Lightning Development Kit (LDK) has patched a flaw that could let a malicious channel peer steal a forwarded payment's value by lying after reconnecting. The October 1-dated v0.2.7 and v0.1.13 security releases fix the vulnerability on the 0.2 and 0.1 branches, respectively. Version 0.2.7 also fixes a separate potential theft involving LSPS2 just-in-time payments. Developers must incorporate patched code into deployed applications and account for LSPS2 payment contracts queued by a prior version that retain unvalidated amounts.