Newsroom

Core Lightning Urges Immediate Upgrade as Attackers Target Unpatched Bitcoin Nodes

2 October, 2026   /   News   /  AI   /   Tags:  lightning, nodes, patches, operators, version

Core Lightning Urges Immediate Upgrade as Attackers Target Unpatched Bitcoin Nodes

Node operators on version 26.06.7 or earlier face active threats after recent security patches for the Lightning Network software

The developers of Core Lightning, an open-source implementation for running nodes on the Bitcoin Lightning Network, issued an urgent call on Friday for operators to upgrade their software. Reports indicate that attackers are actively targeting systems still running version 26.06.7 or earlier.

The team stated that users on those older releases should move to the latest version without delay. The project has not disclosed the specific vulnerabilities under attack or confirmed whether any incidents resulted in lost funds.

Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible.
Core Lightning team

September Security Patches

The latest warning arrives weeks after Core Lightning released version 26.06.8 on September 22. That update followed an investigation announced on September 16 into reports of a potential issue involving experimental features that could affect user funds.

The September release included bug fixes and patches for vulnerabilities responsibly reported by multiple parties. Release notes credited the Bitcoin Red Team along with 12 named individuals and groups, plus anonymous reporters.

Among the addressed problems were flaws that could crash a sender’s node, requests capable of exhausting memory through the software’s REST interface, and a channel-closing bug that risked users losing funds to a penalty under certain conditions.

To reduce the chance of reverse-engineering while operators updated, the project deliberately withheld some tests from the public materials.

Prior Vulnerability Response in August

The September work built on an earlier round of fixes. In August, Core Lightning developers reviewed a large volume of Common Vulnerabilities and Exposures reports, many generated by automated AI tools. After validating the submissions, the team released version 26.06.7 on August 28 to resolve the confirmed issues.

Source code for that update was initially withheld for two weeks to give operators time to upgrade before potential attackers could examine the changes.

At that stage, the project offered an offline configuration option for nodes that could not update immediately. The setting disconnected the node from Lightning peers and halted payments while still allowing the software to monitor the Bitcoin blockchain.

Scope of the Current Alert

Core Lightning’s Friday notice confirms only that reports of attacks on unpatched nodes have been received. It does not identify whether the targeted issues match those fixed in the September release or represent separate problems in older versions.

The software is used solely for Lightning Network nodes and does not involve a vulnerability in the underlying Bitcoin protocol. Operators are advised to install the current release as the primary response.

No total of any stolen funds has been disclosed, and the project has not provided further technical details on the attack methods.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.