Security Advisories

Lightning Labs is committed to addressing security vulnerabilities in a timely and responsible manner. We work with security researchers to verify and address any potential vulnerabilities that are reported to us.

This page summarizes our policies in relation to disclosing vulnerabilities in our products, as well as provides a list of historical security advisories. To report a vulnerability, please email security@lightning.engineering — see Report a Vulnerability below for our PGP key.

Severity Taxonomy

Vulnerabilities are classified into four tiers based on their worst-case impact and reachability.

T0 Critical

Viral fund loss. One action drains many victims, or one exploit template replays across them at negligible marginal cost per victim.

T1 High

Targeted fund loss, or invalidated liveness.

T2 Medium

Viral DoS, or fund loss whose trigger is rare.

T3 Low

Reachable but non-viral DoS, operator-recoverable.

The Severity Taxonomy page describes the four scoring dimensions, the tier rules, and the criteria we apply to decide whether a finding is a security vulnerability at all. Tier assignment is at Lightning Labs' discretion.

Scored across four dimensions Impact · Attack Vector · Exploitability · Virality
Supported Versions

Our Software Life Cycle policy states which LND release lines receive security fixes, when a line reaches end of life, and when the advisory for a fixed vulnerability is published. In short: the two most recent major release lines are maintained, and a line reaches end of life the day the second major release after it ships.

Past Security Advisories
Report a Vulnerability

If you believe you have found a security vulnerability in a Lightning Labs product, please email us. Include a description of the issue, the affected product and version, and steps to reproduce if available. The PGP key below can be used to communicate sensitive information. Please do not report security vulnerabilities through public GitHub issues.

Email security@lightning.engineering