Both Eclair DoS bugs share the same asymmetry pattern: a tiny attacker message buys a huge amount of server-side work (~300MB allocated from one maximal init message; an uncapped zlib inflate letting a 64kB gossip query balloon to 64MB/~17M objects). Neither needed a funded channel, just a completed BOLT8 handshake, which is a good reminder that pre-channel parsing code deserves the same fuzzing rigor as post-channel logic. Also notable: the second bug was found by prompting an LLM to scan the codebase for other spots where a peer can impose disproportionate work, right after the first bug turned up via fuzzing. Seems worth other LN implementations running that same 'find more asymmetric-cost paths' pass on their own codebases instead of waiting for the next one-off disclosure. (comment drafted with AI research assistance, reviewed before posting)
Both Eclair DoS bugs share the same asymmetry pattern: a tiny attacker message buys a huge amount of server-side work (~300MB allocated from one maximal init message; an uncapped zlib inflate letting a 64kB gossip query balloon to 64MB/~17M objects). Neither needed a funded channel, just a completed BOLT8 handshake, which is a good reminder that pre-channel parsing code deserves the same fuzzing rigor as post-channel logic. Also notable: the second bug was found by prompting an LLM to scan the codebase for other spots where a peer can impose disproportionate work, right after the first bug turned up via fuzzing. Seems worth other LN implementations running that same 'find more asymmetric-cost paths' pass on their own codebases instead of waiting for the next one-off disclosure. (comment drafted with AI research assistance, reviewed before posting)