{"id":11914,"date":"2022-11-01T22:51:15","date_gmt":"2022-11-01T22:51:15","guid":{"rendered":"https:\/\/coingrafter.com\/index.php\/2022\/11\/01\/huge-transaction-brought-down-lnd-for-the-2nd-time-is-blockstream-responsible\/"},"modified":"2022-11-01T22:51:15","modified_gmt":"2022-11-01T22:51:15","slug":"huge-transaction-brought-down-lnd-for-the-2nd-time-is-blockstream-responsible","status":"publish","type":"post","link":"https:\/\/coingrafter.com\/index.php\/2022\/11\/01\/huge-transaction-brought-down-lnd-for-the-2nd-time-is-blockstream-responsible\/","title":{"rendered":"Huge Transaction Brought Down LND For The 2nd Time. Is Blockstream Responsible?"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<p><span style=\"font-weight: 400;\">Is LND damaged? Or was the ridiculously massive transaction that unsynched it a direct assault on the LND implementation? Does all of this have an effect on the bigger Lightning Network? And what in regards to the bitcoin community? This story begins with every kind of questions and might\u2019t promise to reply all of them. The recreation is afoot. Something\u2019s occurring. It\u2019s exhausting to find out what, although. And it looks like extra shall be revealed, like we nonetheless don\u2019t have all the information.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Let\u2019s study what we do have and attempt to resolve this. And all of it begins with a abstract of the story up to now.\u00a0<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">What\u2019s With LND And These Huge Transactions?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">On October ninth, a developer referred to as <\/span><a href=\"https:\/\/twitter.com\/brqgoo\/status\/1579216353780957185\" rel=\"noopener\"><span style=\"font-weight: 400;\">Burak announced<\/span><\/a><span style=\"font-weight: 400;\"> \u201cI just did a 998-of-999 tapscript multisig, and it only cost $4.90 in transaction fees.\u201d That curious transaction unsynched the Lightning Network, which missed producing one block. The Lightning Labs workforce, accountable for the LND implementation, launched a repair in a matter of hours. The incident made abundantly clear that the Lightning Network continues to be a piece in progress and the implementations are susceptible to assaults.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Today, Burak stroke once more. \u201cSometimes to find the light, we must first touch the darkness,\u201d <\/span><a href=\"https:\/\/twitter.com\/brqgoo\/status\/1587397646125260802\" rel=\"noopener\"><span style=\"font-weight: 400;\">he tweeted<\/span><\/a><span style=\"font-weight: 400;\"> accompanying <\/span><a href=\"https:\/\/blockstream.info\/tx\/73be398c4bdc43709db7398106609eea2a7841aaf3a4fa2000dc18184faa2a7e\" rel=\"noopener\"><span style=\"font-weight: 400;\">another huge transaction<\/span><\/a><span style=\"font-weight: 400;\">. This time, the affect solely hit LND nodes. Everybody else remained in synch, whereas LND was caught. For some time there, LND nodes might route funds however have been unaware of the state of the chain. Lightning Labs acknowledged the bug of their official channels and started working on <\/span><a href=\"https:\/\/github.com\/lightningnetwork\/lnd\/releases\/tag\/v0.15.4-beta\" rel=\"noopener\"><span style=\"font-weight: 400;\">a hotfix that was released<\/span><\/a><span style=\"font-weight: 400;\"> a number of hours later.<\/span><\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">With the assistance of the <a href=\"https:\/\/twitter.com\/lightning?ref_src=twsrc%5Etfw\" rel=\"noopener\">@lightning<\/a> Labs workforce (h\/t <a href=\"https:\/\/twitter.com\/guggero?ref_src=twsrc%5Etfw\" rel=\"noopener\">@guggero<\/a>), us at <a href=\"https:\/\/twitter.com\/GaloyMoney?ref_src=twsrc%5Etfw\" rel=\"noopener\">@GaloyMoney<\/a> and our CI pipelines the <a href=\"https:\/\/twitter.com\/BTCBeachWallet?ref_src=twsrc%5Etfw\" rel=\"noopener\">@BTCBeachWallet<\/a> nodes are up to date with the bugfix inside 31 blocks after 73be398c4bdc43709db7398106609eea2a7841aaf3a4fa2000dc18184faa2a7e hit.<br \/>Can this keep the report now? <a href=\"https:\/\/t.co\/Utrabq86jF\">pic.twitter.com\/Utrabq86jF<\/a><\/p>\n<p>\u2014 openoms (@openoms) <a href=\"https:\/\/twitter.com\/openoms\/status\/1587460034778337282?ref_src=twsrc%5Etfw\" rel=\"noopener\">November 1, 2022<\/a><\/p>\n<\/blockquote>\n<p><span style=\"font-weight: 400;\">To clarify the implications to the remainder of us, Applied Cryptography Consultant <\/span><a href=\"https:\/\/twitter.com\/peterktodd\/status\/1579269368684638208\" rel=\"noopener\"><span style=\"font-weight: 400;\">Peter Todd analyzed<\/span><\/a><span style=\"font-weight: 400;\"> the state of affairs. \u201cBecause LN is _not_ a consensus system, having different implementations is a good thing. Some of the network is down right now. But there\u2019s no real harm in the rest staying up. Meanwhile, the root cause of the problem is buggy btcd code,\u201d he tweeted.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">So far, every part sounds fantastic. The transaction\u2019s intention appears to focus on a vulnerability with out inflicting appreciable harm. The factor is, Burak wrote, \u201cyou\u2019ll run cln. and you\u2019ll be happy\u201d within the OP_RETURN DATA. And \u201ccln\u201d refers to Core Lightning, LND\u2019s major competitors. A <\/span><a href=\"https:\/\/blockstream.com\/lightning\/\" rel=\"noopener\"><span style=\"font-weight: 400;\">Blockstream product<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-202965 aligncenter\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/11\/BTCUSD_2022-11-01_18-24-41-640x356.png\" alt=\"BTCUSD price chart for 11\/01\/2022 - TradingView\" width=\"640\" height=\"356\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/11\/BTCUSD_2022-11-01_18-24-41-640x356.png 640w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/11\/BTCUSD_2022-11-01_18-24-41-980x545.png 980w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/11\/BTCUSD_2022-11-01_18-24-41-768x427.png 768w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/11\/BTCUSD_2022-11-01_18-24-41-750x417.png 750w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/11\/BTCUSD_2022-11-01_18-24-41.png 1012w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/p>\n<pre style=\"text-align: center;\">BTC value chart for 11\/01\/2022 on Bitstamp | Source: BTC\/USD on <a href=\"https:\/\/www.tradingview.com\/symbols\/BTCUSD\/\" rel=\"noopener\">TradingView.com<\/a><\/pre>\n<h2><span style=\"font-weight: 400;\">Did Someone Report The LND Bug Well Before The Attack?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Another pseudonymous developer <\/span><a href=\"https:\/\/twitter.com\/r32a_\/status\/1587409132973334532\" rel=\"noopener\"><span style=\"font-weight: 400;\">wrote to Burak<\/span><\/a><span style=\"font-weight: 400;\">, \u201cThe ethical thing to do is to a vulnerability disclosure to the Lightning Labs team instead of taking down majority of the nodes in the network.\u201d Then, one more developer named <\/span><a href=\"https:\/\/twitter.com\/ajtowns\/status\/1587414992961216512\" rel=\"noopener\"><span style=\"font-weight: 400;\">Anthony Towns delivered<\/span><\/a><span style=\"font-weight: 400;\"> a mandatory plot twist, \u201cFor what it\u2019s worth, I also noticed this bug and disclosed it to Olaoluwa Osuntokun about two weeks ago. The btcd repo doesn\u2019t seem to have a reporting policy for security bugs, so not sure if anyone else working on btcd found out about it.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cThe initial report was to the wrong place and was missed, I followed up a week later on the 19th and Olaoluwa Osuntokun replied with some thoughts on why this wasn\u2019t caught already and how to do better,\u201d Towns additional elaborated. Later on, Osuntokun confirmed the report and revealed, \u201cas the post was public I deleted it then followed up w\/ him via email. We had a patch ready to go for the minor release (w\/ some other memory optimizations), but obv this preempted it.\u201d<\/span><\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">additionally <a href=\"https:\/\/twitter.com\/ajtowns?ref_src=twsrc%5Etfw\" rel=\"noopener\">@ajtowns<\/a> did contact me, by making a difficulty on my public fork of btcd w\/ particulars, because the put up was public I deleted it then adopted up w\/ him through electronic mail<\/p>\n<p>we had a patch able to go for the minor launch (w\/ another reminiscence optimizations), however obv this preempted it<\/p>\n<p>\u2014 Olaoluwa Osuntokun (@roasbeef) <a href=\"https:\/\/twitter.com\/roasbeef\/status\/1587481219981508608?ref_src=twsrc%5Etfw\" rel=\"noopener\">November 1, 2022<\/a><\/p>\n<\/blockquote>\n<p><span style=\"font-weight: 400;\">He additionally identified an essential factor, \u201cI didn\u2019t imagine someone would work w\/ miners to mine it.\u201d This specific bug required miner participation to go by means of. There may\u2019ve been extra to this assault than meets the attention. However, there have been over $700 in charges hooked up to the transaction. That exorbitant payment may\u2019ve been sufficient to go the weird transaction by means of.\u00a0\u00a0<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Is Blockstream Responsible For The Attack?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">This is the place every part will get tough, as a result of it looks like Burak was beforehand sponsored by Blockstream to work on liquid covenants on Bitmatrix. In a sequence of then-deleted tweets, Lightning Labs CEO Elizabeth Starks appears to be accusing Blockstream of not less than sponsoring the assaults. When questioned by a Blockstream worker, Starks replied, \u201cIs this not true that it\u2019s a sponsored dev?\u201d and \u201cYou appear to have left out the deleted tweet where I specifically mentioned it was clear that this attack was not part of what was sponsored.\u201d<\/span><\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Is this not true that it is a sponsored dev? My level was not that *this* work was funded, however as you wrote this individual is &#8220;def sponsored by blockstream.&#8221; <a href=\"https:\/\/t.co\/s1SHZnnbo5\">pic.twitter.com\/s1SHZnnbo5<\/a><\/p>\n<p>\u2014 elizabeth stark \ud83c\udf60 (@starkness) <a href=\"https:\/\/twitter.com\/starkness\/status\/1587487360958300161?ref_src=twsrc%5Etfw\" rel=\"noopener\">November 1, 2022<\/a><\/p>\n<\/blockquote>\n<p><span style=\"font-weight: 400;\">Enter Suredbits founder<\/span><a href=\"https:\/\/twitter.com\/Chris_Stewart_5\/status\/1587454971150094336\" rel=\"noopener\"><span style=\"font-weight: 400;\"> Chris Stewart, who took it even further<\/span><\/a><span style=\"font-weight: 400;\"> and straight up requested Adam Back to verify \u201cthat Blockstream isn\u2019t sponsoring these attacks on LND as a promotional tool for core lightning.\u201d Adam Back denied any sponsorship and defined what he thinks Burak meant. \u201cCould infer from the op_return message is about the risks of using a non Bitcoin core full node for consensus &amp; Core Lightning uses Bitcoin core. maybe Burak is making that point, empirically. It\u2019s a known limitation from LANGSEC security it\u2019s near impossible to bit-wise compatible.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To put every part to mattress, Blockstream researcher <\/span><a href=\"https:\/\/twitter.com\/Snyke\/status\/1587464627260121089\" rel=\"noopener\"><span style=\"font-weight: 400;\">Christian Decker went on the record<\/span><\/a><span style=\"font-weight: 400;\"> and tweeted, \u201cThis is terrible, the Core Lightning team does not condone attacks of any nature. And namedropping a competitor is in really bad taste. Please follow responsible disclosures, and avoid publicity stunts like this, it\u2019s not helping, and causing a lot of issues!\u201d<\/span><\/p>\n<pre style=\"text-align: center;\">Featured Image by <a href=\"https:\/\/unsplash.com\/@bethlaird?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText\" rel=\"noopener\">Bethany Laird<\/a> on <a href=\"https:\/\/unsplash.com\/es\/s\/fotos\/lightning-storm?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText\" rel=\"noopener\">Unsplash<\/a> | Charts by <a href=\"https:\/\/www.tradingview.com\/\" rel=\"noopener\">TradingView<\/a><\/pre>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-182574 aligncenter\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/05\/lightning-g34645fb93_1280-640x380.jpg\" alt=\"Stripe, a lightning over a city\" width=\"640\" height=\"380\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/05\/lightning-g34645fb93_1280-640x380.jpg 640w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/05\/lightning-g34645fb93_1280-980x583.jpg 980w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/05\/lightning-g34645fb93_1280-768x457.jpg 768w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/05\/lightning-g34645fb93_1280-750x446.jpg 750w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/05\/lightning-g34645fb93_1280.jpg 1021w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/bitcoinist.com\/huge-transaction-brought-down-lnd-blockstream\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] Is LND damaged? Or was the ridiculously massive transaction that unsynched it a direct assault on the LND implementation? Does all of this have an effect on the bigger Lightning Network? And what in regards to the bitcoin community? This story begins with every kind of questions and might\u2019t promise to reply all of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":11916,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ocean_post_layout":"","ocean_both_sidebars_style":"","ocean_both_sidebars_content_width":0,"ocean_both_sidebars_sidebars_width":0,"ocean_sidebar":"","ocean_second_sidebar":"","ocean_disable_margins":"enable","ocean_add_body_class":"","ocean_shortcode_before_top_bar":"","ocean_shortcode_after_top_bar":"","ocean_shortcode_before_header":"","ocean_shortcode_after_header":"","ocean_has_shortcode":"","ocean_shortcode_after_title":"","ocean_shortcode_before_footer_widgets":"","ocean_shortcode_after_footer_widgets":"","ocean_shortcode_before_footer_bottom":"","ocean_shortcode_after_footer_bottom":"","ocean_display_top_bar":"default","ocean_display_header":"default","ocean_header_style":"","ocean_center_header_left_menu":"","ocean_custom_header_template":"","ocean_custom_logo":0,"ocean_custom_retina_logo":0,"ocean_custom_logo_max_width":0,"ocean_custom_logo_tablet_max_width":0,"ocean_custom_logo_mobile_max_width":0,"ocean_custom_logo_max_height":0,"ocean_custom_logo_tablet_max_height":0,"ocean_custom_logo_mobile_max_height":0,"ocean_header_custom_menu":"","ocean_menu_typo_font_family":"","ocean_menu_typo_font_subset":"","ocean_menu_typo_font_size":0,"ocean_menu_typo_font_size_tablet":0,"ocean_menu_typo_font_size_mobile":0,"ocean_menu_typo_font_size_unit":"px","ocean_menu_typo_font_weight":"","ocean_menu_typo_font_weight_tablet":"","ocean_menu_typo_font_weight_mobile":"","ocean_menu_typo_transform":"","ocean_menu_typo_transform_tablet":"","ocean_menu_typo_transform_mobile":"","ocean_menu_typo_line_height":0,"ocean_menu_typo_line_height_tablet":0,"ocean_menu_typo_line_height_mobile":0,"ocean_menu_typo_line_height_unit":"","ocean_menu_typo_spacing":0,"ocean_menu_typo_spacing_tablet":0,"ocean_menu_typo_spacing_mobile":0,"ocean_menu_typo_spacing_unit":"","ocean_menu_link_color":"","ocean_menu_link_color_hover":"","ocean_menu_link_color_active":"","ocean_menu_link_background":"","ocean_menu_link_hover_background":"","ocean_menu_link_active_background":"","ocean_menu_social_links_bg":"","ocean_menu_social_hover_links_bg":"","ocean_menu_social_links_color":"","ocean_menu_social_hover_links_color":"","ocean_disable_title":"default","ocean_disable_heading":"default","ocean_post_title":"","ocean_post_subheading":"","ocean_post_title_style":"","ocean_post_title_background_color":"","ocean_post_title_background":0,"ocean_post_title_bg_image_position":"","ocean_post_title_bg_image_attachment":"","ocean_post_title_bg_image_repeat":"","ocean_post_title_bg_image_size":"","ocean_post_title_height":0,"ocean_post_title_bg_overlay":0.5,"ocean_post_title_bg_overlay_color":"","ocean_disable_breadcrumbs":"default","ocean_breadcrumbs_color":"","ocean_breadcrumbs_separator_color":"","ocean_breadcrumbs_links_color":"","ocean_breadcrumbs_links_hover_color":"","ocean_display_footer_widgets":"default","ocean_display_footer_bottom":"default","ocean_custom_footer_template":"","ocean_post_oembed":"","ocean_post_self_hosted_media":"","ocean_post_video_embed":"","ocean_link_format":"","ocean_link_format_target":"self","ocean_quote_format":"","ocean_quote_format_link":"post","ocean_gallery_link_images":"on","ocean_gallery_id":[],"footnotes":""},"categories":[3],"tags":[148,377,1796,874,5012,2081,965,1482],"class_list":["post-11914","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bitcoin","tag-2nd","tag-blockstream","tag-brought","tag-huge","tag-lnd","tag-responsible","tag-time","tag-transaction","entry","has-media","owp-thumbs-layout-horizontal","owp-btn-normal","owp-tabs-layout-horizontal","has-no-thumbnails","has-product-nav"],"_links":{"self":[{"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/posts\/11914","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/comments?post=11914"}],"version-history":[{"count":1,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/posts\/11914\/revisions"}],"predecessor-version":[{"id":11915,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/posts\/11914\/revisions\/11915"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/media\/11916"}],"wp:attachment":[{"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/media?parent=11914"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/categories?post=11914"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/tags?post=11914"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}