ACINQ/eclair
58.0
Adequate · 27 September 2026
57.8k
lines of production code
Scala
primary language
3
measurements over time
What this system is
Eclair is a Bitcoin Lightning Network node implementation that manages off-chain payment channels, including opening, funding, splicing, and closing. It handles the routing of payments across the network, supporting modern features like blinded routes, Bolt 12 offers, and trampoline relaying. The system provides a REST API and CLI for operator control, backed by modular database storage and on-chain wallet integration for fee management and balance monitoring.
How it got here
2015–2017 — Core architecture modernization and BOLT 12 support
39 changes.
This period focused on a comprehensive architectural overhaul of Eclair, introducing a plugin-based node structure, a modular database abstraction with dual backend support, and typed domain models for type safety. The work also implemented modern Lightning Network standards, including BOLT 12 invoices, dual-funded channels, splicing, and blinded routes, while replacing legacy crypto and RPC components with hardened, efficient alternatives.
2018–2021 — Clustering, Tor, and Protocol Modernization
44 changes.
This period focused on modernizing the Lightning protocol implementation by introducing TLV-based wire formats, Blinded Paths, and Onion Messages, alongside significant architectural shifts like Tor support and a clustered frontend. Concurrently, the codebase underwent extensive refactoring of core subsystems—including payment relaying, key management, and on-chain transaction publishing—while establishing comprehensive test coverage and security hardening for the API and database layers.
2022–2026 — Bolt 12 and channel protocol modernization
24 changes.
This period focused on implementing core Lightning Network upgrades, including native Bolt 12 offer support with blinded path privacy and the interactive transaction protocol for dynamic channel funding and splicing. The work also introduced channel protocol version 5, outgoing HTLC reputation tracking, and per-peer profit scoring to optimize liquidity and routing reliability. These features were supported by extensive refactoring of the channel state machine and the addition of comprehensive integration, fuzz, and unit tests to ensure stability.
Features
AWS Elastic Beanstalk deployment support for Eclair Front
Eclair Front can now be deployed to AWS Elastic Beanstalk. This change introduces a Procfile, a startup script (run.sh), and a Logback configuration (logback\_eb.xml) tailored for the environment. The startup script retrieves the local IP using IMDSv2 and handles certificate setup, while the logging configuration filters out AWS ELB health-check noise and truncates long hexadecimal strings in log messages to improve readability.
eclair-front/modules/awseb · high confidence
Add bash autocompletion for eclair-cli
Users can now enable command-line autocompletion for the eclair-cli tool by installing the new bash completion script located in contrib/eclair-cli.bash-completion. The script provides tab-completion for available subcommands and options, improving the usability of the CLI interface.
contrib · high confidence
Initial default configuration for eclair-core
The \reference.conf\ file in \eclair-core/src/main/resources\ is introduced, establishing the default configuration values for the node. This includes settings for the data directory, network chain (defaulting to mainnet), server and API binding details, Bitcoin Core connection parameters (including authentication and ZMQ subscriptions), and a comprehensive list of Lightning Network feature flags (such as static remote key, payment secrets, and route blinding). It also defines default channel parameters like dust limits, HTLC constraints, funding timeouts, and exception handling strategies, providing the baseline configuration for node operators.
eclair-core/src/main/resources · high confidence
Initial implementation of Tor onion service support
Eclair now includes core components to connect to and operate as a Tor hidden service. This change introduces a Tor controller actor to manage the connection to the Tor control port, a SOCKS5 proxy client for routing traffic, and a protocol handler that supports both password and safecookie authentication methods to create and manage onion services.
eclair-core/src/main/scala/fr/acinq/eclair/tor · high confidence
Initial repository structure and build documentation
This change introduces the foundational project files for Eclair, including a new Dockerfile for containerized builds, build instructions in BUILD.md, and contributor guidelines in CONTRIBUTING.md. It also adds standard repository metadata such as .gitignore, .dockerignore, LICENSE, SECURITY.md, and CLAUDE.md, alongside the Maven wrapper scripts (mvnw, mvnw.cmd) and a codecov configuration file.
(repo-wide) · high confidence
Introduce FrontRouter for distributed gossip handling
Added a new FrontRouter actor that acts as a front-end for the main router, enabling the distribution of connection-handling across multiple machines in an Akka cluster. This component manages the synchronization of routing state from a remote master router, deduplicates incoming gossip announcements to prevent redundant processing, and handles the forwarding of peer routing messages and periodic rebroadcasts, thereby supporting a clustered architecture for improved scalability and resource usage.
eclair-front/src/main/scala/fr/acinq/eclair/router · high confidence
Introduce blockchain watchdog to detect network eclipsing
Eclair now monitors secondary blockchain sources (Blockcypher, Blockstream, MempoolSpace, and bitcoinheaders.net) to detect when it is falling behind the rest of the network, which may indicate an eclipse attack. The new BlockchainWatchdog component periodically queries these external APIs and DNS-based headers, compares the received block heights against the local node, and publishes a warning to the node operator if the skew exceeds a configurable threshold. This feature adds visibility into potential network isolation issues without altering core transaction processing.
eclair-core/src/main/scala/fr/acinq/eclair/blockchain/watchdogs · high confidence
Introduce clustered frontend architecture with TLS-secured cluster communication
The eclair-front module now supports running as a clustered frontend node that distributes connection handling across multiple machines. This change introduces a new boot process (Boot.scala) that initializes an Akka cluster, enforces TLS-TCP transport for secure inter-node communication, and integrates with AWS Secrets Manager or environment variables for node key management. A new ClusterListener monitors cluster membership to detect backend nodes and handle failures, while FrontSetup orchestrates the bootstrap sequence by connecting to a remote backend's switchboard and router actors, establishing a client spawner and server instance within the cluster context.
eclair-front/src/main/scala/fr/acinq/eclair · high confidence
Introduce eclair-front with cluster-aware configuration and logging
This change adds the configuration and startup resources for the new eclair-front component. The application.conf sets up Akka Cluster roles (frontend), defines backend connection settings via environment variables, and configures Kamon with disabled automatic span generation. The logback.xml introduces dedicated rolling log files for general activity and a separate notifications log for important operator alerts, while the eclair-front.sh script provides the JVM startup logic, including Cygwin path handling and Kanela agent integration.
eclair-front/src/main/resources · high confidence
Introduce periodic global balance monitoring and operator alerts
Eclair now includes a new background balance-checking system that periodically computes and reports the node's total on-chain and off-chain balance. This system tracks UTXO counts and balances by status (confirmed, unconfirmed, safe, unsafe) and breaks down off-chain balances by channel state (normal, closing, etc.). It also calculates the difference from the previous balance check to help operators track fund movements. Crucially, if the confirmed on-chain balance falls below an estimated fee-bumping reserve (calculated based on the number of channels), the system publishes a warning notification to the node operator, advising them to add more UTXOs to ensure funds safety in case of force-closes.
eclair-core/src/main/scala/fr/acinq/eclair/balance · high confidence
Introduces per-peer profit scoring and automated liquidity management
Eclair now includes a new peer scoring system that tracks routing profit and volume per peer to optimize channel management. The system monitors daily and weekly profit and volume metrics via Kamon gauges, aggregates payment and channel events into time-bucketed statistics, and uses this data to automatically fund channels with high-performing peers or reclaim liquidity from idle ones. Operators can configure thresholds for auto-funding, auto-closing, and relay fee adjustments to tailor the node's behavior based on profitability.
eclair-core/src/main/scala/fr/acinq/eclair/profit · high confidence
Introduction of interactive transaction protocol for channel funding and splicing
Eclair now implements the interactive-tx protocol, allowing two participants to collaboratively build and sign a shared transaction in a turn-based manner. This new capability enables on-the-fly channel funding, dynamic channel splicing (adding or removing liquidity from an existing channel), and Replace-By-Fee (RBF) for these transactions. The implementation includes dedicated actors for building the transaction structure and funding contributions, supporting both legacy and taproot commitment formats, and integrating with liquidity ads for fee payment.
eclair-core/src/main/scala/fr/acinq/eclair/channel/fund · high confidence
Introduction of outgoing HTLC reputation tracking
The system now tracks the reliability of outgoing payments to remote nodes by recording the success rate and latency of HTLCs. This reputation data is used to calculate an 'outgoing confidence' score, which can influence routing decisions and channel occupancy checks to avoid sending payments to unreliable peers.
eclair-core/src/main/scala/fr/acinq/eclair/reputation · high confidence
Introduction of plugin support and modular node startup
Eclair now supports a plugin architecture, allowing users to extend node functionality by loading custom JAR files at startup. The new \Boot.scala\ entry point manages the plugin lifecycle, invoking \onSetup\ and \onKit\ hooks, while \Plugin.scala\ defines the interfaces for general plugins and \RouteProvider\ plugins that can inject custom routes into the JSON-RPC API. This change also introduces a safer startup process that requires an explicit \eclair.allow-unsafe-startup\ flag to bypass safety checks, and ensures the API service is only started if enabled in the configuration.
eclair-node/src/main/scala/fr/acinq/eclair · high confidence
Introduction of the eclair-cli command-line tool
A new bash-based command-line client (\eclair-cli\) is introduced to interact with the Eclair node's REST API. This tool allows users to execute node commands such as managing channels, invoices, payments, and on-chain transactions via the command line. It supports features like short-channel ID display, password authentication, and custom API endpoint configuration, requiring \curl\ and \jq\ as dependencies.
eclair-core · high confidence
Native Bolt 12 offer support with blinded path privacy
Eclair now includes built-in support for managing and creating Bolt 12 offers without requiring external plugins. The new OfferManager, DefaultOfferHandler, and OfferCreator actors enable users to create offers that utilize blinded payment paths for enhanced privacy. When creating an offer with a blinded path, the system automatically routes through intermediate nodes and pads the path to a configured length to prevent graph analysis. For receiving payments, the system generates invoices with hidden routing fees, allowing the recipient to optionally absorb part of the path costs to improve payer experience while maintaining privacy. This feature integrates directly with the existing router and payment infrastructure.
eclair-core/src/main/scala/fr/acinq/eclair/payment/offer · high confidence
New API parameter extraction and JSON serialization infrastructure
The API layer now includes dedicated form parameter extractors and JSON support to handle a broader range of input types. This adds unmarshalling capabilities for Bitcoin and Lightning primitives such as Bolt11 invoices, short channel IDs, blinded routes, and offers, alongside standard types like timestamps, fees, and public keys. This infrastructure enables the API to accept these specific data formats in requests, supporting features like route finding with specific channel IDs and offer payments.
eclair-node/src/main/scala/fr/acinq/eclair/api/serde · high confidence
New ZMQActor implementation for Bitcoin node communication
A new ZMQActor class has been introduced in the eclair-core module to handle communication with Bitcoin nodes via ZeroMQ. This actor manages the ZMQ socket lifecycle, including TCP keep-alive settings and high watermark configuration to prevent message dropping. It subscribes to specific topics (hashblock and rawtx) to receive new block and transaction events, publishing these as domain events (NewBlock, NewTransaction) to the system event stream. The implementation also monitors connection status, publishing ZMQConnected and ZMQDisconnected events, and uses a scheduled non-blocking check loop to process incoming messages and events.
eclair-core/src/main/scala/fr/acinq/eclair/blockchain/bitcoind/zmq · high confidence
New channel configuration and state management structures
The channel subsystem introduces a new \ChannelConfig\ trait and case class to manage internal channel options, such as \FundingPubKeyBasedChannelKeyPath\, which allows deterministic key derivation from the funding public key for easier fund recovery. This configuration is now explicitly passed through channel initialization data (\INPUT\_INIT\_CHANNEL\_INITIATOR\ and \INPUT\_INIT\_CHANNEL\_NON\_INITIATOR\) and enforced during channel setup. Additionally, the channel state machine and data model have been expanded to support dual-funded channels and splicing, introducing new states like \WAIT\_FOR\_DUAL\FUNDING\\*\ and events like \ChannelFundingCreated\ and \ChannelLiquidityPurchased\ to track the lifecycle of these advanced funding flows.
eclair-core/src/main/scala/fr/acinq/eclair/channel · high confidence
New database abstraction layer with dual backend support
Eclair introduces a new, unified database layer that abstracts storage behind trait-based interfaces (AuditDb, ChannelsDb, NetworkDb, PaymentsDb, PeersDb, OffersDb, LiquidityDb, PendingCommandsDb) and provides concrete implementations for both SQLite and PostgreSQL backends. This change enables users to choose their preferred database engine, with PostgreSQL offering additional features such as schema-based isolation, read-only user grants, and exclusive lease locking for high-availability setups. The new architecture also includes a scheduled file backup handler for SQLite, automated cleanup for revoked HTLC info and stale peer storage, and comprehensive metrics tracking for database operations and backup durations.
eclair-core/src/main/scala/fr/acinq/eclair/db · high confidence
New payment send components for blinded routes, offers, and network probing
This change introduces several new actors and utilities in the payment send module to support advanced payment features. The new \Autoprobe\ actor periodically sends probe payments to random nodes to test channel connectivity and improve routing data. \BlindedPathsResolver\ handles the resolution of blinded paths for Bolt 12 invoices, including unwrapping routes that start at the local node. \OfferPayment\ manages the payment flow for Bolt 12 offers, including sending invoice requests via onion messages and resolving blinded paths. \MultiPartPaymentLifecycle\ and \PaymentLifecycle\ are updated to support these new payment types, with \PaymentInitiator\ coordinating the dispatch to the appropriate lifecycle actor based on the invoice type and features.
eclair-core/src/main/scala/fr/acinq/eclair/payment/send · high confidence
Support for Bolt 12 invoices and offers
Eclair now supports the new Bolt 12 invoice standard, allowing users to receive payments via interactive offers. This change introduces new data models for Bolt 12 invoices (\Bolt12Invoice\, \MinimalBolt12Invoice\) and a unified \Invoice\ trait that automatically dispatches parsing to either Bolt 11 or Bolt 12 formats based on the invoice prefix. The implementation includes support for blinded payment paths within Bolt 12 invoices and updates the payment event system to handle these new invoice types.
eclair-core/src/main/scala/fr/acinq/eclair/payment · high confidence
Support for sending and relaying onion messages
Users can now send and receive onion messages, a new feature allowing encrypted, relayed communication between nodes. This change introduces the \OnionMessages\ module for building and processing encrypted onion packets with support for blinded paths and intermediate nodes, and the \Postman\ actor to manage message sending, routing strategies (direct, explicit route, or auto-discovered), and reply handling. The implementation includes configuration for relay policies, timeout handling, and integration with the offer system for invoice requests.
eclair-core/src/main/scala/fr/acinq/eclair/message · high confidence
Security
Maven dependency integrity verification enabled
The build process now automatically verifies the integrity of downloaded Maven dependencies using SHA-256 checksums. This change ensures that artifacts match their expected checksums before being used, enhancing supply chain security by preventing the use of tampered or corrupted dependencies.
.mvn · high confidence
Maven dependency integrity verification via SHA-256 checksums
The build system now verifies the integrity of downloaded Maven dependencies by storing and checking SHA-256 checksums for artifacts and their POMs in \.mvn/checksums/checksums-central.sha256\. This change ensures that the local Maven cache contains unmodified artifacts, protecting the build against supply-chain tampering or corrupted downloads.
.mvn/checksums · high confidence
Architecture
Introduce modular on-chain wallet and blockchain event abstractions
The \eclair-core\ blockchain package now exposes a structured set of Scala traits and events to decouple wallet operations and blockchain monitoring from the rest of the system. \BlockchainEvents\ defines the core event types (\NewBlock\, \NewTransaction\, \CurrentBlockHeight\, \CurrentFeerates\) that the node emits, while \OnChainWallet\ consolidates wallet capabilities into distinct traits (\OnChainChannelFunder\, \OnChainAddressGenerator\, \OnChainBalanceChecker\) for funding transactions, generating addresses, and checking balances. Additionally, \Monitoring\ introduces Kamon metrics to track RPC performance, fee rates, and watcher activity, providing users with observability into on-chain interactions.
eclair-core/src/main/scala/fr/acinq/eclair/blockchain · high confidence
Refactored API handlers into modular traits
The API endpoint definitions have been reorganized from a single monolithic handler into distinct, modular traits (Channel, Control, Fees, Invoice, Message, Node, Offer, OnChain, PathFinding, Payment, and WebSocket). This change improves code maintainability and separation of concerns by grouping related RPCs—such as channel lifecycle management, payment routing, and invoice handling—into their own dedicated files without altering the external API surface.
eclair-node/src/main/scala/fr/acinq/eclair/api/handlers · high confidence
Refactored channel state machine into modular traits
The channel lifecycle logic has been restructured from a single monolithic file into a set of specialized traits (Channel, ChannelOpenDualFunded, ChannelOpenSingleFunded, CommonFundingHandlers, CommonHandlers, DualFundingHandlers). This change separates the core channel logic, single-funding flow, dual-funding flow, and common utilities into distinct modules, improving code organization and maintainability without altering the external protocol behavior.
eclair-core/src/main/scala/fr/acinq/eclair/channel/fsm · high confidence
Behavioural changes
API security hardening and directive refactoring
The API directives have been refactored into a modular structure (AuthDirective, OriginDirective, DefaultHeaders, etc.) to enforce stricter security and consistency. Browser access is now explicitly rejected via the OriginDirective to prevent CSRF attacks, and default HTTP headers are set to prevent caching. Authentication is handled via basic auth with a delay to deter brute-force attempts. Additionally, the findRoute\* API endpoints now support a 'shortChannelId' output format, allowing users to request routes formatted with short channel IDs instead of the default node IDs.
eclair-node/src/main/scala/fr/acinq/eclair/api/directives · high confidence
API service consolidated into eclair-node with plugin extensibility
The Eclair HTTP API implementation has been moved to the eclair-node subproject, consolidating the service definition into a single \Service.scala\ trait. This change introduces a unified entry point for all API routes (Node, Control, Channel, Fees, PathFinding, Invoice, Offer, Payment, Message, OnChain, and WebSocket) and adds support for external plugins to inject custom routes via the \extraRouteProviders\ parameter.
eclair-node/src/main/scala/fr/acinq/eclair/api · high confidence
Enforced migration path for Eclair versions prior to v0.13.1
The JDBC database layer now strictly validates the database schema version before allowing the node to start. If the detected database version is older than v0.13.0 or v0.13.1, the application will refuse to launch and instruct the operator to upgrade to those specific legacy versions first to perform required channel data and closed-channel migrations. This prevents data corruption or startup failures when upgrading from very old Eclair releases.
eclair-core/src/main/scala/fr/acinq/eclair/db/jdbc · high confidence
Introduces Bouncy Castle-based cryptographic primitives and hardened random number generation
The crypto package now implements core cryptographic functions (ChaCha20-Poly1305, HMAC-SHA256, Noise protocol handshake, Sphinx onion routing, and SHA-chain) using the Bouncy Castle library instead of the previous Java standard or Spongycastle implementations. Additionally, a new \StrongRandom\ generator is introduced, which combines the OS \SecureRandom\ with a custom \WeakRandom\ entropy pool to protect against catastrophic failures in the system's primary random number generator.
eclair-core/src/main/scala/fr/acinq/eclair/crypto · high confidence
Introduction of typed domain models for block height, CLTV expiry, and amounts
Eclair now uses dedicated, strongly-typed case classes for core Lightning Network concepts instead of raw numeric types. \BlockHeight\ wraps the block number, \CltvExpiry\ and \CltvExpiryDelta\ handle absolute and relative expiry times, and \MilliSatoshi\ manages payment amounts. This change prevents accidental mixing of these values and ensures that operations like fee calculations and expiry checks are type-safe, reducing the risk of logic errors in routing and channel management.
eclair-core/src/main/scala/fr/acinq/eclair · high confidence
New Bitcoin Core RPC client with cookie authentication and request batching
The Bitcoin Core RPC communication layer has been replaced with a new implementation that supports cookie-based authentication (reading credentials from a file path) in addition to standard user/password auth, and introduces a batching client that groups up to 50 JSON-RPC requests into a single HTTP call to reduce latency and overhead.
eclair-core/src/main/scala/fr/acinq/eclair/blockchain/bitcoind/rpc · high confidence
New channel codec and type definitions for version 5 protocol
This change introduces the serialization logic and data structures for the new channel protocol version 5. The new \ChannelCodecs5\ defines how channel parameters, funding inputs, and commitment states are encoded, explicitly supporting multiple commitment formats including zero-fee HTLC transactions and simple taproot channels, while rejecting legacy non-anchor channels. The accompanying \ChannelTypes5\ defines the \EncodedCommitments\ structure, which optimizes storage by deduplicating and separating the shared HTLC set from individual commitment records.
eclair-core/src/main/scala/fr/acinq/eclair/wire/internal/channel/version5 · high confidence
New default configuration and logging setup for eclair-node
The eclair-node distribution now ships with a new \application.conf\ that configures Akka for local actor provider mode by default (with cluster support available via extension), sets the Akka log level to DEBUG, and disables Kamon instrumentation and JDBC instrumentation by default. Additionally, \logback.xml\ is introduced to provide rolling file logging for general logs and a separate rolling file for important notifications, while \logback\_colors.xml\ adds colored console output for specific subsystems (Peer, Channel, Payment, etc.). The launcher scripts (\eclair-node.sh\ and \eclair-node.bat\) are updated to support these configurations and include a bundled JVM check for Java 21.
eclair-node/src/main/resources · high confidence
New fee provider architecture with configurable confirmation targets
The fee management system has been refactored to support a pluggable provider model and more granular control over on-chain transaction costs. A new \FeeProvider\ trait allows for different fee estimation strategies, including a \BitcoinCoreFeeProvider\ that retrieves the mempool minimum fee and smart fee estimates, a \FallbackFeeProvider\ that chains multiple providers with a configurable minimum feerate enforcement, a \ConstantFeeProvider\ for static rates, and a \SmoothFeeProvider\ that averages rates over a time window to reduce volatility. Configuration is now handled via \OnChainFeeConf\, which introduces \ConfirmationPriority\ (Slow, Medium, Fast) and \FeeTargets\ to explicitly map funding and closing transactions to specific confirmation speeds, replacing the previous implicit block-target logic.
eclair-core/src/main/scala/fr/acinq/eclair/blockchain/fee · high confidence
New internal serialization infrastructure for Eclair actors
The \eclair-core/src/main/scala/fr/acinq/eclair/remote\ package now includes three new serializer classes: \ScodecSerializer\, \LightningMessageSerializer\, and \EclairInternalsSerializer\. \ScodecSerializer\ provides a base implementation for serializing objects using scodec codecs, while \LightningMessageSerializer\ handles Lightning Network protocol messages. \EclairInternalsSerializer\ is a comprehensive serializer for internal Eclair types, including routing configurations (\PathFindingConf\, \RouterConf\), peer connection states (\PeerConnection.Conf\, \PeerConnection.Kill\), and network synchronization parameters. This change introduces a new mechanism for serializing internal actor messages and configuration states, replacing or supplementing previous serialization methods.
eclair-core/src/main/scala/fr/acinq/eclair/remote · high confidence
New on-chain address renewal logic and ZMQ watcher implementation
This change introduces a new OnChainAddressRefresher component that manages the renewal of on-chain receiving addresses for closed channels, implementing a rate-limiting mechanism to prevent address churn during mass force-closes. It also adds a new ZmqWatcher implementation that subscribes to Bitcoin Core ZMQ events for new blocks and transactions, handling watch triggers and block height validation to replace previous polling or RPC-based monitoring approaches.
eclair-core/src/main/scala/fr/acinq/eclair/blockchain/bitcoind · high confidence
New transaction and commitment specification models
The channel transaction logic has been refactored to support modern commitment formats, including anchor outputs and taproot channels. This introduces new data structures like \CommitmentSpec\ to track off-chain state and \CommitmentOutput\ variants (e.g., \ToLocalAnchor\, \InHtlc\) to represent specific on-chain outputs. The \Transactions\ module now defines distinct \CommitmentFormat\ traits (such as \AnchorOutputsCommitmentFormat\ and \SimpleTaprootChannelCommitmentFormat\) with precise weight constants for fee estimation, while \Scripts\ provides the corresponding witness scripts and logic for these new output types.
eclair-core/src/main/scala/fr/acinq/eclair/transactions · high confidence
PostgreSQL backend now uses dedicated schemas and JSONB columns for improved data organization
The Postgres database implementation has been restructured to use dedicated schemas (e.g., \audit\, \local\, \network\, \liquidity\, \payments\) for each database domain, replacing the previous flat table structure. Additionally, binary data columns are now accompanied by \JSONB\ counterparts, allowing for more efficient querying and indexing of structured data like channel metadata and network announcements. This change includes comprehensive migration logic to upgrade existing databases to the new schema versioning system.
eclair-core/src/main/scala/fr/acinq/eclair/db/pg · high confidence
Refactor channel relaying into dedicated actors
The payment relaying logic has been restructured into a new set of actors: ChannelRelayer, ChannelRelay, NodeRelayer, and NodeRelay. ChannelRelayer now manages the lifecycle of channel relays and selects outgoing channels, while ChannelRelay handles the actual forwarding of HTLCs to downstream channels. Similarly, NodeRelayer dispatches trampoline payments to NodeRelay actors, which aggregate incoming HTLCs and forward them using the router. This separation isolates the concerns of channel selection and node routing, improving modularity and maintainability of the relay system.
eclair-core/src/main/scala/fr/acinq/eclair/payment/relay · high confidence
Refactored JSON serialization architecture with dedicated type serializers
The JSON serialization layer has been restructured to use a new \JsonSerializers.scala\ file that implements a custom \ConvertClassSerializer\ pattern, allowing complex domain objects to be mapped to simple JSON-serializable case classes rather than manually constructing JSON AST nodes. This change introduces specific serializers for core types such as \TimestampSecond\, \TimestampMilli\, \ByteVector\, \TxId\, and \BlockHash\, ensuring consistent output formats (e.g., timestamps now include both ISO 8601 and Unix epoch representations) and preventing the serialization of internal actors like \ActorRef\.
eclair-core/src/main/scala/fr/acinq/eclair/json · high confidence
Refactored incoming payment handling with multi-part support and invoice purging
The incoming payment processing logic in the receive package has been restructured to support multi-part payments and automated invoice cleanup. A new PaymentHandler now orchestrates a chain of ReceiveHandlers, defaulting to a MultiPartHandler that manages concurrent HTLC parts via a MultiPartPaymentFSM, ensuring correct fulfillment or failure when all parts arrive. The system also introduces an InvoicePurger actor that periodically scans the database and removes expired incoming payments, configurable via a purge interval. Additionally, a simple ForwardHandler is provided to delegate messages to other actors, allowing for extensible handler composition.
eclair-core/src/main/scala/fr/acinq/eclair/payment/receive · high confidence
Refactored key management into segregated, specialized managers
The key management architecture has been restructured to separate concerns into distinct managers: \LocalNodeKeyManager\ for node identity, \LocalChannelKeyManager\ for deriving channel-specific keys, and \LocalOnChainKeyManager\ for on-chain wallet operations. This change introduces \ChannelKeys\ and \CommitmentKeys\ to handle the derivation and caching of funding, commitment, and per-commitment keys, while \LocalOnChainKeyManager\ now supports generating BIP84 (P2WPKH) and BIP86 (Taproot) descriptors for integration with Bitcoin Core.
eclair-core/src/main/scala/fr/acinq/eclair/crypto/keymanager · high confidence
Refactored on-chain transaction publishing into specialized actors
The transaction publishing logic in the channel has been restructured into a set of dedicated actors to improve modularity and reliability. The new architecture introduces \FinalTxPublisher\ for publishing pre-signed transactions, \ReplaceableTxPublisher\ for managing fee-bumpable transactions (RBF), \ReplaceableTxFunder\ for handling wallet input selection and fee calculation, \ReplaceableTxPrePublisher\ for validating preconditions before publication, and \MempoolTxMonitor\ for tracking confirmation status and handling mempool evictions. This change replaces the previous monolithic publishing flow with a coordinated pipeline that better handles conflicting transactions, input status checks, and dynamic fee adjustments during force-closes.
eclair-core/src/main/scala/fr/acinq/eclair/channel/publish · high confidence
Refactored peer connection management with dedicated Client and ClientSpawner actors
The peer connection logic in the \io\ package has been restructured to separate connection initiation from peer lifecycle management. A new \Client\ actor now handles the low-level TCP/Tor socket establishment and SOCKS5 proxy negotiation, while a \ClientSpawner\ actor manages the creation of these clients and integrates with Akka Cluster Distributed PubSub to coordinate outgoing connections across cluster nodes. This change isolates the network transport details from the \Peer\ actor, which now focuses on logical peer state and channel management, and introduces \IncomingConnectionsTracker\ to limit connections from peers without established channels.
eclair-core/src/main/scala/fr/acinq/eclair/io · high confidence
Removal of legacy channel data codecs (v0–v3) and enforcement of v0.13.0 migration
The internal channel data storage format has been updated to remove support for legacy codec versions 0 through 3. The \ChannelCodecs\ class now only recognizes version 5 for new data and explicitly fails with a specific error message for any data encoded with versions 0–4. This change enforces that users must have already migrated their channel data using the v0.13.0 release before upgrading to this version; attempting to load older channel data will now result in a failure rather than a silent or partial migration.
eclair-core/src/main/scala/fr/acinq/eclair/wire/internal/channel · high confidence
Router refactored into modular components with blinded route support
The router package has been restructured into distinct modules to improve maintainability and enable new capabilities. Core announcement logic is now in Announcements.scala, while Graph.scala introduces a new weighted path-finding model that incorporates success probabilities and balance estimates for more reliable route selection. BlindedRouteCreation.scala adds support for creating and aggregating fees for blinded payment routes, and RouteCalculation.scala centralizes the route request handling logic. Monitoring.scala provides new Kamon metrics for tracking path-finding performance and gossip sync progress.
eclair-core/src/main/scala/fr/acinq/eclair/router · high confidence
SQLite database schema modernization and new liquidity tracking
The SQLite backend has been updated with a comprehensive schema migration (up to version 11 in the audit database) that switches identifier columns from BLOBs to TEXT for better compatibility and adds detailed fields for channel events, transactions, and payments (including mining fees, liquidity ads, and trampoline relay data). A new dedicated SQLite database for liquidity purchases and on-the-fly funding has been introduced to track liquidity ads and splicing transactions, and a new offers database has been added to support Bolt 12 offer management.
eclair-core/src/main/scala/fr/acinq/eclair/db/sqlite · high confidence
Updated HTLC command codecs to support attribution and fulfillment payloads
The internal command codecs for HTLC settlement commands (CMD\_FAIL\_HTLC and CMD\_FULFILL\_HTLC) have been refactored to support new protocol features. Specifically, the codecs now handle downstream attribution data for failures and fulfillments, as well as optional fulfillment payloads in fulfillment commands. This change ensures compatibility with updated Lightning Network specifications regarding route blinding and failure attribution, allowing the node to correctly serialize and deserialize these new command structures.
eclair-core/src/main/scala/fr/acinq/eclair/wire/internal · high confidence
Wire protocol refactoring to TLV-based channel and HTLC messages
The wire protocol for channel management and HTLCs has been refactored to use the TLV (Type-Length-Value) extension mechanism. This change introduces dedicated codec files (ChannelTlv, HtlcTlv, InteractiveTxTlv) and updates message types (OpenChannel, UpdateAddHtlc, etc.) to carry extensible TLV streams. This enables support for new features such as upfront shutdown scripts, require\_confirmed\_inputs, splice transactions, and accountable HTLCs without breaking compatibility with existing message structures.
eclair-core/src/main/scala/fr/acinq/eclair/wire/protocol · high confidence
Test coverage
Add test configuration for JVM shutdown and cluster settings; Added API response fixtures for channel balances, routing, and payment status; Added Bitcoin Core integration test configuration; Added Java test and utility files for MilliSatoshi and Curve25519; Added comprehensive test coverage for channel configuration, features, and commitment logic; Added comprehensive test suite for the Shutdown channel state; Added comprehensive test suite for the router module; Added comprehensive test suites for payment relay components; Added database test suites for audit, channels, liquidity, network, offers, payments, and peers; Added fuzz testing infrastructure for Lightning message codecs; Added integration test for gossip propagation after channel splicing; Added integration tests for offer-based and trampoline payments; Added integration tests for two- and three-node channel scenarios; Added integration tests for zero-conf channel activation and alias routing; Added non-regression test fixtures for channel state serialization; Added regression tests for channel codec backward compatibility; Added test configuration and BOLT 3 anchor output test vectors; Added test coverage for new IO subsystem components; Added test coverage for payment protocol and lifecycle components; Added test fixtures for multi-node integration scenarios; Added test infrastructure for blockchain wallet and watcher logic; Added test suite for bitcoind RPC client components; Added tests for ChaCha20-Poly1305 encryption; Added tests for FrontRouter gossip handling and aggregation; Added tests for HTLC command codec serialization; Added tests for JSON serialization of core Lightning types; Added tests for Tor proxy configuration and protocol handling; Added tests for blinded path resolution and offer payment flows; Added tests for blockchain watchdog sources and DNS header fetching; Added tests for channel balance computation and listener behavior; Added tests for channel closing negotiation logic; Added tests for channel closing state transitions; Added tests for channel codec serialization and deserialization; Added tests for channel funding and ready states; Added tests for channel opening and dual funding state machines; Added tests for dual funding and channel open state machines; Added tests for onion message routing and postman relay logic; Added tests for reputation scoring and recorder behavior; Added tests for the invoice purger component; Added tests for the new key manager architecture; Added tests for the new on-chain transaction publishing components; Added unit tests for commitment spec logic and transaction generation; Added unit tests for fee provider components; Added unit tests for the OfferManager actor; Added unit tests for the new peer profit scoring system; Expanded test coverage for Lightning protocol codecs; Expanded test coverage for core Lightning Network types and API implementation; Initial test suite for the eclair-node HTTP API; New channel state machine tests for Normal, Offline, Quiescent, and Splice states; New integration test fixtures for basic node scenarios; New integration test suite for Lightning Network components; New test helper methods for channel state testing; New test utilities for logging isolation and fixture management.
Dependencies
Eclair 0.15.0-SNAPSHOT dependency and build configuration
This update establishes the Eclair 0.15.0-SNAPSHOT release baseline, upgrading the build to Java 21 and Scala 2.13.11. It integrates bitcoin-lib 0.49, Akka 2.6.20, and Akka HTTP 10.2.7, while adding Jazzer fuzz testing support via the new eclair-fuzz module. The configuration also updates the test bitcoind download to version 31.1 and sets the Kamon monitoring version to 2.7.4.
(dependencies) · high confidence
Updated Maven Wrapper to version 3.3.2 with Maven 3.9.9
The Maven Wrapper configuration has been updated to use wrapper version 3.3.2 and Maven distribution 3.9.9. This ensures that builds are executed with a consistent, specific version of the build tool, aligning with the project's shift to Java 21.
.mvn/wrapper · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 48 → 58 (+10.0)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 86 (-14.5)
- Architecture 94 → 97 (+3.1)
- Maturity 59 → 61 (+2.2)
- Readiness 26 → 45 (+18.7)
- Security 59 → 69 (+9.4)
Resolved (26)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 6 more
New (283)
- BalanceActor.apply (cognitive 18) (eclair-core/src/main/scala/fr/acinq/eclair/balance/BalanceActor.scala)
- BitcoinCoreClient.cpfp (cognitive 23) (eclair-core/src/main/scala/fr/acinq/eclair/blockchain/bitcoind/rpc/BitcoinCoreClient.scala)
- BitcoinCoreClient.signPsbt (cognitive 19) (eclair-core/src/main/scala/fr/acinq/eclair/blockchain/bitcoind/rpc/BitcoinCoreClient.scala)
- BitcoinCoreClient.validate (cognitive 22) (eclair-core/src/main/scala/fr/acinq/eclair/blockchain/bitcoind/rpc/BitcoinCoreClient.scala)
- BitcoinCoreFeeProvider.getFeerates (cognitive 50) (eclair-core/src/main/scala/fr/acinq/eclair/blockchain/fee/BitcoinCoreFeeProvider.scala)
- BlindedPathsResolver.resolveBlindedPaths (cognitive 16) (eclair-core/src/main/scala/fr/acinq/eclair/payment/send/BlindedPathsResolver.scala)
- Boundary-crossing change coupling: Eclair.scala ↔ Channel.scala (eclair-core/src/main/scala/fr/acinq/eclair/Eclair.scala)
- Boundary-crossing change coupling: Eclair.scala ↔ FormParamExtractors.scala (eclair-core/src/main/scala/fr/acinq/eclair/Eclair.scala)
- Change coupling: Channel.scala ↔ Scripts.scala (eclair-core/src/main/scala/fr/acinq/eclair/channel/fsm/Channel.scala)
- Change coupling: ChannelOpenDualFunded.scala ↔ ChannelOpenSingleFunded.scala (eclair-core/src/main/scala/fr/acinq/eclair/channel/fsm/ChannelOpenDualFunded.scala)
- Change coupling: Commitments.scala ↔ ChannelKeyManager.scala (eclair-core/src/main/scala/fr/acinq/eclair/channel/Commitments.scala)
- Change coupling: Helpers.scala ↔ ChannelKeyManager.scala (eclair-core/src/main/scala/fr/acinq/eclair/channel/Helpers.scala)
- Change coupling: InteractiveTxBuilder.scala ↔ ChannelTlv.scala (eclair-core/src/main/scala/fr/acinq/eclair/channel/fund/InteractiveTxBuilder.scala)
- Change coupling: OnChainFeeConf.scala ↔ Channel.scala (eclair-core/src/main/scala/fr/acinq/eclair/blockchain/fee/OnChainFeeConf.scala)
- Change coupling: PgChannelsDb.scala ↔ SqliteChannelsDb.scala (eclair-core/src/main/scala/fr/acinq/eclair/db/pg/PgChannelsDb.scala)
- Channel.handleNewBlock (cognitive 22) (eclair-core/src/main/scala/fr/acinq/eclair/channel/fsm/Channel.scala)
- Channel.resumeSpliceSigningSessionIfNeeded (cognitive 28) (eclair-core/src/main/scala/fr/acinq/eclair/channel/fsm/Channel.scala)
- ClassTooLong: EclairImpl (eclair-core/src/main/scala/fr/acinq/eclair/Eclair.scala)
- Commitment.canSendAdd (cognitive 18) (eclair-core/src/main/scala/fr/acinq/eclair/channel/Commitments.scala)
- Coverage not measured — no coverage collector is wired up
- …and 263 more
Changes since last survey
- 37 commits — 29 feature/other, 8 fixes
By area
- eclair-core/src — 27 commits
- (root) — 7 commits
- .mvn/checksums — 1 commit
- eclair-front/modules — 1 commit
- eclair-node/src — 1 commit
Notable commits
- fix: (Minor) Fix flaky test in WaitForAcceptChannelStateSpec (#3364)
- fix: Fix a batch of Tor-related issues (#3354)
- fix: Fix a batch of low-severity issues (#3355)
- fix: Fix flaky tests caused by port allocation race (#3384)
- fix: Fix several on-the-fly-funding bugs (#3351)
- fix: Gossip queries fixes and improvements (#3345)
- fix: More AI fixes and defense-in-depth (#3376)
- fix: Multiple bug fixes found by AI scanning (#3346)
- change: (Minor) Update claude gitignore files (#3363)
- change: Add more checks around funding amount and channel reserve (#3352)
- change: Add optional rate-limit on incoming pre-auth connections (#3356)
- change: Add support for option_onion_messages_only_channels (#3342)
- change: Add support for fulfillment payload (#3321)
- change: Back to dev (#3371)
- change: Back to dev (#3379)
- change: Better documentation for remote bitcoind (#3359)
- change: Eclair v0.14.2 release (#3370)
- change: Eclair v0.14.3 release (#3377)
- change: Emit ChannelPersisted event at channel creation (#3361)
- change: Explicitly match on-the-fly HTLCs after a restart (#3357)
- …and 17 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ACINQ/eclair was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 972dfe995de0a24e8b496c6cf7144e7db377d51d — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.