"Updates Overflow" Attacks against Two-Party Eltoo ? [combined summary]



Individual post summaries: Click here to read the original discussion on the lightning-dev mailing list

Published on: 2022-12-14T05:57:06+00:00


Summary:

The email conversation discusses the use of two-party eltoo with punishment and Mallory's ability to generate signatures for UA.0 through UA.n. It mentions the scriptPubKeys for different transactions and the ability of lightning nodes to gossip mempool state for channel closes. The conversation also explores the potential attack known as "update overflow" in which an attacker creates a long chain of update transactions to delay confirmation of the final settlement transaction and double-spend an HTLC forwarded by a routing hop. Mitigation strategies such as fee-bumping and a scorched approach are proposed but may not fully prevent the attack. The discussion also covers the possibility of an attacker aggregating update transactions across Lightning channels and the potential implications of miner-harvesting attacks. Finally, the author acknowledges any mistakes or confusions and invites further discussion on the topic.


Updated on: 2023-08-01T00:56:33.642652+00:00