
ACINQ Patches Eclair Lightning Flaws With Fund-Loss Risk

ACINQ Patches Eclair Lightning Flaws With Fund-Loss Risk
WEEX View
- The immediate variable is upgrade adoption among Eclair node operators. The company urged users to update, and unpatched nodes remain exposed during channel closures, splicing, and on-the-fly funding flows.
- Markets should also watch whether the disclosure remains a contained client-level patch or prompts broader scrutiny of Lightning fee-handling and channel-close safety across implementations. The report points to similar attack pressure elsewhere in the ecosystem.
- For operators, the practical risk is not Bitcoin base-layer failure but edge-case loss inside Lightning channel management, where fee limits, relay checks, and expiry buffers become part of the safety boundary.
ACINQ said it released Eclair 0.14.3 on Sept. 14 to fix three vulnerabilities in its Bitcoin Lightning implementation, including one that could let a malicious channel peer push a victim’s local balance into miner fees during a cooperative channel close.
According to ACINQ’s disclosure, the most severe issue affected cooperative channel closures. A malicious counterparty could propose a closing fee higher than the victim’s available balance, causing the entire local balance to be paid out as miner fees. Eclair 0.14.3 now rejects fee proposals above the configured maximum.
ACINQ also patched a second flaw tied to splicing, where funds could become stranded if a splice was left unfinished. A third issue involved on-the-fly funding, where a malicious wallet could manipulate payment timing. The updated software now checks relay fees and expiry buffers before committing funds and adds a default cap for channel-opening fees.
The company said operators should upgrade to avoid exploitation. The available information does not include a formal CVE reference or a detailed affected-version list beyond the release of Eclair 0.14.3, and there is no confirmed report in the provided material that the flaws were exploited in the wild before the patch.
Independent technical research cited in the supporting material describes a related Eclair weakness in on-chain monitoring during force-close conditions, where a node could fail to detect a revealed preimage if it only tracked HTLCs from its local commitment state. That issue points to a broader Lightning security challenge: channel safety can depend on how implementations handle old but still valid commitment states, fee updates, and on-chain settlement edge cases.
Why It Matters
This patch matters because Eclair is infrastructure software, and failures at the channel-management layer can translate into direct fund loss even when Bitcoin itself is operating normally. For Lightning users and service operators, the news is a reminder that operational security depends not only on custody and keys, but also on timely client updates and reliable handling of close-out scenarios.
It also adds to a wider pattern of Lightning implementations tightening defenses around fee logic and forced channel closure behavior. As more activity relies on off-chain payment rails, implementation-level bugs may draw more attention from operators, wallet providers, and infrastructure firms that depend on predictable settlement behavior.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreJapan 10-Year JGB Yield Jumps After BOJ Tightening Signal
Japan
Bank of Russia Mutual Fund Crypto Rules Expand Indirect Access
The Bank of Russia reportedly widened mutual fund access to crypto-related instruments, but the exact rule text, investor scope, and reported 10% and 20% limits remain unclear from available documentation.
Hut 8 Poolin Texas Sites Bid Awaits Court Approval
Hut 8 was reported as the winning bidder for Poolin’s Texas sites at $140 million, but Poolin’s Chapter 11 sale still faces a September 29 court hearing in New Jersey.
Kalshi Denies Formal CFTC Investigation Into Trading Activity
Kalshi says the CFTC has not contacted the company and it does not believe it faces a formal investigation, while no public CFTC filing currently confirms a September 24 enforcement case.



