Persistent Denial-of-Service Flaw Discovered in Eclair Lightning Implementation
A newly disclosed vulnerability in Eclair, a prominent Bitcoin Lightning Network implementation, has revealed a critical flaw that allows attackers to crash nodes repeatedly without incurring on-chain costs. The bug, which affects versions 0.14.0 and earlier, enables a persistent denial-of-service (DoS) state that cannot be resolved by a simple restart. Because the node saves malicious channel records to its database, it reloads the problematic data upon startup, leading to a cycle of memory exhaustion.
The Mechanics of the Unfunded-Channel Attack
The flaw stems from inconsistent checks between temporary and final channel identifiers, which allowed Eclair’s internal counters to undercount unfunded channels. A malicious peer could exploit this by sending a flood of channel-opening requests without ever broadcasting a funding transaction or paying a single satoshi in on-chain fees. In testing environments, this technique successfully exhausted a 4 GB Java virtual machine (JVM) heap in under 48 minutes by accumulating over 217,000 fake records. Unlike typical DoS attacks that clear upon reboot, these records remain stored on the disk, ensuring that the node crashes again as soon as it attempts to restore its database.
Patching and Recovery Measures
Researcher Erick Cestari, who published the findings, noted that recovery requires manual intervention, such as increasing the JVM heap size or manually deleting fake records from the channel database. While this specific issue was addressed in version 0.14.1 in July, developers at ACINQ now strongly recommend that all operators upgrade to version 0.14.3. This later release addresses not only the persistent-crash bug but also separate fund-loss vulnerabilities and a secondary race-condition bug disclosed by researcher Matt Morehouse. Ensuring nodes are running the latest software is essential for maintaining network availability and protecting against sophisticated database-flooding tactics.