Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Lightning Labs Discloses Critical Bug That Marked Canceled Bitcoin Payments as Settled

A vulnerability in older Lightning Terminal versions could mark canceled Bitcoin Lightning invoices as paid, potentially leading merchants to release goods or credit without receiving funds. The issue has been patched, but outdated installations remain exposed.
3 hours ago 13 views
Lightning Labs Discloses Critical Bug That Marked Canceled Bitcoin Payments as Settled

Lightning Labs disclosed a critical vulnerability on September 21, 2026, affecting older versions of its Lightning Terminal software. The bug could mark a Bitcoin Lightning invoice as paid even after a payment was canceled and returned to the sender, creating significant risk for merchants.

A merchant relying on the false invoice status could release goods or credit without receiving funds. Lightning Labs rates the vulnerability as high severity due to this potential for financial loss, though the company has not disclosed any actual merchant losses from the flaw.

How the Bug Occurred

The issue stemmed from a mismatch between the software's invoice record and the payment's actual outcome. Lightning payments use hashed time-locked contracts (HTLCs) to transfer funds. In this case, an HTLC was canceled on the network and returned to the sender, but the receiving node still recorded the invoice as settled in its database.

The vulnerability involved two separate defects. First, tapd, software for Taproot Assets bundled with Lightning Terminal, had an invoice interceptor that treated any HTLC carrying custom wire records as an asset payment. Some sender implementations added an experimental endorsement record even to ordinary Bitcoin payments, causing tapd's strict-forwarding rule to instruct lnd to cancel the HTLC set.

Second, the lnd Lightning node had a separate accounting error. When an interceptor canceled an HTLC set, affected versions canceled the payment on the network but still marked the invoice as settled in the database. This defect meant that any other client of lnd's HtlcModifier interface that canceled an HTLC set could produce the same mismatch.

The vulnerability did not affect Bitcoin's base layer, and sender funds were not at risk according to the advisory.

Fixes and Affected Versions

Lightning Labs released fixes before public disclosure. The tapd trigger was fixed in version 0.5.1 on February 12, 2025. The lnd accounting error was fixed in version 0.19.0-beta on May 22, 2025.

Lightning Terminal version 0.15.0-alpha and later include both fixes. Affected versions include earlier Terminal releases, Taproot Assets through version 0.5.0, and lnd versions 0.18.4-beta through 0.18.5-beta.

For Terminal operators who cannot update and have no asset channels, Lightning Labs recommends using the --taproot-assets-mode=disable flag to avoid the tapd trigger that exposed the vulnerability.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $84,130.53+0.36% EthereumETH $2,675.04+0.11% Tether USDUSDT $1.0000-0.03% BNBBNB $771.55+0.69% XRPXRP $1.53+2.64% USDCUSDC $1.000.00% SolanaSOL $116.56+1.70% TRONTRX $0.3384-1.55% HyperliquidHYPE $91.75+0.14% ZcashZEC $1,553.54+3.46%
Prices by Coinranking. Informational only.