What happened
Hydra released hydra-node 2.4.1 as a critical security update for GHSA-cg83-6w6r-6hx3. The issue affected versions 2.3.0 and 2.4.0 of the Layer 2 head software.
When confirming a snapshot, an optimized path re-applied requested transactions without signature verification or Plutus script evaluation. An unvalidated transaction could therefore reach a confirmed snapshot.
Why it matters
The release notes describe a scenario in which a malicious head participant could use an invalid signature or failing script to spend a co-participant’s funds. Hydra says every participant must sign a snapshot, so running an upgraded node restores full validation for that participant.
Version 2.4.1 removes the optimization and always fully validates transactions. It is described as a drop-in upgrade from 2.4.0.
Important limit
This concerns hydra-node and Hydra heads, not the Cardano base protocol. The supplied record does not say that funds were stolen, and it says the Hydra on-chain scripts, snapshot signature, and hydra.db format are unchanged.
Watch for confirmation that affected Hydra head participants have moved from 2.3.0 or 2.4.0 to 2.4.1.
Upstream references and independent checks
Digest dated 2026-09-03 · upstream model claude-sonnet-4-6. Direct links are matched to all 2 upstream source IDs.
This Research brief was generated by Terra from a dated upstream research digest. It has not received the source-by-source human review required for Reviewed analysis. Material limit: The evidence is limited to an official Hydra repository release record, with no independent media corroboration or reported thefts in the supplied material.
