Core Lightning Urges Upgrade as Attackers Target Unpatched Lightning Nodes
Key Takeaways
- •Core Lightning's team has urged operators on version 26.06.7 or to upgrade immediately following reports that attackers are targeting unpatched Lightning Network nodes.
- •The developers have not disclosed which vulnerabilities are being attacked or what impact the targeting could have on affected nodes.
- •Version 26.06.8, released on Sept. 22, patched flaws that could crash sending nodes, exhaust memory in the REST interface, and cause users to lose funds through a channel-closing penalty bug.
- •The release intentionally withheld some tests to make it harder for attackers to reverse-engineer and exploit the vulnerabilities while operators upgraded.
- •The warning follows an August episode in which version 26.06.7 addressed confirmed vulnerabilities after a high volume of AI-generated CVE reports, though the team has not said whether the current targeting involves the September fixes or anything newer.

The team behind Core Lightning, an open-source node implementation for the Bitcoin Lightning Network, has urged operators running older versions to upgrade immediately after receiving reports that attackers are targeting unpatched nodes.
“Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible,” the team said in a Friday post on X. Blockstream, the company behind Core Lightning, shared the same alert on X.
Core Lightning did not specify which vulnerabilities the attackers were targeting or what impact the activity could have. Cointelegraph reached out to Core Lightning for comment. With no technical details released, the upgrade call is the only guidance the team has attached to the warning.
Core Lightning, formerly known as c-lightning, is developed by Blockstream and is among the widely used implementations for operating a node on the Lightning Network, Bitcoin’s layer-2 payment protocol that enables faster and cheaper transactions through off-chain payment channels. Because balances in those channels are held and moved by node software rather than the Bitcoin base layer, the implementation an operator runs is directly responsible for channel funds — a reason implementation teams stress prompt version upgrades when targeting is reported.
On Sept. 16, Core Lightning said it was investigating reports of a potential issue affecting experimental features in the software that could impact user funds. Roughly six days later, it released version 26.06.8.
The Sept. 22 update delivered general bug fixes alongside patches for “vulnerabilities responsibly reported by a number of sources.” The release notes credit the Bitcoin Red Team and 12 other named individuals and groups, along with anonymous reporters.
According to the changelog, the fixes addressed flaws that could crash senders’ nodes, requests that could exhaust memory in the software’s REST interface, and a channel-closing bug that could cause users to lose funds to a penalty.
The release deliberately withheld some tests to make it harder for attackers to reverse-engineer and exploit the vulnerabilities while operators upgraded.
The warning follows an earlier episode in August, when Core Lightning said it was working on a coordinated fix after assessing a high volume of AI-generated Common Vulnerabilities and Exposures (CVE) reports received over recent weeks. Two days later, it released version 26.06.7 to address the confirmed vulnerabilities.
The team has not said whether the reported targeting involves the Sept. 22 fixes or anything newer, leaving the Friday alert and any follow-up disclosure as the details to watch. In the meantime, operators can check their installed version against the 26.06.7 threshold named in the alert.
Related: Core Lightning confirms multiple vulnerabilities, prepares security update