Bitcoin’s Lightning Network Faces Existential Risk in “Flood and Loot” Attack

2020-7-4 15:42

Two cryptocurrency enthusiasts from the Hebrew University in Israel tested a known attack vector involving Hash Time-Locked Contracts on the Lightning Network. They concluded that attackers could use these vulnerabilities to perform profitable attacks on unsuspecting victims.

What Is the “Flood and Loot” Attack?

The researchers, Jona Harris and Aviv Zohar, note that these vulnerabilities are inherent to the way HTLCs work, and avoiding this attack is impossible. 

For the uninitiated, HTLCs are a form of cryptographic defense mechanism that lets payment receivers and senders eliminate counterparty risk while using the Lightning Network, or at least that was the original intent. 

The attack enables a malicious actor to siphon Bitcoin from many victims simultaneously by overloading their channels and the lightning network’s capacity. 

“We show that only 85 simultaneously attacked channels are enough to guarantee that the attacker gets away with some money,” said one of the researchers in a blog post.

The victim cannot defend itself against the attack either. The cost of failing the attack is negligible, as the attacker only spends the transaction fees and no other assets in the process.

The attacker starts by opening as many payment channels with victims and sends transactions to another node that the hacker owns. 

Then at a time when Bitcoin transaction fees are high, the attacker accepts the transactions on one end but doesn’t deliver the HTLC owed amount on the other, forcing the victim to go to the blockchain to collect his fair share.

However, because the Bitcoin blockchain is congested and the attacker can change the fees he pays for his transactions, he can outbid the victim in a race to claim the HTLC. 

If the attacker is successful, the blockchain treats the transaction as if it never happened, and returns all funds to the attacker.

The End of Bitcoin’s Lightning Network?

The researchers began studying this particular vulnerability after Bitcoin developer Matt Corallo discovered it on Apr. 21, 2020. Users on Twitter are expressing a mixture of disbelief, disappointment, theories on possible solutions, and accolades for the researchers. 

Very good attack. It seems that the right near term solution is to strictly limit number of inflight HTLCs? I wonder if LN implementations are able to queue up HTLC requests by value so each payment can take its turn through a channel. https://t.co/wSr0uWmPM4

— Zero Knowledge Goof (@LLFOURN) June 28, 2020

Solving this issue is vital for keeping the Bitcoin’s dreams of a speedy layer 2 solution alive.

Already, Ethereum is showing greater promise in this regard. As of last week, 10,000 synthetic BTC have merged into the growing DeFi space.

The future nonetheless looks bright for Bitcoin. Jona Harris told Crypto Briefing that: 

“I believe the Lightning Network is here to stay. The community is aware of it and continuously works on improving the protocol.”

Similar to Notcoin - Blum - Airdrops In 2024

origin »

Santiment Network Token (SAN) на Currencies.ru

$ 0.0865709 (-0.22%)
Объем 24H $210
Изменеия 24h: 9.95 %, 7d: 19.49 %
Cегодня L: $0.0865709 - H: $0.0865709
Капитализация $0 Rank 5672
Цена в час новости $ 0.1454 (-40.46%)

attack lightning network contracts hash involving time-locked

attack lightning → Результатов: 18


Фото:

Bancor Aftermath: Charlie Lee Sees Lightning Network As ‘Ultimate’ Exchange

Self-proclaimed ‘decentralized’ exchange platform Bancor has resumed operations after a $12 million hack, officials confirmed Wednesday. Bancor Resumes Trading After ‘Scam’ Accusations Bancor — which initially lost its own BNT, Ether (ETH) and Pundi X tokens in the attack — faced a broader industry backlash as the sudden theft sparked criticism its decentralization claims were fraudulent.

2018-7-13 23:00


BitPico намерены провести атаку 51% в сети Bitcoin Cash

Команда BitPico, включающая в себя «разработчиков биткоина, майнеров и китов» заявила о скором начале полномасштабной атаки на сеть Bitcoin Cash. Об этих планах команда написала в своём Твиттере.

2018-6-27 12:41


Фото:

‘Roger Ver Will Now Cry’: Stress Testers Start Attack on Bitcoin Cash

BitPico, a group of “Bitcoin developers, miners and whales” which previously stress-tested the Lightning Network, has begun attacking altcoin Bitcoin Cash (BCH). ‘The Bcash attack has been started’ In a series of tweets beginning June 22, the group, whose members’ identities remains unclear, declared that having tested Lightning’s mainnet implementation for rigidity via a coordinated attack, it would do the same to test the BCH network – this time using a 51% attack.

2018-6-26 20:00