AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 56 Bitcoin

Merge pull request #11290 from allenpiscitello/fix/blinded-path-fee-overflow

Public commit record

What the developer wrote

Authored by ziggieXXX

78/100 · Adequate
Merge pull request #11290 from allenpiscitello/fix/blinded-path-fee-overflow

blindedpath: avoid uint32 overflow in accumulated fee calc
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit fixes a math overflow bug in LND's blinded payment paths. When building a private (blinded) route for an invoice, the node adds up per-hop fees using 32-bit unsigned integers. If the total base fee or fee rate exceeded about 4295, the sum would wrap around to a tiny number. The invoice would then advertise fees that were too low, so any payer sending through that path would underpay and the payment would fail. The fix uses checked 64-bit arithmetic and simply skips any route whose true fees don't fit in the invoice's 32-bit fields, rather than advertising incorrect fees.

Recommended action

Apply the patch and include the new tests. Nodes that create blinded invoices should upgrade so they do not advertise under-reported fees for high-fee routes. No immediate action is needed for payment senders, but they may retry failed blinded payments after the receiving node upgrades.

Security signals we found

01

Integer overflow in fee aggregation leading to under-reported invoice fees

02

Blinded path payinfo fields are uint32, requiring exact representation of enforced fees

03

Payments to affected invoices would fail due to payer underpayment

04

Fix uses checked arithmetic (bits.Mul64/bits.Add64) and rejects overflowing paths

05

Release notes explicitly describe the bug as a fixed overflow

Risk score

Why this scored 56/100

Our methodology →
Potential impact 18/30
Exploitability 8/25
Stealth signal 6/15
Affected reach 10/15
Confidence 9/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.