Core Lightning is investigating a vulnerability in an experimental feature that could expose user funds to risk. The project advised nodes with experimental features enabled to disable them immediately and wait for an official patch. High-risk options include --experimental-dual-fund, --experimental-splicing, and --experimental-peer-storage.
SlowMist said a similar issue fixed in August allowed a remote peer to specify arbitrary or zero fees during channel opening or fund adjustment. The local node could sign and write the data to its database without further verification, potentially forcing abnormal fee payments or triggering a crash loop that kept the node offline. SlowMist recommended removing all experimental parameters, keeping the node in offline mode rather than shutting it down completely to preserve on-chain monitoring, verifying patch signatures before upgrading, and avoiding unofficial patch links.
Core Lightning Experimental Feature Vulnerability May Put Funds at Risk
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
