AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Bitcoin

Merge pull request #10984 from f321x/fix_onchain_backup_discovery

Public commit record

What the developer wrote

Authored by ghost43

73/100 · Adequate
Merge pull request #10984 from f321x/fix_onchain_backup_discovery

lnwallet: fix discovery of onchain backups
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit fixes how Electrum's Lightning wallet discovers and watches 'on-chain channel backups'—recovery records embedded in funding transactions. Previously, backups could be missed if the wallet learned about a transaction in stages, or if two channels reused the same on-chain funding address. The fix makes the wallet re-check transactions when more of their inputs are identified as belonging to the wallet, and switches watcher callbacks from being keyed by address to being keyed by the unique funding outpoint. A malicious or buggy remote peer could reuse a funding public key, causing two channels to share the same address; the old code might then overwrite the watcher callback for one channel with the other, leaving a backup unwatched and funds unrecoverable if the channel closed.

Recommended action

Treat this as a security fix and include it in the next maintenance release. Users who rely on Lightning channel backups, especially restored wallets, should upgrade. No immediate emergency response is indicated because exploitation requires a malicious or uncooperative remote peer and a specific address-reuse scenario, but the fix prevents a real loss-of-funds vector.

Security signals we found

01

Loss of funds due to missed channel backup discovery

02

Watcher callback collision when funding address is reused

03

Insufficient replay protection for on-chain backup OP_RETURN data

04

Race/ordering issue between transaction addition and wallet input discovery

05

Regression test added for same-funding-address channel backup scenario

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.