• Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
Wednesday, March 29, 2023
No Result
View All Result
AltCoin 247
  • Home
  • Cryptocurrency
  • Bitcoin
  • DEFI
  • Regulation
  • Litecoin
  • Dogecoin
  • Altcoin
  • Home
  • Cryptocurrency
  • Bitcoin
  • DEFI
  • Regulation
  • Litecoin
  • Dogecoin
  • Altcoin
No Result
View All Result
AltCoin 247
No Result
View All Result
Home Bitcoin

security – What is the October 2022 bug in LND, what caused it and what would prevent a similar bug in future?

by altcoin247
October 11, 2022
in Bitcoin
0
currencies – How are crypto prices calculated by an exchange? Example game in a spreadsheet to illustrate


There was a bug in LND and btcd which was exposed by a perfectly valid 998-of-999 Taproot multisig transaction broadcast by Burak on October 9th 2022. This transaction met the Taproot consensus rules activated on the network in November 2021, was included in a block by a miner and verified by all Bitcoin Core full nodes (and as far as I know alternative implementations other than btcd).

(The transaction was analyzed here by AdamISZ.)

The Taproot consensus rule upgrade included in BIP342:

Script size limit: The maximum script size of 10000 bytes does not apply. Their size is only implicitly bounded by the block weight limit.

btcd full nodes rejected the transaction and the block the transaction was included in and its blockchain stalled. The btcd wire parsing library was still enforcing the maximum script size limit from SegWit version 0 for SegWit version 1 transactions.

This impacted all LND nodes (both those backed by a Bitcoin Core full node and those backed by a btcd full node) because the btcd wire parsing library that deserializes raw blocks is a LND dependency.

As Olaoluwa Osuntokun (LND, btcd maintainer) stated on Twitter:

The issue was in btcd’s wire parsing library that deserializes raw blocks, the initial implementation of segwit v0 included a consensus level check for witness size limits but also hoisted this check up to the wire parsing layer

With segwit v1, this prior limit of the max accepted witness size was removed, in place of things like the sigop cost abstraction, effectively leaving the limit to the max block weight/size

btcd’s initial segwit v1 implementation correctly updated the consensus logic, but failed to also update the defense-in-depth check in the wire parsing layer (when parsing off the wire you want some sort of upper limit)

With regards to who it will impact and whether they will lose money, this depends on the LND user, on whether channel counterparties seek to exploit this bug and how quickly users are able to update to LND v0.15.2. Other Lightning node implementations (Core Lightning, eclair, LDK etc) are unaffected. If the LND node is backed by a btcd full node then the btcd full node will also need updating. There are two ways this bug could be exploited if LND users aren’t able to update speedily. Channel counterparties could broadcast a revoked state and unless the LND node comes back up within 2 weeks or an external watchtower is employed money could be lost this way. In addition if the LND node is a routing node money could be lost by its inability to close a channel if HTLC hash preimage(s) are not provided by channel counterparties prior to the timeout.

There was further discussion on why the Taproot (BIP341) static test vectors didn’t catch the bug in the LND repo. Olaoluwa Osuntokun again:

btcd is/was using this test vectors. The issue here is that the code the parsed the witnesses for these test vectors isn’t the same code that’s used to read blocks off the wire. When a new block comes in, we fetch the raw block then attempt to decode it, which triggered this issue.

This bug was also covered in Bitcoin Optech.





Source_link

altcoin247

altcoin247

Next Post
Crypto Rule Suggestions From U.S. Panel Seek To Plug Holes

Crypto Rule Suggestions From U.S. Panel Seek To Plug Holes

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Top Polygon (MATIC) Rival Arbitrum Officially Announces DAO Governance and ARB Token Drop

Top Polygon (MATIC) Rival Arbitrum Officially Announces DAO Governance and ARB Token Drop

2 weeks ago
Dogecoin “Has To” Crack Its Previous ATH, David Gokhshtein Predicts Potential

Dogecoin “Has To” Crack Its Previous ATH, David Gokhshtein Predicts Potential

5 months ago

Popular News

  • As Pound Crumbles, a Third of UK Citizens Now Own Cryptocurrency

    As Pound Crumbles, a Third of UK Citizens Now Own Cryptocurrency

    0 shares
    Share 0 Tweet 0
  • How Crypto Exchange Can Revolutionize Businesses

    0 shares
    Share 0 Tweet 0
  • Das Blockmagazin ist da! – Der Altcoinspekulant

    0 shares
    Share 0 Tweet 0
  • Crypto regulations to curb money laundering

    0 shares
    Share 0 Tweet 0
  • How Does Uniglo (GLO) Manage To Have A 35% Price Spike Unlike Fantom (FTM) And Dogecoin (DOGE)?

    0 shares
    Share 0 Tweet 0
AltCoin 247

Welcome to Altcoin247 The goal of Altcoin247 is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

Category

  • Altcoin
  • Bitcoin
  • Cryptocurrency
  • DEFI
  • Dogecoin
  • Litecoin
  • Regulation

Site Links

  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Recent Posts

  • Senate Banking Committee Holds Hearing on Recent Bank Collapses, Calls for Tougher Regulations – Regulation Bitcoin News
  • The US Banking Crisis Isn’t Over Yet: Joe Biden

Copyright © 2022 Altcoin247.net | All Rights Reserved.

No Result
View All Result
  • Home
  • Cryptocurrency
  • Bitcoin
  • DEFI
  • Regulation
  • Litecoin
  • Dogecoin
  • Altcoin

Copyright © 2022 Altcoin247.net | All Rights Reserved.

What Are Cookies
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT