Core Lightning Warning to Bitcoin users: Lightning Network Node operators, please upgrade immediately. Reports have been received that attackers are targeting systems still running version 26.06.7 or earlier.
Core Lightning indicates that operators running version 26.06.7 or earlier should upgrade immediately, as there are reports that attackers are targeting unpatched nodes.
Urgent Security Update: If you are running version 26.06.7 or an earlier version, please upgrade to the latest version as soon as possible, the team stated.
Core Lightning did not disclose which vulnerabilities were being targeted, nor did it explain what effects attackers could achieve on nodes that had not been patched. Therefore, this alert does not indicate whether these attacks are related to a vulnerability fixed in September or another issue affecting older versions.
Prior to the issuance of this alert, the developers of Core Lightning have released multiple rounds of security updates since August. crypto.news previously reported that after reviewing a large number of vulnerability disclosure reports ( CVE ) generated by AI, the project team identified several vulnerabilities in August.
At that time, operators waiting for the release of the secure version could choose to run Core Lightning in offline mode. This configuration would disconnect the node from other nodes in the Lightning group, and stop sending, receiving, or routing payments, while still allowing the daemon process to continue monitoring the Bitcoin blockchain.
Core Lightning Another set of vulnerabilities has been patched.
Security efforts continued to progress in September. Core Lightning stated on September 16 that they were investigating a potential issue involving an experimental feature.
Developers stated that this issue could affect users' funds, but no detailed information was disclosed immediately at that time. Subsequently, version 26.06.8 was released on September 22, which included bug fixes and patches for vulnerabilities that had been responsibly reported to the project team.
In the release notes for 26.06.8, thanks were expressed to Bitcoin Red Team, 12 named researchers and their teams, as well as those who chose to report issues anonymously.
Core Lightning It is highly recommended to install this version, and it is stated that there is no embargo period for this update. However, the developers have not yet made a small amount of test content publicly available.
The project team stated that keeping these tests confidential will make it more difficult for potential attackers to identify and reverse-engineer the underlying vulnerabilities during the operator's node updates.
From the software update logs, it can be seen that there are several security-related fixes. One of them addresses an issue that could cause the sender node to crash, while another fix deals with requests that may consume available memory through the REST interface using Core Lightning.
Another issue related to channel closure brings direct financial risks. In some cases, this vulnerability may result in users losing funds due to fines when closing a channel.
Core Lightning does not specify whether any of these specific vulnerabilities are currently being targeted. Its latest warning merely indicates that reports have been received of attackers targeting unpatched nodes.
Previous fixes were related to the AI report surge.
The latest developments continue another round of coordinated security responses that began in August.
At that time, Core Lightning stated that as more powerful AI models were used to scan open-source code for potential security issues, developers received a large number of vulnerability reports.
Not every submission is a genuine vulnerability; developers need to review and verify each report individually before deciding which issues require fixing. In the end, some of these reports were confirmed to be true.
Version 26.06.7 was released on August 28 to fix vulnerabilities discovered in this work. The developers initially delayed the public release of their source code by two weeks to give operators time to update their systems, in order to prevent potential attackers from reverse-engineering the fixed defects after studying the changes.
After the embargo period ends, the source code will be made public in September.
In previous security responses, Core Lightning advised operators that upgrading should be the primary measure. Nodes that cannot be immediately upgraded to the secure version can also be run in offline mode temporarily, rather than completely stopping the daemon process.
Keeping the daemon process running allows nodes to continue monitoring channel-related transactions on Bitcoin. Lightning nodes that are completely stopped will not perform the same monitoring when offline.
At that time, the project party did not disclose any evidence indicating that attackers had successfully exploited these vulnerabilities, nor did they report any financial losses suffered by users due to the confirmed vulnerabilities.
There has been a change in the situation in one regard: Core Lightning indicates that reports have been received of attackers targeting unpatched nodes, but it has not yet been disclosed whether any attacks were successful or whether any losses were incurred.
Lightning The software has also faced other security incidents.
In 2026, other software related to the Bitcoin Lightning ecosystem also encountered security issues.
In August, BTCPay Server warned users that there was a Lightning vulnerability that was being exploited, affecting installations that had not yet been upgraded to version 2.4.2.
This vulnerability will expose the macaroon credentials of the LND administrator in the affected BTCPay Server installations. The administrator has extensive permissions over the associated Lightning wallet. Once attackers obtain these credentials, they may use them to access the connected wallet.
Some funds from affected Lightning nodes were transferred away. BTCPay Server subsequently offers a 10% reward for recovery; if all stolen assets are recovered, the maximum reward will be 3 BTC.
BTCPay indicates that all versions prior to 2.4.2 are affected, including the candidate release version of 2.4.2. On-chain wallets are not affected by this vulnerability.
A few days earlier, Zeus Wallet took its infrastructure offline after encountering a cyberattack.
Zeus indicates that the attack was brought under control within a few hours, and during the audit period, the infrastructure was kept offline. This self-hosted Lightning wallet stated that customer funds were neither lost nor at risk; their investigation also did not find any vulnerabilities in the Lightning node software.
During the event, if the user's Lightning Service Provider channel is closed, an alternative channel will be provided after the service is restored.
Bitcoin node software also requires security updates in other areas.
Security fixes are not limited to software that runs directly on Lightning.
Bitcoin Core disclosed a high-risk vulnerability in May that could potentially allow miners to remotely cause affected Bitcoin nodes to crash. The vulnerability is identified as CVE-2024-52911 and affects versions after 0.14.0 and before 29.0.
Before making it public, the developers had already fixed this issue in Bitcoin Core 29.0.
The vulnerability involves the script interpreter of Bitcoin Core during block verification. A specially crafted invalid block may cause nodes to attempt to access data even after the relevant memory has been released.
To exploit this vulnerability, the attacker needs to generate a block that is specially constructed and contains sufficient proof of work to reach the top of the chain, making it a costly endeavor to utilize. Bitcoin Core indicates that remote code execution is possible, but due to limitations on block data, this outcome is considered unlikely.
For the operators of Core Lightning, the current instructions are clearer: those still running nodes with version 26.06.7 or any earlier versions should upgrade to the latest version as soon as possible; however, the project team has not disclosed the method of the attack, nor have they indicated which specific patched vulnerability is being targeted.












