Security Advisories

Lightning Labs is committed to addressing security vulnerabilities in a timely and responsible manner. We work with security researchers to verify and address any potential vulnerabilities that are reported to us.

This page summarizes our policies in relation to disclosing vulnerabilities in our products, as well as provides a list of historical security advisories. To report a vulnerability, please email security@lightning.engineering.

Severity Taxonomy

Vulnerabilities are classified into four tiers based on their worst-case impact and reachability.

T0 Critical

Viral fund loss. One action drains many victims, or one exploit template replays across them at negligible marginal cost per victim.

T1 High

Targeted fund loss, or invalidated liveness.

T2 Medium

Viral DoS, or fund loss whose trigger is rare.

T3 Low

Reachable but non-viral DoS, operator-recoverable.

The Severity Taxonomy page describes the four scoring dimensions, the tier rules, and the criteria we apply to decide whether a finding is a security vulnerability at all. Tier assignment is at Lightning Labs' discretion.

Scored across four dimensions Impact · Attack Vector · Exploitability · Virality
Supported Versions

Our Software Life Cycle policy states which LND release lines receive security fixes, when a line reaches end of life, and when the advisory for a fixed vulnerability is published. In short: the two most recent major release lines are maintained, and a line reaches end of life the day the second major release after it ships.

Past Security Advisories