Odaily Planet Daily News Senior Bitcoin developer "Calle" issued a vulnerability alert to node operators running Lightning Network Daemon (LND) version 0.18.5 or LITD version 0.14.1 or earlier. The vulnerability is related to how LND checks the description field of lightning invoice settlements, allowing hackers to remotely manipulate their payment status and steal funds.
Satoshi Labs co-founder Pavol Rusnak also issued this warning to remind Lightning Network users to update their node software as soon as possible. The newly released node software LND 0.18.5 and LITD 0.14.1 fix this remote threat vector. It should be noted that LND 18.5 was just released last week, so many LND nodes are still outdated and vulnerable.
As of press time, the number of outdated LND nodes is in the hundreds or thousands. Historically, LND has been the preferred software for most lightning node operators. (Protos)