Newsroom
2 October, 2026 / News / AI / Tags: lightning, nodes, patches, operators, version

Node operators on version 26.06.7 or earlier face active threats after recent security patches for the Lightning Network software
The developers of Core Lightning, an open-source implementation for running nodes on the Bitcoin Lightning Network, issued an urgent call on Friday for operators to upgrade their software. Reports indicate that attackers are actively targeting systems still running version 26.06.7 or earlier.
The team stated that users on those older releases should move to the latest version without delay. The project has not disclosed the specific vulnerabilities under attack or confirmed whether any incidents resulted in lost funds.
The latest warning arrives weeks after Core Lightning released version 26.06.8 on September 22. That update followed an investigation announced on September 16 into reports of a potential issue involving experimental features that could affect user funds.
The September release included bug fixes and patches for vulnerabilities responsibly reported by multiple parties. Release notes credited the Bitcoin Red Team along with 12 named individuals and groups, plus anonymous reporters.
Among the addressed problems were flaws that could crash a sender’s node, requests capable of exhausting memory through the software’s REST interface, and a channel-closing bug that risked users losing funds to a penalty under certain conditions.
To reduce the chance of reverse-engineering while operators updated, the project deliberately withheld some tests from the public materials.
The September work built on an earlier round of fixes. In August, Core Lightning developers reviewed a large volume of Common Vulnerabilities and Exposures reports, many generated by automated AI tools. After validating the submissions, the team released version 26.06.7 on August 28 to resolve the confirmed issues.
Source code for that update was initially withheld for two weeks to give operators time to upgrade before potential attackers could examine the changes.
At that stage, the project offered an offline configuration option for nodes that could not update immediately. The setting disconnected the node from Lightning peers and halted payments while still allowing the software to monitor the Bitcoin blockchain.
Core Lightning’s Friday notice confirms only that reports of attacks on unpatched nodes have been received. It does not identify whether the targeted issues match those fixed in the September release or represent separate problems in older versions.
The software is used solely for Lightning Network nodes and does not involve a vulnerability in the underlying Bitcoin protocol. Operators are advised to install the current release as the primary response.
No total of any stolen funds has been disclosed, and the project has not provided further technical details on the attack methods.









