Fun

Custodial Lightning Network Service Attack Discovered by LN ‘Newbie’ — Hacker Strikes 6 LN Custodians

News Feed - 2021-09-21 06:09:52

Custodial Lightning Network Service Attack Discovered by LN "Newbie" — Hacker Strikes 6 LN Custodians


On September 18, a Redditor posted to the r/bitcoin forum and explained how he discovered a way to “attack [the] lightning Network’s custodial services.” The Reddit account dubbed “Reckless Satoshi” wanted to figure out if a “discrepancy between real routing fees and service’s transaction fee can be exploited for a profit.” The researcher disclosed that he wanted to see how large the damage could be and said “it is bad.” 6 Lightning Network Custodial Services Attacked, Researcher Discloses Findings to Offenders Prior to Public Disclosure


A Redditor called Reckless Satoshi published a disclosure post on r/bitcoin this past Saturday and disclosed how he had found a vulnerability with routing fees and some of the Lightning Network’s custodial services. The research attack was done in good faith and after it was complete he disclosed the bugs to the offending services before publishing his findings. Reckless Satoshi used the Lightning Network (LN) attack on six different services including Bitfinex, Muun, Okex, Lnmarkets, Southxchange, and Walletofsatoshi. The Reddit post published by Reckless Satoshi on September 18, 2021.


Reckless Satoshi said the attack was “cheap, but not free,” and a “simple attack.” After depositing funds into the custodial services, Reckless Satoshi used “a node that will be routing the payments between the custodial service and the receiving node.” The attack’s parameters according to the Github code published by Reckless Satoshi.


“If a positive net return is possible, then it is just a matter of optimizing the size of the fee collected and the transaction speed rate to see how big the damage could be,” Reckless Satoshi added. “It is easy to see how this attack must be feasible on any service with [a] free withdrawal fee.”


Reckless Satoshi also published his attack to the code repository site Github. After explaining how he placed a node in the middle, the researcher added: This is one of the simplest attacks. In fact, the only LN attack I can think of, but also I am just a newbie in the process of learning. I assume there are people out there much more capable of conducting this research. Who knows, maybe there have been sizable losses in the past that remain undisclosed. Lightning Network Total Value Locked at $112 Million, Up Over 100% Since the End of July


The visitors who read Reckless Satoshi’s forum thread thanked him for conducting the research and disclosing the bugs to specific custodial LN providers. “I’m glad to see that people are not hacking/exploiting the system just for malicious purposes or to make quick profit out of it,” an individual wrote in response to the disclosure. Moreover, a number of Redditors discussing Reckless Satoshi’s findings argued over what they should call the attack. The Lightning Network total value locked (TVL) on Monday, September 20, 2021, according to defipulse.com stats.


At the time of writing, the Lightning Network has seen its total value locked (TVL) slide by 9.3% during the last 24 hours. However, since July 20, 2021, the LN TVL jumped over 100% from $56 million that day to today’s (2,600+ BTC) $112 million TVL held in the Lightning Network. Much of the 9.3% TVL slide on LN is due to the recent crypto market rout on Monday morning, September 20, as the crypto economy has slid 9% in value during the last 24 hours.


What do you think about the Lightning Network attack described by the Redditor Reckless Satoshi? Let us know what you think about this subject in the comments section below. Largest NFT Market by Volume Opensea Launches Smartphone Application NEWS | 11 hours ago JPMorgan Strategist Estimates Ether"s Fair Value at $1,500 Amid Competition From "Ethereum Killers" NEWS | 16 hours ago Tags in this story $112M TVL, 6 offenders, Attack, BitFinex, bug, Hacker, lightning network, ln, LN bug, LN hack, LN Newbie, LN Services, Lnmarkets, Muun, Node in the middle, Okex, Profit, Reckless Satoshi, Routing fees, Southxchange, The Lightning Network, Vulnerability, Walletofsatoshi.


Image Credits: Shutterstock, Pixabay, Wiki Commons, defipulse.com Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Ethereum and layer-2 addresses surge 127% this year — Glassnode
Helen Partz9 hours agoEthereum and layer-2 addresses surge 127% this year — GlassnodeWhile Bitcoin saw a 20% drop in daily active addresses in Q2 2024, Ethereum and L2s posted a 127% increase in such addresses in H1 20
Jesse Coghlan34 minutes agoCrypto bull run: Traders share their plans for the ‘tornado’ to comeMillions of new crypto investors could be experiencing their very first bull run soon, and those who’ve been through it
Square Enix Contemplates ‘Robust Entry’ Into Blockchain Games as Part of Business Strategy
Square Enix Contemplates "Robust Entry" Into Blockchain Games as Part of Business Strategy Square Enix, one of the biggest developers and publishers in the gaming world, has acknow
Physical Crypto Bank Opens in India — These 14 Locations Offer In-Person Banking, Lending, Crypto Exchange
Physical Crypto Bank Opens in India — These 14 Locations Offer In-Person Banking, Lending, Crypto Exchange A crypto bank has begun opening physical branches in
Bitcoin privacy will survive despite CoinJoin closure — zkSNACKs CEO
Gareth Jenkinson14 hours agoBitcoin privacy will survive despite CoinJoin closure — zkSNACKs CEOThe impending closure of zkSNACKs’ CoinJoin service has been described as a setback for Bitcoin developers and privacy p
Ripple CEO Warns of Harm to Crypto Industry if SEC Wins Lawsuit Over XRP
Ripple CEO Warns of Harm to Crypto Industry if SEC Wins Lawsuit Over XRP The CEO of Ripple Labs has warned of the harm to the crypto industry if the U.S. Securities and Exchange Co
Reddit converts excess cash into Bitcoin and Ethereum
Brayden Lindrea8 hours agoReddit converts excess cash into Bitcoin and EthereumThe social news network also revealed it has been experimenting with Ether and MATIC as a form of payment for sales of virtual goods.2497 Tot
Bitcoin trader says sub-$57K BTC price would help sustain bull market
William Suberg8 hours agoBitcoin trader says sub-$57K BTC price would help sustain bull marketBitcoin could use a deeper dip to reset “bull market sustainability,” some of the latest BTC price analysis concludes.3491
Fintechs Accounted for Over 30% of Tracked Kenyan Tech Startups in 2022 — Study
Fintechs Accounted for Over 30% of Tracked Kenyan Tech Startups in 2022 — Study As of November 2022, Kenyan fintechs accounted for 30.2% or 93 out of the 308 tracked tech startup
Binance Calls for Global Crypto Regulation While Launching ‘Crypto Is Evil’ Ad Campaign
Binance Calls for Global Crypto Regulation While Launching "Crypto Is Evil" Ad Campaign Cryptocurrency exchange Binance has called for “global regulatory frameworks for cryp
Jeff Booth Warns of Debt Deflation If Federal Reserve Keeps Hiking Interest Rates
Jeff Booth Warns of Debt Deflation If Federal Reserve Keeps Hiking Interest Rates The author of “The Price of Tomorrow,” Jeff Booth, has warned about debt deflation, ca
DeFi Defied: Five Key Benefits The COV Token Will Bring To Covesting
DeFi Defied: Five Key Benefits The COV Token Will Bring To CovestingIn the ever-evolving crypto market that never sleeps, new trends and coins are popping up every passing day. The