Developer of the Lightning Network Withdraws After Revealing a Serious Issue

Shortly after a new serious vulnerability was discovered in the layer-2 payment protocol, Lightning Network developer Antoine Riard took a step back from the project.

In a study posted on Github, Riard described a scenario in which hostile actors may steal money from the Lightning Network by using “replacement cycling attacks,” a sort of attack in which they could swap out an unconfirmed transaction for another.

The new class of replacement cycling assaults “puts lightning in a very perilous position,” according to Riard, even though “low-hanging fruit mitigations” can make the deployment of these attacks more resilient. Only a “sustainable fix,” like a “consensus upgrade” in the Bitcoin network, in the developer’s opinion, can address the problem.

Riard acknowledged that for the previous ten months, no replacement cycling attacks had been seen or reported.

Riard stated that he is ceasing his engagement with the Lightning Network’s development because the problem in this particular situation has not yet been fixed, including “coordinating the handling of security issues at the protocol level.” The developer intends to concentrate more on creating the Bitcoin core in the interim.

Only about seven transactions can be processed on the Bitcoin blockchain every second when the network is operating at peak efficiency. However, at times of greater demand, this may be lower. The Lightning Network steps in at this point.

To increase scalability, the Lightning Network is an additional layer on top of the Bitcoin network. It helps assure speedier processing by reducing some of the transaction load on the Bitcoin blockchain. Since its introduction, Lightning Network has contributed to reducing the volume of transactions on the Proof of Work network.

