirmations.

- Advertisement -

The update scales the number of required confirmations for channel closures from one block up to six blocks, with larger channels requiring more confirmations. The merged changes are available in PR 10331.

The patch also revises LND’s state machine to monitor competing channel close transactions in real time and to detect negative confirmations, meaning a transaction seen in a block that is later removed by a reorg. A confirmation is a block that includes a transaction; more confirmations reduce the chance a transaction will be reversed during a reorg.

Lightning Labs co-founders Elizabeth Stark and Olaoluwa “Roasbeef” Osuntokun launched the LND software in 2016. Osuntokun originally acknowledged the security concern in issue 53, which remained open for years and was described as “unresolved for a decade.”

The issue was effectively a design tradeoff: LND prioritized faster, mostly secure channel closes for user experience, accepting a small reorg risk. That tradeoff existed while the network and funds at risk were much smaller than today.

- Advertisement -

LND is widely used among Lightning implementations; a survey of implementations is available in this overview on Medium. The change comes after long-term maintenance and community contributions and follows the project’s commercial growth as a venture-backed LND company.

For updates and further coverage, follow on X, Google News, or YouTube.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

$50M AAVE Swap Yields $36K Despite Warning

A trader lost nearly $50 million on Thursday after swapping that amount of USDT...

Teamsters Threaten to Block Paramount-WBD Merger

The International Brotherhood of Teamsters opposes the Paramount Skydance-Warner Bros. Discovery merger without enforceable...

STRC Sales Surge, Eye Record Single-Day Bitcoin Buy

A community dashboard tracking Strategy's STRC sales suggests March 12, 2026 could see the...

SEC’s Peirce Urges Simpler Rules Amid Tokenization Talks

SEC Commissioner Hester Peirce argues regulators should avoid micromanaging markets and consider simplifying disclosure...

Rust VENON Malware Targets Brazilian Banking Apps

A new Rust-based banking Trojan named VENON is targeting Brazilian users, departing from the...

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...