0x0312a19f0312…0312a1a2

ConfirmedSecurity586 vB45 sat/vB3 min decode

Electrum 4.8.2 Patches Lightning Backup Flaw, but Old Files May Still Fail

Electrum 4.8.2 embeds missing Lightning payment keys in future backups, but older exports for anchor channels with non-deterministic keys still need replacing from retained wallet data.

Outputs

  1. Electrum 4.8.2, dated Sept. 11, fixes a Lightning backup defect affecting anchor channels with non-deterministic Lightning keys (PRs 10852 and 10851).

  2. Old backups lack the payment key needed to sweep anchor-channel outputs after a remote force-close; PR 10851 fixes exports that previously deleted a randomly generated Lightning private key.

  3. BIP39 and xprv-based wallets always have non-deterministic Lightning keys; Electrum-seed wallets are deterministic only if the wallet file was created in version 4.1 or later.

Electrum has shipped a security update that fixes a Lightning Network backup defect, but the patch does not rescue backups created before the fix. Users holding older exports tied to anchor channels and non-deterministic Lightning keys must regenerate them from retained wallet data.

The flaw affects two categories of backups: individual channel exports and exported full-wallet files. Older backups from wallets with non-deterministic Lightning keys lack the payment-key information needed to reclaim a user's balance from an anchor channel — a Lightning channel type that uses anchor outputs — after the remote peer force-closes the channel. Without that key material, the backup cannot sweep the output, meaning it cannot claim the coins on the Bitcoin blockchain.

Version 4.8.2, dated Sept. 11, remains the latest release listed on Electrum's official website as of Oct. 1. The individual-backup fix, merged in the project's GitHub repository under pull request 10852, embeds the payment-key data required to claim funds from an anchor channel closed by the counterparty. The same fix hides the option to request a remote force-close when a backup cannot sweep the resulting output, preventing users from triggering a close whose proceeds they could not recover.

A second patch, PR 10851, repairs wallet-file exports by retaining a randomly generated Lightning private key that the export process previously discarded. Maintainer SomberNight explains that re-enabling Lightning in such a backup would generate different keys, leaving its older channel-backup records insufficient to spend anchor-channel funds.

Electrum's release notes define two conditions that must both hold for a backup to be at risk. First, the wallet must have non-deterministic Lightning keys — keys that cannot be recreated from the wallet's seed. Second, the backup must concern an anchor channel. The warning covers both individual channel exports and full-wallet exports relevant to Lightning recovery.

The wallet type determines exposure. Lightning wallets based on BIP39 seeds or imported extended private keys (xprvs) always carry non-deterministic Lightning keys. Electrum-seed wallets differ: their Lightning keys are deterministic only when the wallet file was created in version 4.1 or later. Files created in 4.0.x do not qualify merely because the software has since been updated — the creation version of the file, not the installed client, is what matters.

The client surfaces the condition in its interface. On desktop, wallet information marks Lightning channels as non-recoverable from the seed. On Android, the channel-opening dialog warns that a channel cannot be recovered from the seed. Anchor-channel use remains the additional condition for the defect to bite.

The operational consequence is a manual remediation step. An upgrade changes the software that produces and reads backups, not the backups themselves. Electrum's documented remedy therefore requires fresh exports, and affected wallets display a startup warning prompting users to act. The replacement step depends on retaining the original wallet data needed to produce a new export; installing newer software does not guarantee recovery of key material already lost when that data was discarded.

For operators running Lightning nodes on Electrum with anchor channels, the practical deadline is immediate: any peer-initiated force-close against a stale backup would strand the channel balance until the missing key material is restored. Users who exported channel backups before version 4.8.2 and cannot locate their original wallet files face the narrowest recovery path, since no software update can reconstruct a randomly generated key that no longer exists anywhere.

via electrum.org (Original)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles