<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Payment-Channel — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/payment-channel/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 31 Mar 2026 15:21:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/payment-channel/feed.xml" rel="self" type="application/rss+xml"/><item><title>MPPX TypeScript Interface Vulnerability (CVE-2026-34209)</title><link>https://feed.craftedsignal.io/briefs/2026-07-mppx-vuln/</link><pubDate>Tue, 31 Mar 2026 15:21:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-mppx-vuln/</guid><description>A vulnerability exists in mppx TypeScript interface before version 0.4.11, allowing attackers to close or grief channels for free by submitting close vouchers equal to the settled amount due to incorrect validation.</description><content:encoded><![CDATA[<p>The mppx library is a TypeScript interface designed for machine payments protocols. A vulnerability, identified as CVE-2026-34209, exists in versions prior to 0.4.11. Specifically, the <code>tempo/session</code> cooperative close handler incorrectly validates close voucher amounts. Instead of using a less than or equal to (<code>&lt;=</code>) comparison, it uses a less than (<code>&lt;</code>) comparison when checking against the on-chain settled amount. This flaw allows a malicious actor to submit a close voucher with an amount…</p>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>payment-channel</category><category>typescript</category></item></channel></rss>