Core Lightning has told operators running version 26.06.7 or earlier to upgrade immediately after receiving reports that attackers are targeting unpatched nodes. The team has not said which vulnerabilities are being exploited or whether any attack has caused lost funds. The alert follows a string of security updates for the Bitcoin Lightning Network software since August.
Core Lightning has urged operators running version 26.06.7 or earlier to move to the latest release as soon as possible. According to the Core Lightning team: "If you're running version 26.06.7 or earlier, please upgrade to the latest release".
The team has not disclosed which vulnerabilities are being targeted in the reported attacks or what an attacker could achieve against an unpatched node. The warning therefore does not establish whether the attacks involve a flaw fixed in September or a separate issue affecting older versions.
Version 26.06.8 closed several flaws
Core Lightning released version 26.06.8 on Sept. 22 with fixes for vulnerabilities that had been responsibly disclosed to the project. The release notes credited the Bitcoin Red Team alongside 12 named researchers and groups.
The changelog covered a bug that could crash a sender's node, another that could exhaust memory through the REST interface, and a separate channel-closing issue that could cause a user to lose funds to a penalty. Core Lightning has not said whether any of those specific flaws are now being targeted.
AI-generated reports drove the August fixes
The situation follows a coordinated response that began in August, when developers confirmed vulnerabilities after reviewing a high volume of AI generated vulnerability reports. Not every submission represented a genuine problem, so developers reviewed and validated the reports before deciding which issues required fixes.
Version 26.06.7 followed on Aug. 28, with its source code initially withheld for two weeks to give operators time to update before the patched flaws could be studied.
Other Lightning software has faced incidents this year
BTCPay Server warned in August about an active exploit affecting installations that had not moved to version 2.4.2, a flaw that exposed LND administrator macaroon credentials and drained funds from some affected nodes. BTCPay Server later backed a 10% recovery bounty, capped at 3 BTC.
Zeus Wallet took its infrastructure offline days earlier after a cyberattack it said was contained within hours, adding that customer funds were neither lost nor placed at risk.
For Core Lightning operators, the instruction is narrower: nodes still running 26.06.7 or earlier should move to the latest release, while the project has yet to disclose the attack method behind the current warning.
Source: crypto.news
Trading involves risk.