Core Lightning Nodes Under Attack: Upgrade Immediately

1 hour ago 2 sources negative

Key takeaways:

  • Core Lightning's urgent patch exposes BTC Layer-2 security risks, pressuring node operators to upgrade.
  • Unknown exploit details may fuel uncertainty; swift upgrades could limit BTC Lightning contagion.
  • Traders should monitor fund-loss reports; repeated Lightning breaches may test BTC scaling confidence.

Core Lightning has issued an urgent security warning advising Bitcoin Lightning Network node operators to upgrade immediately after receiving reports that attackers are targeting systems still running version 26.06.7 or earlier. The team has not disclosed which vulnerabilities are being exploited or whether any attacks have resulted in lost funds.

The alert, shared on Oct. 2, follows the release of Core Lightning version 26.06.8 on Sept. 22. That update patched several security flaws, including a bug that could crash a sender’s node, a REST interface issue that could exhaust memory, and a channel-closing bug that carried direct financial risk by potentially causing users to lose funds to a penalty during channel closures.

Release notes credited the Bitcoin Red Team, 12 named researchers and groups, and anonymous reporters. Developers also withheld a small number of tests from the public release to make it harder for attackers to reverse engineer the patched vulnerabilities while node operators were updating.

The latest warning follows a wave of AI-generated vulnerability reports that Core Lightning developers have been reviewing since August. Version 26.06.7 was released on Aug. 28 after several reports were confirmed as legitimate problems, and its source code was initially withheld for two weeks. In September, Core Lightning said it was investigating a potential issue involving experimental features that could affect user funds.

The broader Lightning ecosystem has faced other security incidents in 2026. In August, BTCPay Server warned that installations before version 2.4.2 exposed LND administrator macaroon credentials, allowing funds to be drained from some Lightning nodes; a 10% recovery bounty capped at 3 BTC was later offered. Around the same time, Zeus Wallet took infrastructure offline after a cyberattack but said customer funds were not lost. Bitcoin Core also disclosed a high-severity vulnerability in May, tracked as CVE-2024-52911, that could allow a miner to remotely crash vulnerable nodes.

Core Lightning has not yet revealed the attack method or which patched flaw is being targeted in the current attacks, but operators on older releases should move to the latest version as soon as possible.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.