What happened

Hydra released hydra-node 2.4.1 as a critical security update for GHSA-cg83-6w6r-6hx3. The issue affected versions 2.3.0 and 2.4.0 of the Layer 2 head software.

When confirming a snapshot, an optimized path re-applied requested transactions without signature verification or Plutus script evaluation. An unvalidated transaction could therefore reach a confirmed snapshot.

Why it matters

The release notes describe a scenario in which a malicious head participant could use an invalid signature or failing script to spend a co-participant’s funds. Hydra says every participant must sign a snapshot, so running an upgraded node restores full validation for that participant.

Version 2.4.1 removes the optimization and always fully validates transactions. It is described as a drop-in upgrade from 2.4.0.

Important limit

This concerns hydra-node and Hydra heads, not the Cardano base protocol. The supplied record does not say that funds were stolen, and it says the Hydra on-chain scripts, snapshot signature, and hydra.db format are unchanged.

What to watch

Watch for confirmation that affected Hydra head participants have moved from 2.3.0 or 2.4.0 to 2.4.1.

Sources and limits

Upstream references and independent checks

Digest dated 2026-09-03 · upstream model claude-sonnet-4-6. Direct links are matched to all 2 upstream source IDs.

  1. 1
    2.4.1Direct upstream source · 5f8ac8e1159c765137d77d0e8235475b6ee5dad5
  2. 2
    2.4.1Direct upstream source · a9f97181b81a4ac7e2f93565c8908feb8e050969

This Research brief was generated by Terra from a dated upstream research digest. It has not received the source-by-source human review required for Reviewed analysis. Material limit: The evidence is limited to an official Hydra repository release record, with no independent media corroboration or reported thefts in the supplied material.