← All stories
⚠

Core Lightning node security and urgent upgrade advisories

Core Lightning has issued urgent guidance for operators after receiving reports that attackers are targeting nodes still running 26.06.7 or earlier. The project first flagged an investigatory issue on Sept. 16 tied to experimental features that could affect user funds, then shipped version 26.06.8 on Sept. 22. The 26.06.8 release bundled bug fixes and patches for vulnerabilities responsibly disclosed by the Bitcoin Red Team, 12 named researchers and groups, and several anonymous reporters. The changelog cites fixes for defects that could crash sender nodes, exhaust memory via the REST interface, and a channel-closing flaw that might cause funds to be lost through penalties.

Core Lightning’s public advisory urges immediate upgrade for anyone still on 26.06.7 or older, but the team has not disclosed which specific vulnerability is being exploited in the reported attacks or whether losses have been confirmed. Developers deliberately withheld a small set of tests from the public release to make reverse-engineering harder while operators update. The warning follows a coordinated security response that began in August, when the project processed a high volume of AI-generated CVE reports; several submissions were later verified and addressed in 26.06.7 (released Aug. 28) and subsequent updates.

The wider Lightning ecosystem has seen related incidents this year: BTCPay Server warned in August about an exploit affecting pre-2.4.2 releases that exposed LND admin macaroon credentials, later backing a 10% recovery bounty capped at 3 BTC. Separately, Bitcoin Core disclosed a high-severity issue tracked as CVE-2024-52911 in May and patched it in Bitcoin Core 29.0. For Core Lightning operators the actionable instruction is clear: upgrade to the latest release as soon as possible. Most end users who access Lightning via custodial or third-party wallet apps rely on those providers to manage updates, but self-hosted node operators face a direct upgrade obligation to protect funds in payment channels.