Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Core Lightning warns of attacks targeting unpatched Bitcoin Lightning nodes
00

Core Lightning warns of attacks targeting unpatched Bitcoin Lightning nodes

Oct 2, 2026

Core Lightning has issued an urgent security warning advising Bitcoin Lightning Network node operators to immediately upgrade from version 26.06.7 or earlier. The warning follows reports of active attacks targeting unpatched nodes. While developers have not disclosed which specific flaws are being exploited or if any funds have been lost, the latest version 26.06.8 patches critical bugs that can crash nodes or cause users to lose funds during channel closures.

Active attacks and the version 26.06.8 patch

  • ▪Core Lightning developers temporarily withheld a small number of tests from the public release of version 26.06.8 to prevent attackers from reverse-engineering and exploiting the patched vulnerabilities.
  • ▪Core Lightning released version 26.06.8 on September 22, 2026, to patch a channel-closing bug, a node-crashing flaw, and REST interface memory exhaustion bugs, approximately six days after disclosing an investigation into experimental features that could affect user funds.
  • ▪Core Lightning warned Bitcoin Lightning Network node operators on October 2, 2026, to immediately upgrade nodes running version 26.06.7 or earlier due to reports of active attacks targeting unpatched nodes.
  • ▪Core Lightning has not publicly disclosed which specific vulnerabilities are being exploited in the active attacks or whether any node operators have lost funds.

Security risks for node operators

  • ▪Lightning Network nodes are attractive targets because they must keep cryptographic keys online to route payments in real time, giving attackers direct access to funds on unpatched systems.
  • ▪Only Bitcoin Lightning Network users who operate their own Core Lightning nodes need to manually install the security update, while wallet app providers typically handle upgrades for non-node-running users.

August 2026 security response

  • ▪During the August 2026 security response, Core Lightning advised operators who could not immediately upgrade to run their nodes in an offline mode that monitored the Bitcoin blockchain while stopping payments.
  • ▪In August 2026, Core Lightning developers received AI-generated vulnerability reports and released version 26.06.7 on August 28, 2026, to address the confirmed flaws, withholding its source code for two weeks to allow operators time to update.

Other August 2026 Lightning exploits

  • ▪An active exploit in August 2026 targeted BTCPay Server installations, exposing administrator credentials and allowing attackers to drain funds from some connected Lightning nodes.
  • ▪Zeus Wallet temporarily took its infrastructure offline following an August 2026 cyberattack, but confirmed that customer funds were neither lost nor placed at risk.

Debatable claims

  • ▪Core Lightning's withholding of security tests is justified to protect unpatched nodes
  • ▪Core Lightning should immediately disclose the specific vulnerabilities being actively exploited
  • ▪The Lightning Network's requirement of keeping keys online poses an unacceptable security risk

5 sources

Gncrypto
Core Lightning Urges Upgrades After Attacks Target Old Nodes
View source article
Crypto
Bitcoin Lightning security alert issued as attackers target older Core Lightning nodes
View source article
Cointelegraph
Core Lightning Warns of Attacks on Unpatched Nodes
View source article
Beincrypto
Is Your Bitcoin on Lightning at Risk? Depends on Who Runs the Node
View source article
Blockonomi
Core Lightning Warns Bitcoin Node Operators to Upgrade After Attack Reports
View source article

Story comments

Loading comments…

Topics

Bitcoin security & risksBitcoin Layer 2s & scaling