📈 Get daily crypto insights that make you smarter about your money

Hackers Are Now Actively Attacking Old Bitcoin Lightning Nodes — Why Core Lightning Operators Must Upgrade Today

The developers of Core Lightning, one of the main software implementations powering Bitcoin’s Lightning Network, have issued an urgent warning: attackers are actively targeting nodes still running version 26.06.7 or earlier, and every operator must upgrade to the latest release immediately.

By Amir Hassan | October 2, 2026

If you use Bitcoin only through an exchange app, this alert does not directly affect you. But if you run your own Lightning Network node — the second-layer system built on top of Bitcoin that makes small payments fast and cheap — this is the maintenance chore you cannot skip. Here is what happened, and why it matters for anyone who cares about how blockchain infrastructure stays secure.

The Hook: From Patches to Active Attacks

“Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible,” the Core Lightning team said. What makes this warning different from a routine patch notice is the word “attackers.” According to the team, it has received reports that bad actors are targeting nodes that have not been updated.

Notably, Core Lightning has not disclosed which vulnerabilities are being exploited, whether any attacks have succeeded, or whether any funds have been lost. That silence is deliberate — revealing the attack method would hand a roadmap to every copycat criminal. But it also means node operators cannot assess their own risk. The only safe assumption is that running old software is now dangerous.

On-Chain Evidence: What the Patches Actually Fixed

The latest release, version 26.06.8, shipped on September 22 with fixes for several security flaws responsibly disclosed to the project — including bugs that could crash nodes, exhaust their memory, or cause funds to be lost during channel closures. The release notes credit the Bitcoin Red Team alongside twelve named researchers and groups, plus anonymous reporters.

The timeline matters here. In August, Core Lightning developers confirmed multiple vulnerabilities after wading through a wave of AI-generated security reports — submissions produced by increasingly capable AI models scanning open-source code, not all of which were real. Version 26.06.7 followed on August 28, and its source code was deliberately withheld for two weeks so operators could update before attackers could study the changes and work backwards to find the patched flaws. The source was published after that embargo ended in September. A month later, someone appears to have done exactly that reverse-engineering work anyway.

The Core Conflict: Open Source Means Open Targets

This episode highlights the fundamental tension in open-source blockchain infrastructure. Lightning software’s code is public for anyone to inspect — that transparency builds trust and invites audit, but it also means that once a patch lands, clever attackers can compare old and new code to locate the very bug that was fixed. Developers deploy countermeasures like source embargoes and withheld test cases, but those only buy time.

The AI angle raises the stakes further. The same machine-learning tools that help security researchers find bugs faster also help attackers — and they flooded Core Lightning’s maintainers with reports that had to be manually verified. The Lightning ecosystem is, in effect, a live experiment in what software security looks like when both defenders and attackers have AI assistance.

For operators who genuinely cannot upgrade immediately, the team has previously offered a stopgap: run the node in offline mode, which disconnects it from Lightning peers and stops payments from being sent, received, or routed, while the software keeps monitoring the underlying Bitcoin blockchain. It is the digital equivalent of closing the shop but keeping the security cameras on.

Market Implications: A Broader Pattern of Lightning Trouble

The Core Lightning alert is not an isolated incident. Across 2026, several pieces of the Lightning ecosystem have faced security problems:

  • BTCPay Server warned in August of an active exploit affecting installations before version 2.4.2, which exposed administrator credentials carrying extensive permissions over connected Lightning wallets. Funds were drained from some affected nodes, and the project later backed a 10 percent recovery bounty, capped at 3 BTC if all stolen assets were recovered.
  • Zeus Wallet took its infrastructure offline after a cyberattack in the same month. The self-custodial wallet said the attack was contained within hours and customer funds were never at risk.
  • Bitcoin Core itself disclosed a high-severity vulnerability in May — tracked as CVE-2024-52911 — that could let a miner remotely crash nodes running versions after 0.14.0 and before 29.0, though exploiting it required costly proof-of-work and had been patched before disclosure.

For ordinary Bitcoin holders, the takeaway is not panic — none of these events compromised Bitcoin’s core chain. It is a reminder that the layers built around Bitcoin, especially the small-payment Lightning rails, are younger software maintained by small teams, and their security depends on operators staying current.

The Verdict

If you run a Core Lightning node on version 26.06.7 or earlier, stop reading and update — the attack reports are live, and the fixes have been available since September 22. If you are an investor watching from the sidelines, treat this as a preview of open-source security in the AI era: faster patches, but also faster weaponization of old bugs. Infrastructure risk rarely shows up in the price chart, but it shapes the trust that price ultimately rests on.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

8 thoughts on “Hackers Are Now Actively Attacking Old Bitcoin Lightning Nodes — Why Core Lightning Operators Must Upgrade Today”

  1. updated both my nodes within the hour of seeing this. refusing to say what the attack vector is while confirming active targeting is scary, you can’t even assess your own exposure on 26.06.7

    1. Same here. The disclosure tradeoff is fair, no roadmap for copycats, but ‘running old software is now dangerous’ is the only assumption a node operator needs anyway

  2. still on 26.06.7 because a plugin dependency pinned it. guess im compiling from source this weekend, thanks attackers

    1. check if your pinned plugin shipped a 26.08 release first, half of them patched within hours of the advisory. saved me a whole weekend of dependency hell on two nodes

      1. can confirm, my fee forwarder plugin shipped a 26.08 build within hours of the advisory. whole upgrade took maybe 20 minutes on both nodes. if you are still on 26.06.7 tonight you are basically volunteering your channels

    2. ^ feel this. two of my channels are with peers still on old CLN. their node getting popped means my liquidity gets stuck too

  3. Not disclosing which vulnerability is being exploited is standard practice, but it means operators cannot assess their own exposure. Upgrade now, ask later.

  4. the scary wording is actively targeting. advisories usually say could be exploited. someone is popping old CLN nodes right now and we only learn which bug when funds actually move

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$86,467.00+2.9%ETH$2,737.55+1.7%SOL$122.06+3.7%BNB$780.70+1.4%XRP$1.53+3.2%ADA$0.2551+3.7%DOGE$0.0966+2.3%DOT$1.22+3.1%AVAX$11.13+1.6%LINK$14.34+0.1%UNI$9.05-1.6%ATOM$1.75+1.8%LTC$70.27+4.7%ARB$0.2055+2.2%NEAR$4.89-1.2%FIL$1.05+4.7%SUI$1.19+3.4%BTC$86,467.00+2.9%ETH$2,737.55+1.7%SOL$122.06+3.7%BNB$780.70+1.4%XRP$1.53+3.2%ADA$0.2551+3.7%DOGE$0.0966+2.3%DOT$1.22+3.1%AVAX$11.13+1.6%LINK$14.34+0.1%UNI$9.05-1.6%ATOM$1.75+1.8%LTC$70.27+4.7%ARB$0.2055+2.2%NEAR$4.89-1.2%FIL$1.05+4.7%SUI$1.19+3.4%
Scroll to Top