New research: Bitcoin Lightning Network could have multiple security holes

To make Bitcoin more scalable, Joseph Poon and Thaddeus Dryja created the Lightning Network in 2016. The project improves scalability by creating a second layer on the Bitcoin blockchain, and significantly increases transaction speed, as transactions do not require confirmation from all nodes on the network.

lightning-1625550_960_720

Image source: pixabay

However, after a formal security audit last September, the network was found to have multiple vulnerabilities.

Blockchain technology company Blockstream and some of its enterprise projects have been actively involved in the development of the Lightning Network. They even developed a C-lightning implementation of the network in C.

Recently, Christian Decker, a researcher at Blockstream, and Utz Nisslmueller, Klaus-Tycho Foerster, and Stuttgart in the Department of Computer Science at the University of Vienna A research paper was co-authored by Stefan Schmid.

Considering how the Lightning Network uses Gossip algorithms and detection mechanisms to support nodes, this paper investigates whether these mechanisms can be used to access sensitive transaction data.

This paper proposes two attack methods: probing attack and timing attack.

A probe attack is an attempt by a malicious participant to proactively determine the maximum amount of money that can be transferred on a connected target channel. A timed attack is defined as an attack that an attacker attempts to take to find out how long it takes for a routed payment to actually reach its destination.

The research paper shows that as long as "only one channel's balance is lower than or equal to the second lowest balance on the route from the attacking node", it is practical to track payment on any node's reachable channel from the attacking node.

However, researchers also point out that nodes that call themselves private can prevent broadcasts via Gossip, which can be useful for mobile wallets or nodes with limited runtime, such as personal computers.

In addition, although the research team believes that due to the nature of Lightning Network routing, it is impossible to find out the time to the original payment source, they also found that the timing attack "has generated uniformity on the local network with almost no external interference Results of the distribution. "

This research shows that the off-chain routing mechanism of the Layer 2 expansion solution can be used to obtain the status of the private information network, which may pose a threat to end users, because most users connect to a single, well-connected node in order to communicate with Other users interact.

With the continuous development of the Lightning Network, these problems are expected to be resolved, allowing the Bitcoin blockchain to expand and meet the requirements for large-scale adoption.

We will continue to update Blocking; if you have any questions or suggestions, please contact us!

Share:

Was this article helpful?

93 out of 132 found this helpful

Discover more

Blockchain

WIRED Investigating the Mysterious Hacker Incident on the Day of FTX Bankruptcy

Author | Wired Translated | Wu Shuo Blockchain Original Link https//www.wired.com/story/ftx-1-billion-crypto-heist/ w...

Market

FTX's approval for liquidating $3.4 billion worth of tokens this week, what impact will it have on the market?

FTX may obtain court approval for asset liquidation on September 13th. Under the pressure of 3.4 billion sell-off, th...

Opinion

Amazon's participation and the skyrocketing value of AI company Anthropic become FTX's biggest hope of repaying the debt?

FTX previously invested $500 million as a lead investor in Anthropic's Series B financing round, so the expected appr...

Blockchain

How many entities hold Bitcoin? These 7 exchanges are worth watching

Written by: Rafael Schultze-Kraft Translation: Lu Jiangfei Source: Chain News Problems with quantifying the number of...

Blockchain

Bibox and SKR staged the coin ring, and the IEO gambling nature became more intense.

At 8 am on the 22nd, two hours before the start of the first Star Project (IEO) on the Bibox Exchange, Bibox official...

Blockchain

Lawyer's point of view | Analysis of the regulatory environment behind the investigation of the currency exchange

Author: Hu Tao Source: The chain catcher's recent investigation of the currency exchange has triggered industry ...