📈 Get daily crypto insights that make you smarter about your money

Core Lightning Tells Node Operators to Upgrade Now as Attackers Target Older Versions

Core Lightning has issued an urgent warning to Bitcoin Lightning Network node operators: attackers are actively targeting systems still running version 26.06.7 or earlier, and anyone affected needs to upgrade immediately. The team behind the popular open source Lightning node implementation says it has received reports of attacks against unpatched nodes, though it has not disclosed which vulnerabilities are being exploited or whether any funds have been lost so far.

By Amir Hassan | October 3, 2026

The Alert

“Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible,” the Core Lightning team said in its warning to operators.

The message is deliberately short on detail. Core Lightning has not said which vulnerabilities the reported attacks involve, what an attacker could achieve against an unpatched node, or whether the activity is connected to the flaws fixed in recent releases. That ambiguity is part of responsible disclosure: saying too much before operators have patched would hand attackers a roadmap.

For regular investors, the practical takeaway is simple. If you run a Lightning node — or know someone who does — the fix is already available, and the window to apply it without incident is now.

What the September Patch Actually Fixed

The latest stable release, version 26.06.8, shipped on September 22 with bug fixes and patches covering vulnerabilities that had been responsibly disclosed to the project. The release notes credited the Bitcoin Red Team alongside 12 named researchers and groups, plus reporters who chose to stay anonymous. Core Lightning strongly recommended installing the release and said there was no embargo period, though developers temporarily withheld a small number of tests from the public release to make it harder for prospective attackers to reverse engineer the underlying flaws while operators were still updating.

Several of the fixes can be identified from the changelog, and each carries a different kind of risk:

  • Node crash bug — a problem capable of crashing a sender’s node, disrupting payment routing.
  • Memory exhaustion — requests through Core Lightning’s REST interface that could consume available memory and degrade or disable a node.
  • Channel closing flaw — under certain conditions, a bug that could result in a user losing funds to a penalty when a channel was closed, a direct financial risk rather than a mere availability issue.

Core Lightning has not confirmed that any of those specific flaws are what attackers are now targeting. The warning only states that reports have been received of attacks against unpatched nodes.

A Summer of Security Work

The current alert is the latest chapter in a busy few months for the project. In August, Core Lightning confirmed multiple vulnerabilities after reviewing a large volume of AI-generated Common Vulnerabilities and Exposures reports. Not every submission represented a genuine problem — developers had to validate the wave of reports before deciding which issues warranted fixes — but several were confirmed as legitimate.

Version 26.06.7, released on August 28, addressed vulnerabilities identified during that effort. In an unusual step, developers withheld the source code for two weeks to give operators time to update before attackers could study the changes and work backwards to identify the patched flaws. The source was published after the embargo ended in September.

Security work continued into September. On September 16, the team said it was investigating reports of a potential problem involving experimental features that could affect user funds, though details were not immediately released. Version 26.06.8 followed six days later.

What Operators Should Do

Upgrading is the project’s main recommendation, and it always has been. During the earlier response, Core Lightning told operators that nodes unable to install the security release immediately could temporarily run in offline mode instead of stopping the daemon entirely. That configuration disconnects a node from Lightning peers and stops payments from being sent, received or routed, while allowing the daemon to keep watching the Bitcoin blockchain for channel-related transactions — something a fully stopped node would not do.

The distinction matters. A routing node earns fees by forwarding payments, so downtime has a cost. Offline mode preserves the node’s ability to monitor its channels and respond to force-close situations on-chain while cutting off the attack surface that peer connections create. It is a stopgap, not a solution, but it is far better than an unpatched node exposed to the public network.

Why This Matters Beyond Node Runners

The Lightning Network is Bitcoin’s payments layer, and routing nodes are its plumbing. Most casual Bitcoin users never run one, but exchanges, wallets and payment processors increasingly rely on Lightning channels for fast, cheap transfers. A wave of compromised routing nodes would not threaten Bitcoin’s base layer, but it could freeze or steal channel funds and erode confidence in Lightning-based services.

The episode also highlights a newer dynamic: the August disclosure round was triggered partly by AI models being used to comb open source code for vulnerabilities. That cuts both ways. The same tooling that helps researchers find bugs quickly also lowers the barrier for attackers probing live systems, which compresses the time between a patch’s release and its exploitation in the wild. Core Lightning’s decision to embargo source code — twice in two months — reflects exactly that pressure.

For now, the project’s guidance stands: check your version, and if it is 26.06.7 or older, upgrade today. Attackers are not waiting, and neither should operators.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

Disclaimer: This article is for informational purposes only and does not constitute financial advice.

27 thoughts on “Core Lightning Tells Node Operators to Upgrade Now as Attackers Target Older Versions”

  1. Ran a CLN node for three years and this is the first time I have seen them refuse to name the CVE. Usually they at least hint at the class of bug. That silence makes me think the exploit is trivially discoverable once the patch diffs.

    1. Upgraded both my routing nodes within an hour of the alert. If you are sitting on 26.06.7 just do it now, the update is painless and your channels stay up.

    2. three years running and never seen them sit on the CVE name either. the changelog wording about channel closing is basically a hint, treat it as urgent

  2. Petra Lindqvist

    Genuine question for node runners: does an unpatched CLN node put channel funds at risk, or is it mostly peer gossip / data issues? The article says they will not say what an attacker can achieve, which is the part that worries me.

    1. The fact that they are seeing active attacks and still not disclosing tells you the window matters. Anyone who procrastinates Lightning updates because routing is boring is about to learn an expensive lesson.

    2. github thread has the answer, the channel closing bug is the funds exposure, penalty loss on a force close you never signed. ten minutes of upgrading beats praying

    3. from what people in the cln github thread are saying, channel funds are exactly the concern with the closing flaw. if you are unpatched, treat every peer as hostile until you upgrade

    4. channel closing flaw is the dangerous one per the github thread, unpatched nodes can lose funds on a close they didnt initiate. upgraded both my nodes an hour after the alert

    5. per the CLN github chatter the channel closing flaw is the funds one. if you cannot upgrade today at least watch for closes you did not initiate

    6. per the github thread yes, channel funds are exposed on the closing flaw. watch for closes you did not initiate and upgrade, the rpi path took me five minutes with channels intact

    7. answered upthread, the channel closing flaw is the funds exposure one. penalty loss on a force close you never initiated. upgrade before you touch anything else

  3. withholding CVE details while attacks are live is correct, the patch diff is disclosure enough for port scanners. no shame in pausing channels for a day if you cant patch tonight

  4. Channel closing flaw is the scary one. Penalty loss on a bug you didnt create is rough. Already bumped my node, took ten minutes.

    1. took me about the same. and the fact attackers are already probing means the patch diff is the real disclosure, upgrade first and read the changelog after

      1. this, the patch diff went public the second the release hit. anyone still on 26.06.7 is basically announcing it to port scanners

        1. channelwatch_ie

          the diff went public in minutes and the scanners were probing within the hour. upgraded both nodes before coffee, ten minutes is cheaper than one forced close

    2. Good on them withholding a few tests until people patched. Helps less when the changelog basically points at the fixes though.

    3. That REST memory exhaustion issue explains why my node kept choking last week. Rebooted it twice before reading this alert.

      1. sudden but explains a lot, my gossip restarts stopped the day i patched. the rest fix alone was worth the ten minutes

        1. same here, two weeks of random gossip restarts i blamed on my vps. upgraded monday, quiet since. the rest fix alone was worth it

  5. upgrade took five minutes on a raspberry pi node, channels came back up fine. no excuse to sit on 26.06.7 at this point

  6. half the network still shows old versions on the explorers. routing revenue is thin enough that some operators simply are not watching their nodes

    1. explorers showing hundreds of unpatched peers is also a map for the attackers. would not be shocked if fee income stops being the excuse after the first confirmed loss

  7. ran the update on three nodes within an hour of the notice. if you operate a routing node and you are still on an old version you are the low hanging fruit, full stop

  8. Worth remembering most lightning nodes are hobbyist boxes on a raspberry pi that someone set up in 2021 and never touched again. The upgrade notice will reach maybe half of them.

  9. Running 26.06.8 on two routing nodes since tuesday, gossip restarts gone and fee income looks normal. The scary part is the explorers still showing hundreds of unpatched peers

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$85,237.00-0.1%ETH$2,690.40-0.4%SOL$119.23-2.0%BNB$787.21-0.2%XRP$1.49-0.9%ADA$0.2635+6.4%DOGE$0.0943-0.2%DOT$1.20+0.2%AVAX$10.89-1.9%LINK$13.79-2.4%UNI$8.89-1.5%ATOM$1.80+1.3%LTC$70.38-1.4%ARB$0.2031+0.8%NEAR$5.00+2.4%FIL$1.10+4.2%SUI$1.18-5.0%BTC$85,237.00-0.1%ETH$2,690.40-0.4%SOL$119.23-2.0%BNB$787.21-0.2%XRP$1.49-0.9%ADA$0.2635+6.4%DOGE$0.0943-0.2%DOT$1.20+0.2%AVAX$10.89-1.9%LINK$13.79-2.4%UNI$8.89-1.5%ATOM$1.80+1.3%LTC$70.38-1.4%ARB$0.2031+0.8%NEAR$5.00+2.4%FIL$1.10+4.2%SUI$1.18-5.0%
Scroll to Top