Electrum patches Lightning flaw, but old Bitcoin backups break
Electrum version 4.8.2 patches a critical Lightning backup vulnerability, but users with non-deterministic keys and anchor channels must generate new backups to ensure fund recovery.
A recent security update for Electrum resolves a flaw in Lightning backups, though certain Bitcoin wallet users must still generate and save new backups.
Legacy backups originating from wallets utilizing non-deterministic Lightning keys do not contain the data required to recover funds from anchor channels—a specific variety of Lightning channel—following a remote closure.
Released on Sept. 11, version 4.8.2 continues to serve as the most recent software version featured on Electrum’s official website as of Oct. 1.
This individual-backup patch introduces essential payment-key details required for users to retrieve their balances when a peer closes an anchor channel. Without this information, a compromised backup misses the specific key needed to sweep the output, preventing the user from claiming their coins on the Bitcoin blockchain.
Which wallets need attention?
According to Electrum’s release notes, two specific criteria must be met: the wallet must utilize non-deterministic Lightning keys, and the backup must involve an anchor channel.
Because non-deterministic keys cannot be derived from a wallet’s seed, this warning applies to both individual channel exports and full-wallet backups associated with Lightning recovery.
Lightning wallets dependent on BIP39 seeds or imported extended private keys (xprvs) consistently feature non-deterministic Lightning keys. Electrum-seed wallets operate differently; their Lightning keys are considered deterministic provided the wallet file was generated in version 4.1 or a later release. Files originally created in version 4.0.x do not qualify simply because the software has since been updated.
Within desktop interfaces, wallet details explicitly designate Lightning channels as unrecoverable via the seed, whereas the channel-opening dialog on Android issues a warning that the channel cannot be restored using the seed alone. The utilization of anchor channels serves as the remaining prerequisite for this backup vulnerability.
New Bitcoin proposal rescues locked multisig wallets – At a hidden cost
Furthermore, the individual-backup update removes the user interface option to trigger a remote force-close whenever the backup lacks the capability to sweep the resulting output. This limitation prevents a backup from initiating a channel close if it cannot successfully claim the associated output.
Pull Request 10851 fixes wallet-file exports by preserving a randomly generated Lightning private key that past export processes used to erase. Project maintainer SomberNight notes that reactivating Lightning on such a backup would result in the creation of new, different keys, rendering previous channel-backup records inadequate for spending funds stored in anchor channels.
Updating the software alters how backups are both generated and interpreted. Consequently, Electrum’s official guidance mandates creating fresh exports, and impacted wallets will prompt users with a startup warning.
Successfully replacing old files relies on preserving the foundational wallet data necessary to execute a new export. Simply installing the updated software does not ensure the retrieval of key material that was already lost alongside that data.
?Frequently Asked Questions
01What caused the Electrum backup issue?
Older backups from wallets utilizing non-deterministic Lightning keys lacked the specific payment-key information necessary to reclaim funds from anchor channels after a remote close.
02Which Electrum version contains the fix?
Version 4.8.2, released on Sept. 11, addresses the Lightning backup defect.
03Do all wallets require new backups?
No, only wallets meeting two conditions require action: they must use non-deterministic Lightning keys, and the backup must involve an anchor channel.
04How can I tell if my wallet is affected?
Desktop versions will mark Lightning channels as non-recoverable from the seed, while Android versions display a warning during the channel-opening dialog. Affected wallets will also show a startup warning after updating.



