Core Lightning warns operators on old versions as attackers target unpatched nodes

3 min read
Core Lightning warns operators on old versions as attackers target unpatched nodes
PrimeXBT Editorial Team
Reviewed by PrimeXBT

Topics in article

Core Lightning has told operators running version 26.06.7 or earlier to upgrade immediately after receiving reports that attackers are targeting unpatched nodes. The team has not said which vulnerabilities are being exploited or whether any attack has caused lost funds. The alert follows a string of security updates for the Bitcoin Lightning Network software since August.

Core Lightning has urged operators running version 26.06.7 or earlier to move to the latest release as soon as possible. According to the Core Lightning team: "If you're running version 26.06.7 or earlier, please upgrade to the latest release".

The team has not disclosed which vulnerabilities are being targeted in the reported attacks or what an attacker could achieve against an unpatched node. The warning therefore does not establish whether the attacks involve a flaw fixed in September or a separate issue affecting older versions.

Version 26.06.8 closed several flaws

Core Lightning released version 26.06.8 on Sept. 22 with fixes for vulnerabilities that had been responsibly disclosed to the project. The release notes credited the Bitcoin Red Team alongside 12 named researchers and groups.

The changelog covered a bug that could crash a sender's node, another that could exhaust memory through the REST interface, and a separate channel-closing issue that could cause a user to lose funds to a penalty. Core Lightning has not said whether any of those specific flaws are now being targeted.

AI-generated reports drove the August fixes

The situation follows a coordinated response that began in August, when developers confirmed vulnerabilities after reviewing a high volume of AI generated vulnerability reports. Not every submission represented a genuine problem, so developers reviewed and validated the reports before deciding which issues required fixes.

Version 26.06.7 followed on Aug. 28, with its source code initially withheld for two weeks to give operators time to update before the patched flaws could be studied.

Other Lightning software has faced incidents this year

BTCPay Server warned in August about an active exploit affecting installations that had not moved to version 2.4.2, a flaw that exposed LND administrator macaroon credentials and drained funds from some affected nodes. BTCPay Server later backed a 10% recovery bounty, capped at 3 BTC.

Zeus Wallet took its infrastructure offline days earlier after a cyberattack it said was contained within hours, adding that customer funds were neither lost nor placed at risk.

For Core Lightning operators, the instruction is narrower: nodes still running 26.06.7 or earlier should move to the latest release, while the project has yet to disclose the attack method behind the current warning.

Source: crypto.news

Trading involves risk.

Most traded markets

XAU / USD
+0.37% 4,192.71
BRENT
-3.37% 103.409
BTC / USD
+3.47% 86,205.6
EUR / USD
+0.2% 1.12652
USTEC
+0.74% 30,729.35
AAPL
+0.15% 330.94
View all markets

Author

PrimeXBT
Our Editorial Team consists of leading experts with a proven record in the fields of trading, cryptocurrencies, blockchain and finance. We thoroughly research the sources of information in order to provide readers with quality content that serves edu...
Read author’s articles
Alert Triangle Risk Disclaimer
Disclaimer: Some past publications may be outdated. We recommend following our news to stay up to date with the latest information. For any questions, feel free to contact our support team via the chat below.
The content provided here is for informational purposes only. It is not intended as personal investment advice and does not constitute a solicitation or invitation to engage in any financial transactions, investments, or related activities. Past performance is not a reliable indicator of future results.
The financial products offered by the Company are complex and come with a high risk of losing money rapidly due to leverage. These products may not be suitable for all investors. Before engaging, you should consider whether you understand how these leveraged products work and whether you can afford the high risk of losing your money.
The Company does not accept clients from the Restricted Jurisdictions as indicated in our website/ T&C. Some services or products may not be available in your jurisdiction.
The applicable legal entity and its respective products and services depend on the client’s country of residence and the entity with which the client has established a contractual relationship during registration.

Today in markets

Browse Crypto News

Register Now

Trading involves risk

Get started in minutes

Our clients love how fast and simple our sign-up is. It takes just a few minutes to get started!

Get Started Get Started
Get started in minutes

Need Help?

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.