A vulnerability in the publsp and liquiditystr (#995577) Lightning Service Provider (LSP) liquidity leasing protocols was exploited, allowing attackers to obtain liquidity with initial balance without paying the full amount. Multiple LSPs lost funds in the attack, despite early detection and mitigation efforts.
pull down to refresh
Every Lightning service gets hit with a drainage attack eventually, we once had someone exploit internal payments even though external payments had locks/atomic transactions... every Lightning node is a bounty
Even with the atomic solution in place we still run a separate watchdog that tracks LND and DB balances and shuts down on any discrepency
post mortem:
view on njump.meFuck... That was smart... And kind of basic at the same time.
It's very unfortunate. Sorry for the loss.
Once again, truly sorry.