v0.14.1
Eclair version containing critical channel opening flow fixes 2
300 MB
Memory allocated and discarded by a single maximum-length init message in older Eclair versions 1
1 MB per second
Memory leak rate caused by the open_channel race condition exploit 2
48 minutes
Time required for a single connection to crash a node with a 4 GB heap using the unfunded channel flood 2

Overview of Eclair Vulnerabilities

Recent security disclosures have revealed multiple denial-of-service (DoS) vulnerabilities affecting Eclair, a popular Lightning Network node implementation 12. Security researcher Matt Morehouse published the details of these vulnerabilities on Delving Bitcoin 12. The identified flaws affect Eclair versions v0.13.1, v0.14.0, and earlier 12. To protect their systems, node operators are advised to upgrade to Eclair version v0.14.1 or later 2.

While some of the underlying issues were partially addressed in Eclair version v0.14.0, which was released in May, complete protection against the channel opening flow exploits requires version v0.14.1 12.

Initialization and Gossip Vector Details

The first set of vulnerabilities involves the initialization handshake and gossip query protocols 1. Each attack requires only a completed BOLT8 handshake, not an active channel 1. One vulnerability lies in how Eclair parsed feature bits within an initialization message 1. Because the node parsed these bits individually, it allocated multiple objects for each bit 1. Consequently, a single initialization message of maximum length could allocate and discard approximately 300 MB of memory while monopolizing a parsing thread for up to 300 ms 1. In testing, an attacker utilizing a few dozen connections to repeat this message successfully disconnected all of a node's peers within one minute and exhausted its memory within five minutes 1. Morehouse discovered this bug using a fuzzer named smite 1.

Another vulnerability was found in Eclair's handling of gossip queries 1. Although BOLT7 removed zlib encoding for specific query messages in April 2022, Eclair continued to accept them 1. Because Eclair's zlib decompression lacked an output limit, a 64 kB message could inflate to 64 MB and generate about 17 million objects 1. A flood of these messages could take an Eclair node offline within seconds 1. Morehouse located this flaw by using a large language model (LLM) to search the codebase for resource asymmetry bugs 1.

Channel Opening Flow Flaws

Two additional vulnerabilities target Eclair's channel opening flow 2. The first, designated as LNF-2026-0003, is an open_channel race condition 2. In Eclair version v0.14.0 and earlier, a delay exists between checking for duplicate temporary channel IDs and inserting a new channel into the node's map 2. An attacker can exploit this delay by pipelining identical messages, causing Eclair to spawn two channel actors for a single ID 2. The second actor overwrites the first, leaving an orphaned actor that consumes about 25 KB of heap memory 2. Exploiting this race repeatedly leaks approximately 1 MB of memory per second, eventually causing a crash 2.

The second channel opening flaw is an unfunded channel flood 2. Attackers can bypass Eclair's rate limiter by reusing a channel's final ID as the temporary ID of the next request 2. This trick causes the rate limiter to track the ID twice and remove both entries at once, allowing the number of pending channels to grow indefinitely 2. Because each pending channel stores peer features occupying about 65 KB, a single connection can exhaust a node with a 4 GB heap in roughly 48 minutes 2. Because these channels are persisted, the node will crash repeatedly upon restarting until the database is manually cleaned or the heap size is increased 2.

Broader Lightning Network Impact

While the detailed vulnerabilities specifically target Eclair, other popular Lightning Network implementations are also undergoing maintenance and security updates 1. For instance, LND released version v0.21.4-beta.rc1, which is a release candidate for a maintenance release 1. This LND release candidate includes a fix for channel announcement synchronization and introduces a restriction on new legacy channels 1.

The discovery of the Eclair bugs also highlights the evolving role of automated testing tools 12. Morehouse utilized both the specialized Lightning Network fuzzer smite and an LLM-based harness to identify these deep architectural flaws 12. The LLM-based tool specifically mapped codebase entry points and invariants to hunt for violations using the BOLT specifications as a reference 2.

What is not yet established

  • Whether Core Lightning nodes are affected by similar vulnerabilities, as the provided disclosures only detail Eclair and LND 12.
  • The exact timeline of when all active Eclair node operators will complete their upgrades to version v0.14.1 or later 2.
  • Whether other Lightning Network implementations have similar race conditions in their channel opening flows 2.

Frequently asked questions

Which Eclair versions are vulnerable to these denial-of-service attacks?

Eclair versions v0.13.1, v0.14.0, and all earlier versions are vulnerable to these exploits 12.

How can an attacker exploit the open_channel race condition?

An attacker can pipeline identical open_channel messages to bypass duplicate checks, spawning two channel actors for a single ID and leaking about 1 MB of memory per second 2.

What tools were used to discover these Eclair vulnerabilities?

The vulnerabilities were discovered by Matt Morehouse using the fuzzer smite and an LLM-based harness that maps codebase entry points against BOLT specifications 12.

Sources

  1. Bitcoin Optech — Bitcoin Optech Newsletter #425 (2026-10-02) https://bitcoinops.org/en/newsletters/2026/10/02
  2. Delving Bitcoin — Disclosure: DoS vulnerabilities fixed in Eclair v0.14.1 (2026-10-01) https://delvingbitcoin.org/t/disclosure-dos-vulnerabilities-fixed-in-eclair-v0-14-1/2928

This brief is for information and education. It is not financial advice or a recommendation to buy or sell.