New Bitcoin Lightning Network Vulnerability Exposed: The Replacement Cycling Attack (2024)

Zach Anderson Oct 22, 2023 09:07

A new vulnerability termed as "replacement cycling attack" on the Lightning Network has been unveiled by a developer known as mononaut. The attack manipulates the transaction mechanism of the network, potentially causing financial loss to users. This revelation has led to the resignation of security researcher Antoine Riard from the Lightning Network development team. Despite the challenges, the network's locked-in value stands at $159.5 million, indicating its growing popularity since 2018.

New Bitcoin Lightning Network Vulnerability Exposed: The Replacement Cycling Attack (1)

A recent revelation on the Lightning Network vulnerability known as a “replacement cycling attack” has prompted notable security researcher and developer, Antoine Riard, to step down from his role on the Lightning Network development team. The disclosure of this attack came to light through a detailed thread shared on Twitter by a developer known as mononaut, on 21st October 2023. This attack exploits a particular mechanism within the Lightning Network’s transaction process, causing potential financial loss to users engaged in a channel.

The Mechanism Behind the Attack

The Lightning Network operates as a second layer on top of the Bitcoin blockchain, with the primary goal of scaling the Bitcoin (BTC) transaction capability by facilitating off-chain, peer-to-peer transactions. Users can establish payment channels within the network, execute multiple transactions off-chain, and then record the aggregate transaction on the Bitcoin blockchain upon completion. The core of this attack lies in the manipulation of the Hash/Time Lock Contract (HTLC) outputs, which are essential for securing transactions while they are routed through the network.

The attack unfolds in a multi-step process. Initially, when a payment is being routed through a user, say Bob, from Alice to Carol, the payment is safeguarded by HTLC outputs in Bob's pre-signed channel commitments with each peer. A crucial feature of this setup is the timelock mechanism, which ensures that the outgoing HTLC to Carol expires before the incoming HTLC from Alice, providing Bob a window to react in case of any issues.

The attacker’s objective is to exploit this mechanism by forcing Bob to time-out the transaction on-chain when Carol fails to reveal the payment preimage before the timelock expiration at block T. Upon doing so, Bob broadcasts a transaction to close his channel with Carol and reclaims his funds through an "htlc-timeout" transaction. The attackers, upon spotting this transaction, swiftly broadcast an "htlc-preimage" transaction with a higher fee rate, replacing Bob’s transaction in the mempool. This cycle is repeatedly performed to thwart Bob’s attempt to reclaim his funds, ultimately leaving Bob at a financial loss if the cycle continues for Δ blocks, allowing Alice to time-out the HTLC on the other channel.

Antoine Riard’s Resignation and Concerns

The intricacy and potential danger posed by this attack have raised grave concerns among developers. Antoine Riard vocalized these concerns in a conversation on a public mailing list maintained by the Linux Foundation. He highlighted the tough predicament the Bitcoin community finds itself in due to these newly discovered attack vectors, terming the Lightning Network's situation as "perilous."

Riard stressed that a substantial remedy can only be achieved at the base layer of the network, which might necessitate modifications to the core Bitcoin network, a move requiring robust community consensus due to its impact on the decentralized ecosystem's security architecture. The concerns go beyond just this attack, touching on the overall complexity of the network and the high expectations placed on user experience by the Lightning Network developers.

Despite these hurdles, the Lightning Network continues to gain traction with a reported value locked in of $159.5 million, as per data from DefiLlama, marking a steady growth since its inception in 2018. However, Riard’s departure and warning signal looming challenges for the primary cryptocurrency ecosystem, necessitating a thorough examination and resolution of these vulnerabilities to sustain the network's growth and user trust.

Image source: Shutterstock

New Bitcoin Lightning Network Vulnerability Exposed: The Replacement Cycling Attack (2024)
Top Articles
How Does a Strong Dollar Affect Investing in the Stock Market?
DTD - WisdomTree U.S. Total Dividend Fund
Toa Guide Osrs
Radikale Landküche am Landgut Schönwalde
Room Background For Zepeto
Es.cvs.com/Otchs/Devoted
Sam's Club Gas Price Hilliard
Which aspects are important in sales |#1 Prospection
8 Ways to Make a Friend Feel Special on Valentine's Day
Housework 2 Jab
United Dual Complete Providers
Top tips for getting around Buenos Aires
Conscious Cloud Dispensary Photos
Q Management Inc
Spider-Man: Across The Spider-Verse Showtimes Near Marcus Bay Park Cinema
50 Shades Of Grey Movie 123Movies
[Cheryll Glotfelty, Harold Fromm] The Ecocriticism(z-lib.org)
Program Logistics and Property Manager - Baghdad, Iraq
Ac-15 Gungeon
Form F-1 - Registration statement for certain foreign private issuers
Shadbase Get Out Of Jail
F45 Training O'fallon Il Photos
1 Filmy4Wap In
Regina Perrow
Foodsmart Jonesboro Ar Weekly Ad
Darrell Waltrip Off Road Center
Angel Haynes Dropbox
Weather October 15
Hwy 57 Nursery Michie Tn
Kleinerer: in Sinntal | markt.de
Tire Pro Candler
The Menu Showtimes Near Amc Classic Pekin 14
Greencastle Railcam
El agente nocturno, actores y personajes: quién es quién en la serie de Netflix The Night Agent | MAG | EL COMERCIO PERÚ
AP Microeconomics Score Calculator for 2023
Ket2 Schedule
Mistress Elizabeth Nyc
Go Smiles Herndon Reviews
Muziq Najm
Bitchinbubba Face
Pathfinder Wrath Of The Righteous Tiefling Traitor
Craigslist Minneapolis Com
Southwest Airlines Departures Atlanta
Rise Meadville Reviews
Zeeks Pizza Calories
Costner-Maloy Funeral Home Obituaries
Lightfoot 247
Phunextra
Cars & Trucks near Old Forge, PA - craigslist
Escape From Tarkov Supply Plans Therapist Quest Guide
Latest Posts
Article information

Author: Virgilio Hermann JD

Last Updated:

Views: 6143

Rating: 4 / 5 (61 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Virgilio Hermann JD

Birthday: 1997-12-21

Address: 6946 Schoen Cove, Sipesshire, MO 55944

Phone: +3763365785260

Job: Accounting Engineer

Hobby: Web surfing, Rafting, Dowsing, Stand-up comedy, Ghost hunting, Swimming, Amateur radio

Introduction: My name is Virgilio Hermann JD, I am a fine, gifted, beautiful, encouraging, kind, talented, zealous person who loves writing and wants to share my knowledge and understanding with you.