0x549203345492…54920331

ConfirmedSecurity627 vB92 sat/vB3 min decode

Core Lightning Warns Attackers Are Actively Targeting Unpatched Bitcoin Lightning Nodes

Core Lightning urged operators running version 26.06.7 or earlier to upgrade immediately, warning that attackers are actively targeting unpatched Bitcoin Lightning nodes.

Outputs

  1. Core Lightning warned on Friday that attackers are targeting nodes running version 26.06.7 or earlier and urged immediate upgrades.

  2. Version 26.06.8, released Sept. 22, patched vulnerabilities reported by the Bitcoin Red Team and 12 other named individuals and groups, including a channel-closing bug that could cause fund loss.

  3. In August, Core Lightning triaged a high volume of AI-generated CVE reports and released 26.06.7 within two days to fix confirmed vulnerabilities.

Core Lightning, the open-source Lightning Network node implementation maintained by Blockstream, has warned that attackers are actively targeting nodes still running unpatched versions of its software.

The team issued the warning on Friday, Oct. 3, telling operators to act without delay. “Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible,” Core Lightning said in a public statement.

The project did not specify which vulnerabilities attackers are targeting or estimate the potential impact on user funds. Operators running the affected versions face exposure that the maintainers consider serious enough to warrant an urgent, unscheduled public appeal.

The warning follows a rapid sequence of security activity. On Sept. 16, Core Lightning disclosed that it was investigating reports of a potential issue affecting experimental features in the software that could impact user funds. Roughly six days later, on Sept. 22, the project shipped version 26.06.8.

That release delivered general bug fixes alongside patches for “vulnerabilities responsibly reported by a number of sources.” The release notes credit the Bitcoin Red Team and 12 other named individuals and groups, in addition to anonymous reporters.

The changelog details three fixes with direct operational consequences for node operators. One patch addressed flaws that could crash the nodes of payment senders, an availability risk for routing operations. Another closed a vector in which malicious requests could exhaust memory in Core Lightning’s REST interface, a classic denial-of-service surface. A third fixed a channel-closing bug that could cause users to lose funds to a Lightning penalty transaction — a flaw with direct capital-loss implications rather than mere downtime.

The maintainers made a deliberate disclosure trade-off. Release notes for 26.06.8 withheld some regression tests to make it harder for attackers to reverse-engineer the patched vulnerabilities while operators completed their upgrades. The move signals that Core Lightning treats the flaws as exploitable in the window between disclosure and full network adoption of the patched release.

The episode also reflects a broader operational burden for open-source Bitcoin infrastructure maintainers. In August, Core Lightning said it was working on a coordinated fix after assessing a high volume of AI-generated Common Vulnerabilities and Exposures (CVE) reports submitted over recent weeks. Two days after that announcement, it released version 26.06.7 to address the confirmed vulnerabilities among those reports. The flood of machine-generated submissions forces maintainers to triage real defects from noise, stretching the time and attention available for genuine security work.

For Lightning routing operators and merchants running Core Lightning in production, the calculus is straightforward. Nodes left on version 26.06.7 or earlier now face confirmed, active scanning or exploitation attempts by unspecified actors, against vulnerabilities that include at least one fund-loss vector and multiple denial-of-service paths. Liquidity locked in channels on unpatched nodes carries that risk until operators complete the upgrade.

The situation also carries network-level implications. The Lightning Network’s routing capacity is concentrated among a relatively small set of well-run nodes, but a long tail of smaller operators often lags on updates. Widespread exploitation against stragglers could degrade routing reliability and erode confidence in Lightning as a payment rail, independent of any individual operator’s losses.

Core Lightning’s handling of the AI-generated CVE flood in August, followed by the confirmed vulnerabilities patched in 26.06.7 and the expanded fixes in 26.06.8, suggests the project is operating under sustained adversarial pressure. Operators should expect the maintainers to continue staged disclosure — patching first, publishing full technical detail later — and should treat any Core Lightning release labeled as security-relevant as an immediate operational priority rather than a routine maintenance item.

via x.com (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles