Open-Source Bitcoin Lightning Implementation Core Lightning Warns that Attackers are Targeting Unpatched Nodes

Core Lightning maintainers issued an urgent notice on October 2, 2026, telling operators of the open-source Bitcoin Lightning implementation to move off older builds after receiving reports that attackers are actively probing nodes that have not applied recent security updates.

In a post from the project’s official account, the team said anyone still running version 26.06.7 or anything earlier should install the current release as soon as possible.

The message stated that reports of targeting against unpatched nodes had already come in, and it framed routine upgrades as a practical step in safeguarding channel balances.

The notice did not name the flaws under attack, describe an exploit path, or confirm any loss of funds.

It pointed operators toward the latest published release rather than describing a temporary workaround.

The warning sits on top of a compressed security cycle that began in late summer.

In August 2026, Core Lightning said a surge of vulnerability reports, many of them machine-generated, had turned up real issues.

Maintainers shipped version 26.06.7 on August 28 with signed binaries and held the matching source back for about two weeks so operators could update before the changed code made the bugs easier to reconstruct.

Nodes that could not upgrade immediately were advised to restart with an offline flag that blocks peer traffic while the process continues to watch the Bitcoin chain and respond if a counterparty force-closes a channel.

Powering a node completely off was described as the weaker choice, because an offline machine cannot detect cheating attempts.

Mid-September brought a separate investigation into problems tied to experimental features that could affect user funds.

On September 22 the project published version 26.06.8, which it recommended for every node runner.

Unlike the prior point release, that update carried no embargo: the release and its fixes were available at once.

A small set of tests was still withheld for a time so the underlying issues would be harder to reverse-engineer while operators installed the software.

Release notes credited the Bitcoin Red Team, a list of named researchers, and anonymous reporters.

Public changelog descriptions of the September fixes refer to defects that could crash a sending node, requests capable of exhausting memory through the REST interface, and a channel-closing bug that could leave a user exposed to a penalty.

Separate reporting has also described a revoked-commitment path in which an old channel state might be broadcast without the usual penalty response.

Core Lightning has not said whether the attacks reported on October 2 map to any one of those issues.

The project’s own earlier posts stressed that keeping a node current is part of protecting funds, and the October notice repeats that stance under more urgent language.

Operators on Docker should also confirm image digests, because some images tagged as 26.06.7 between late August and early September reported the new version at startup without containing the corresponding fixes.

Those tags were later replaced.

Lightning nodes hold live payment channels outside the base chain, so a reachable, unpatched process can be messaged by peers.

The October advisory treats that exposure as active rather than theoretical and asks operators on 26.06.7 or older to upgrade without delay. Technical detail on what the attackers are using remains unpublished in the notice itself.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend