Aug 7 - Jul 30, 2026
The researchers recalculated the maximum number of hops an OM can traverse to be 481, adjusting for a payload size increase per hop from 65 bytes to 68 bytes. The study introduces a novel mitigation strategy named "Soft Leash," which incorporates a proof-of-work (PoW) requirement that intensifies with each additional hop, thereby enhancing the computational effort needed to execute attacks. This approach mirrors defenses used in Tor, as discussed in Tor's blog post. Additionally, the paper suggests implementing rate limiting based on the total channel capacity of the receiving node to manage traffic flow effectively and deter DoS attacks. It also recommends routing protocols that prioritize paths according to the nodes' channel capacities, which would not only route through more capable nodes but also integrate higher rate limits, thus increasing the cost for potential attackers.
The document, however, lacks a foundational argument for the actual existence of DoS threats via onion messages and does not provide a formal analysis of these risks. It emphasizes the need to prevent routing loops—a major concern—but details about the actual vulnerabilities remain unexplored. Furthermore, it acknowledges that lightning developers have agreed on a "backpressure" strategy if these threats become more pronounced, indicating a proactive approach to potential vulnerabilities.
The ongoing discussion within the community, especially concerning the implementation of strategies like option_onion_messages_only_channels (see GitHub discussion), raises questions about the adoption rates of such options and their effectiveness. There is a noticeable curiosity about how many nodes currently support option_onion_messages and how this figure will evolve, particularly in comparison to newer strategies aimed at enhancing network security and functionality.
TLDR
We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.
We'd love to hear your feedback on this project.
Give Feedback