Lightning Labs disclosed a high-severity vulnerability affecting legacy versions of its Lightning Terminal suite. The defect could cause a payment that was cancelled on the network to be recorded as settled, potentially prompting merchants to release goods or credits without actually receiving funds.
How the error manifested
When a Lightning payment is sent, it travels as a hashed time-locked contract (HTLC). In the reported scenario, the HTLC was cancelled and the funds returned to the sender, yet the receiving node’s invoice database still marked the transaction as completed. Merchants relying on that status could unintentionally fulfill orders or issue refunds despite the payment never finalising.
Software components at fault
Two parts of the Lightning stack were implicated. First, the tapd module, which powers Taproot Assets, enabled an invoice interceptor that treated any HTLC carrying custom wire records as an asset payment. Certain sender implementations added an experimental endorsement record even for plain BTC transfers, triggering tapd’s strict-forwarding rule and causing lnd to cancel the HTLC set while the invoice remained marked as paid.
Second, a flaw in lnd itself meant that when an interceptor cancelled an HTLC set, the client cancelled the payment on the wire but failed to update the invoice’s settlement flag in its database. This mismatch could be reproduced by any client using lnd’s HtlcModifier interface that cancelled an HTLC set.
Patch history and current status
Lightning Labs rated the vulnerability as high severity because a false-paid status could lead operators or payment services to release value without a completed transaction. The advisory noted that the sender’s funds were not at risk.
- The tapd trigger was corrected in v0.5.1 on 12 February 2025.
- The underlying lnd accounting error was fixed in v0.19.0-beta on 22 May 2025.
- Lightning Terminal v0.15.0-alpha, released after the September 2026 advisory, bundles both fixes.
Earlier Terminal releases, up to taproot-assets v0.5.0 and lnd 0.18.4-beta through 0.18.5-beta, remain vulnerable. Operators who cannot upgrade immediately can mitigate the risk by launching the terminal with the flag --taproot-assets-mode=disable, which prevents the tapd trigger from activating.
Ongoing threats
The advisory also warned that malicious bots are actively scanning exposed Bitcoin payment servers in an attempt to steal master administrative keys, underscoring the importance of keeping software up-to-date and securing server access.
Why it matters
The Lightning Network is a critical layer-2 solution for scaling Bitcoin transactions, and many merchants rely on its fast, low-cost payments. An invoice-status discrepancy undermines trust in the system and could expose businesses to financial loss if goods are dispatched without payment. Prompt adoption of the patched Terminal version, or disabling the taproot-assets mode where upgrades are not feasible, is essential to preserve the integrity of Lightning-based commerce.




