Bitcoin Lightning Network application development library LDK (Lightning Development Kit) has released v0.2.7 and v0.1.13 security patches to fix a vulnerability that could allow a malicious channel peer to steal funds from forwarded payments by misrepresenting the state after reconnection. Version v0.2.7 also fixes a defect in LSPS2 payment amounts. Developers need to integrate the relevant patches into their deployed software.