Key Takeaways
- Core Lightning says attackers are targeting nodes on version 26.06.7 or earlier.
- Version 26.06.8 landed Sept. 22 with fixes for vulnerabilities that can threaten funds.
- Operators face no confirmed loss tally as Core Lightning pushes immediate upgrades.
Core Lightning Sounds Alarm as Attackers Target Unpatched Nodes
Core Lightning has a fairly simple message for anyone still running old software: upgrade now. On Oct. 1, the Bitcoin Lightning Network node implementation warned that attackers are targeting nodes running version 26.06.7 or earlier, turning a patch released Sept. 22 into an urgent security matter.
Exactly what the attackers are exploiting remains under wraps. The project hasn’t confirmed that any attack succeeded or that funds were stolen, but version 26.06.8 patched vulnerabilities ranging from denial-of-service problems to a channel-closing defect capable of putting money on the line.
The Patch Came Before the Alarm
Core Lightning, maintained under the Elements Project, told node operators to move to the latest release “as soon as possible” after receiving reports of attackers targeting unpatched nodes. The crypto firm Blockstream amplified the warning and urged operators still running older builds to install 26.06.8.
The curious part is the calendar. Version 26.06.8 arrived Sept. 22, roughly 10 days before the attack warning, and maintainers already strongly recommend upgrading. Some tests were deliberately withheld to make the underlying vulnerabilities harder for prospective attackers to reverse-engineer while operators had time to patch. Then the heat was on.
Public descriptions of the release point to three classes of bugs. One could crash a sender’s node. Another could exhaust memory through Core Lightning’s REST interface. The nastiest involves channel closing and can potentially cost a user funds through a penalty mechanism gone wrong.
When Closing a Channel Goes Sideways
Moreover, the Lightning Network’s punishment system is designed so that if a peer cheats by broadcasting an obsolete channel state, then the honest participant can claim a penalty. A defect in the 26.06 line could cause Core Lightning to mistake certain transactions for an ordinary cooperative close and miss the revoked commitment hiding underneath.
In that scenario, software meant to catch the cheater could fail to pull the trigger, leaving the other side with funds that should have been forfeited. The project hasn’t said whether attackers are exploiting that particular flaw, the crash vulnerability, the REST problem or another issue whose details remain partially concealed.
That distinction matters. This isn’t a vulnerability in Bitcoin itself. It affects Core Lightning, one implementation of the Lightning Network, a scaling network built upon Bitcoin. LND, Eclair and LDK weren’t named in the advisory, while ordinary wallet users don’t necessarily run Core Lightning nodes at all. Their exposure depends on the infrastructure sitting behind their wallets.
A Security Cycle That Started in August
Thursday’s warning didn’t come out of nowhere. On Aug. 26, Core Lightning disclosed that it was sorting through a heavy batch of AI-generated vulnerability reports. Several turned out to be legitimate, prompting a coordinated fix.
Operators were told not to simply pull the plug. Instead, Core Lightning recommended restarting with –offline, which cuts peer connections while keeping the daemon watching the blockchain and able to respond to a force-close. A powered-down node can’t perform that job. Version 26.06.7 followed around Aug. 28, but another investigation opened Sept. 15 involving experimental features that could affect funds. Six days later came 26.06.8. Roughly 10 days after that, reports of active targeting landed.
Online Money Makes Patching Different
Lightning nodes aren’t cold wallets gathering dust in a drawer. Their channel keys stay online because nodes must route payments in real time. That makes outdated software more than an uptime headache. Funds can be sitting directly in the machinery an attacker is trying to break.
No public loss tally exists, and Core Lightning hasn’t said the attacks succeeded. For now, every node still running 26.06.7 or earlier remains in the group the project says attackers are targeting. Operators are being told to install 26.06.8 or later, verify signatures or Docker digests, and keep experimental features disabled unless they understand the risks.
The patch has been sitting in public for days. Now somebody appears to be knocking on the doors that haven’t installed it. In the meantime, many wonder how many more bugs will be found in the crypto industry by AI-assisted discoveries.
Lightning Security Alert: Alby Reveals Critical Hub Vulnerability
On Sept. 9, 2026, Alby, the Bitcoin Lightning Network and Nostr tooling company, revealed a critical security flaw in older…
Lightning Security Alert: Alby Reveals Critical Hub Vulnerability
On Sept. 9, 2026, Alby, the Bitcoin Lightning Network and Nostr tooling company, revealed a critical security flaw in older…
Lightning Security Alert: Alby Reveals Critical Hub Vulnerability
On Sept. 9, 2026, Alby, the Bitcoin Lightning Network and Nostr tooling company, revealed a critical security flaw in older…
Credit: Source link

