pull down to refresh
21 sats \ 3 replies \ @Wumbo 20h \ on: Stealing Sats from the Lightning Network Custodial Services (2022) security
Interesting attack vectory
My favorite part:
I wrote a simple python script able to generate local LN invoices and submit them to the exchange to process the withdrawals. It reached top speeds of up to ~300 withdrawals per minute (200 ms per withdrawal), simply wow! That makes for ~15K sats per minute. I did not optimize further the script, as the channel was already near being maxed out (current maximum pending HTLCs for a channel is 483 and they were taking long to settle). In addition, my RaspberryPi was getting CPU limited, I believe due to encrypting/decrypting the onion packages.
When your heist is limited by your own CPU haha
reply