Fair enough and thank you for the added context.
I have a separate single channel LND node running LNBits so I can run the Lightning Piggys for my kids. I don't allow new signups. Are you saying I should not be running this cause it could still get owned?
I'm weary of any publicly accessible program that can send sats from my node, hence why I built a seperate node with minimal funds on it.
Only the node that is used can be drained
Also, if you do not expose it to the internet, you are mostly fine
Closing it off from the web defeats its use case. Limiting sign ups is probably a good first step.. but Does this problem still exist in v1 (pending release)
Seems like a glaring issue like this should be more broadly discussed. Especially for a codebase that is so regularly utilized by the Bitcoin Lightning community
Not currently. There likely are a lot of other bugs though due to the garbage code quality, and the current payment handling code can register sent payments as not sent in certain cases
Thread collapsed
Thread collapsed
Thread collapsed