On October 2, developers at Core Lightning urged operators running nodes on versions 26.06.7 or earlier to promptly update their software. The team reported that attackers are targeting nodes lacking the latest security patches.

Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible.

We’ve received reports that attackers are targeting unpatched nodes. Keeping your node up to date is an important step in protecting your funds. https://t.co/E9ggGJsIit

— Core Lightning ⚡️ (@Core_LN) October 2, 2026

Details regarding the specific vulnerabilities exploited by the attackers and the potential consequences remain undisclosed, and there have been no confirmed reports of financial losses.

Core Lightning is a widely used implementation of the Bitcoin Lightning Network micropayment protocol, developed and maintained by Blockstream.

The current stable version is 26.06.8, which was released on September 22, and includes fixes for bugs and vulnerabilities identified by the Bitcoin Red Team, independent researchers, and other community members.

The developers strongly recommended upgrading to this version. To prevent reverse engineering of the patches, they temporarily withheld some test details, giving operators additional time to perform updates.

Previous Alerts

In August, the team encountered numerous vulnerability reports, some generated by AI tools. After investigation, the developers confirmed the existence of genuine security issues.

On August 27, Core Lightning representatives advised operators to switch their nodes to offline mode using the —offline parameter if they were unable to apply the fixes immediately. This mode disconnects the node from Lightning peers while still allowing it to monitor the Bitcoin blockchain.

A day later, version 26.06.7 was released with fixes for the confirmed vulnerabilities. The details of the patches were initially concealed for two weeks to minimize the risk of reverse engineering before a significant portion of the network could be updated. The source code was made public on September 11.

On September 16, Core Lightning specifically warned operators using experimental features to disable them while investigating potential issues that could affect user funds. Six days later, the developers released version 26.06.8 with additional security fixes, which they now recommend for users of versions 26.06.7 and earlier.

It is worth noting that in August, attackers managed to withdraw funds from Lightning Network nodes operating through the BTCPay payment server. The developers confirmed the theft and urged users of the LND software to update to version 2.4.2 immediately or disable their servers.

Follow ForkLog on social media

Telegram (main channel) Facebook X If you found an error in the text, highlight it and press CTRL+ENTER