Core Lightning urges upgrades after attacks target old nodes

Core Lightning urged operators running version 26.06.7 or earlier to upgrade after receiving reports that attackers were targeting unpatched Lightning nodes.
The team behind Core Lightning, open-source software for operating Bitcoin Lightning Network nodes, urged users to upgrade immediately after receiving reports that attackers were targeting unpatched nodes.
In a Friday post, the team wrote: “Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible.” It did not identify the vulnerabilities being targeted or report confirmed losses.
The warning followed an investigation into a potential issue involving experimental Core Lightning features that could affect user funds. The team disclosed the issue on Sept. 16 and released version 26.06.8 about six days later, on Sept. 22.
The update included bug fixes and patches for vulnerabilities reported by several sources. Its release notes credited the Bitcoin Red Team, 12 named individuals and groups, and anonymous researchers.
According to the changelog, some fixes addressed flaws that could crash a node while sending funds or allow requests to consume excessive memory through the software’s REST interface. Another fix addressed a channel-closing bug that could cause users to lose funds through a penalty mechanism.
Core Lightning withheld some tests from the release to make it harder for attackers to identify the flaws and develop exploits while operators installed the update. The team did not provide a date for publishing the withheld testing information.
In August, Core Lightning reported a high volume of artificial intelligence-generated Common Vulnerabilities and Exposures reports and began coordinating a security fix. Two days later, it released version 26.06.7 to address the vulnerabilities it had confirmed.
Core Lightning is used to operate nodes on the Bitcoin Lightning Network, which processes Bitcoin payments through channels outside the main blockchain. Operators running older versions may remain exposed to vulnerabilities addressed in version 26.06.8.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








