Core Lightning warns attackers are targeting unpatched nodes

Core Lightning warned node operators on Friday that attackers are actively targeting installations running version 26.06.7 or earlier and advised upgrading to the latest release immediately. The team previously issued a security investigation and released patches in subsequent updates after reports of vulnerabilities that could affect funds and node stability.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 2 hours agoUpdated about 2 hours ago0 views
Core Lightning warns attackers are targeting unpatched nodes

Why It Matters

The Lightning Network relies on correctly patched node software to protect funds and maintain network stability; unpatched Core Lightning nodes may be exposed to crashes, memory-exhaustion vectors, or channel-closing bugs that have been described in the project's changelogs. A rapid, coordinated upgrade reduces the risk that attackers can exploit disclosed flaws while operators remain vulnerable.

Key Facts

  • Affected versions: Core Lightning versions 26.06.7 and earlier
  • Immediate action advised: Upgrade to the latest release as soon as possible
  • Investigation timeline: Core Lightning began investigating potential issues on Sept. 16 and released 26.06.8 about six days later
  • Patch contributors: Release notes credit the Bitcoin Red Team, 12 named individuals/groups, and anonymous reporters
  • Types of fixes: Patches addressed node crashes, REST memory exhaustion, and a channel-closing bug that could lead to penalty losses

The Core Lightning development team has issued an urgent security advisory telling operators running version 26.06.7 or earlier to upgrade immediately after reports emerged that attackers are actively targeting unpatched nodes. The team’s message, posted Friday, did not specify which precise vulnerabilities were being exploited or the full scope of potential impacts.

Earlier in September, Core Lightning said it was probing a potential issue tied to experimental features that might affect user funds. That inquiry led to the release of version 26.06.8 roughly six days after the initial investigation began. The Sept. 22 update bundled general bug fixes with patches for multiple vulnerabilities that had been responsibly disclosed.

The project’s changelog attributes contributions to the Bitcoin Red Team, a dozen named individuals and groups, and several anonymous reporters. Among the fixes listed were patches for conditions that could crash sender nodes, requests that could exhaust memory in the REST interface, and a channel-closing bug capable of triggering penalty losses for users.

To limit the risk of attackers reverse-engineering the fixes, the release intentionally withheld some tests so that exploit details would be harder to reconstruct while operators upgraded. The advisory follows earlier activity in August, when Core Lightning said it was coordinating a response after receiving a high volume of AI-generated CVE reports and later issued version 26.06.7 to address confirmed issues.

Cointelegraph reached out to Core Lightning for comment; the project’s public advisories and changelogs were the source of the timeline and technical details reported here.

Keep Reading