Lumen Loop
All news
Articlestellar.orgStellar Development Foundation11y ago

Removal of partial payments

Stellar Development Foundation removed a partial payments feature from the protocol after discovering it could cause fund loss if anchors weren't aware of the DeliveredAmount field requirement. The legacy feature has been eliminated and all known anchors were notified.

AnchorsSecurityPayments
Lumen Loop's take

The Stellar Development Foundation identified a security issue with a partial payments feature inherited from legacy Ripple code that allowed senders to transmit only a fraction of stated payment amounts. The vulnerability arose because anchors checking only the Amount field would miss the actual delivered amount in the DeliveredAmount field, potentially resulting in financial losses. SDF notified all known anchors on October 8 and subsequently removed the feature from the Stellar codebase due to its minimal protocol value and unnecessary complexity. The issue no longer exists on the Stellar network, and SDF is preparing updated integration documentation with community input.

Mentioned projects
1 project linked
S
Stellar Development FoundationInfrastructure & Services
Audited
InfrastructureCommunity

The Stellar Development Foundation (SDF) is a non-profit organization that supports the development and growth of the Stellar ne…

View →