The Exploited Bug in LNbank
A Portuguese Bitcoin investor, Hugo Ramos, recently fell victim to a bug exploit that resulted in the loss of 4.07 BTC (equivalent to $164,500). The bug was found within a Lightning Network plugin called LNbank. Ramos, who lost almost his entire holdings, has started a crowdfunding campaign to recover his family’s savings.
“On December 6th, I woke up and realized that most of my LN node balance had been stolen. (…) At this point (about 20 minutes after waking up), 407,361,805 SATS (4.07 BTC) had been drained. I decided to shut down the node.”
— Hugo Ramos
The LNBank Bug and Reimann’s Response
LNBank is a Lightning Network plugin developed by Dennis Reimann at BTCPay Server. Reimann acknowledged the bug on NOSTR two days after Ramos’ incident and recommended updating to LNBank v1.8.9 to address the vulnerability.
“I’ve been notified of a critical vulnerability in the LNBank plugin! I recommend all instances running LNBank to update immediately to LNBank v1.8.9 to mitigate this critical vulnerability.”
— Dennis Reimann
Ramos reached out to Reimann, expressing his frustration over the late notification and requesting assistance: “Thanks for the late ‘heads up’. On past Wednesday, 4BTC were stolen from my LN node because of the LNbank bug. Any chance you can help me in any way? I lost almost all my life savings.”
Who is Hugo Ramos?
Hugo Ramos, residing in El Salvador, is a controversial figure within the local Bitcoin community. He identifies as a “toxic maximalist” and has faced accusations of expressing hate. Ramos sought support from various entities affected by the bug, including LNBank developers, the Czech exchange Anycoin, and Bitlifi wallet. He claims that some of the stolen Bitcoins were sent to these wallets.
“If KYC is not about preventing cases like this or punishing criminals, then what is it for?”
— Hugo Ramos
However, another commentator criticized Ramos, stating that he was responsible for his own loss and should refrain from blaming others. The Lightning Network remains an experimental project designed to scale Bitcoin, so users should avoid storing significant amounts in such environments. It is also advisable not to install third-party applications on devices where wallets are stored.
Hot Take: Unlikely Recovery of Stolen Funds
Unfortunately, it is highly improbable that Hugo Ramos will be able to retrieve the stolen funds worth over $164,500 at present.