AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 36 Bitcoin

Merge pull request #11277 from GeorgeTsagk/maxfeeratio-ceiling

Public commit record

What the developer wrote

Authored by ziggieXXX

73/100 · Adequate
Merge pull request #11277 from GeorgeTsagk/maxfeeratio-ceiling

[1.5/3] aux revocation: allow maxFeeRatio above 1.0
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This change loosens a safety cap on Bitcoin transaction fees for a specific LND wallet RPC. Previously, callers could not allow fees larger than the transaction's total output value. Now they can opt in to a ratio up to 5x the output value, with a hard ceiling and an audit log warning. The intended use is legitimate: sweeping or re-creating tiny 'asset carrier' outputs that hold only about 1000 satoshis of Bitcoin but carry valuable off-chain assets. Without the higher cap, those operations could be blocked when on-chain fees spike. The change is defensive rather than a vulnerability fix, but it does increase the damage a compromised caller or malicious user with RPC access could do by overpaying fees.

Recommended action

Treat this as a configuration/risk change, not an urgent vulnerability patch. Operators should monitor FundPsbt calls with maxFeeRatio > 1.0 via the new warning log, restrict RPC access to trusted callers, and ensure wallet policies require explicit approval for high fee ratios. Review whether 5.0 is the appropriate ceiling for deployed use cases.

Security signals we found

01

Relaxation of a fee-ratio safety bound from 1.0 to 5.0

02

New audit log warning when caller opts into ratio > 1.0

03

Hard ceiling at 5.0 to catch misconfiguration

04

Default maxFeeRatio remains 0.2 for internal flows

05

Only the FundPsbt RPC path exposes the opt-in

Risk score

Why this scored 36/100

Our methodology →
Potential impact 8/30
Exploitability 6/25
Stealth signal 4/15
Affected reach 7/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.