AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 66 Bitcoin

Reject seed files with an invalid length (#3389)

Public commit record

What the developer wrote

Authored by pm47

88/100 · Strong
Reject seed files with an invalid length (#3389)

Seed files were read without checking their length. Creating a seed file is not atomic: if we crash between creating the file and writing the seed, an empty seed file is left behind. On the next restart we
would then derive our node and channel keys from an empty seed.

We now refuse to start if a seed file doesn't contain exactly 32 bytes. The only exception is legacy seeds (before 31022ceca5), which were serialized compressed private keys: 32 bytes followed by 0x01. We keep accepting them, without dropping the trailing byte, so that our keys don't change.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This patch fixes a bug in the Eclair Bitcoin Lightning node where, if the node crashed while creating its secret seed file, it could leave an empty file behind. On the next restart, Eclair would silently use that empty seed to generate all the node's private keys, producing predictable keys that could let an attacker steal funds. The fix now refuses to start unless the seed file contains exactly 32 bytes, while still accepting older 33-byte legacy seed files.

Recommended action

Upgrade to a release containing this commit. Operators should verify that existing seed files are 32 bytes (or 33-byte legacy seeds ending in 0x01) and have secure filesystem permissions. If an empty or short seed file was ever used, treat derived keys as compromised and rotate funds to a new node with a freshly generated 32-byte seed.

Security signals we found

01

Use of weak/predictable cryptographic seed for key derivation

02

Missing input validation on security-critical seed file

03

Non-atomic file write creating corrupt/empty secret material

04

Patch adds explicit length validation and startup failure on invalid seed

05

Test cases added for empty seed rejection and legacy seed compatibility

Risk score

Why this scored 66/100

Our methodology →
Potential impact 24/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.