Core Lightning Urges Immediate Upgrade as Attackers Target Unpatched Nodes
Core Lightning has told node operators running version 26.06.7 or earlier to upgrade immediately after receiving reports of attackers targeting unpatched Bitcoin Lightning Network nodes. The team did not disclose which vulnerabilities are being exploited or their potential impact.
The developers behind Core Lightning, an open-source node implementation for the Bitcoin Lightning Network, issued an urgent warning on Friday telling operators on older software to update right away. In a public message, the team said anyone running version 26.06.7 or earlier should move to the latest release as soon as possible, citing reports that attackers are actively targeting unpatched nodes. Cointelegraph reported that the team did not specify which vulnerabilities were being targeted or what impact a successful attack could have, and Cointelegraph has reached out to Core Lightning for comment.
The alert follows a security update shipped on Sept. 22 as version 26.06.8, roughly six days after Core Lightning said it was investigating reports of a potential issue affecting experimental features that could put user funds at risk. That release combined bug fixes with patches for vulnerabilities the team described as responsibly reported by a number of sources. The release notes credit the Bitcoin Red Team alongside 12 other named individuals and groups, as well as anonymous reporters, according to Cointelegraph.
The changelog detailed several of the flaws addressed, including bugs that could crash senders' nodes, requests capable of exhausting memory in Core Lightning's REST interface, and a channel-closing defect that could cause users to lose funds to a penalty. Notably, the maintainers deliberately withheld some tests from the release in order to make it harder for attackers to reverse-engineer and exploit the vulnerabilities while operators completed their upgrades.
The incident caps a stretch of heightened security activity for the project. In August, Core Lightning said it was assembling a coordinated fix after reviewing a high volume of AI-generated Common Vulnerabilities and Exposures reports that had arrived over the preceding weeks. Two days later it published version 26.06.7 to address the vulnerabilities that were confirmed at the time.
Core Lightning has not said how many nodes remain unpatched or whether any operators have already suffered losses. The team's guidance remains straightforward: operators on 26.06.7 or earlier should upgrade to the newest release immediately, while those already on 26.06.8 are on the version that carried the bulk of the recent fixes.
TopicsCore Lightning · Bitcoin Lightning Network · Blockstream · Bitcoin Red Team · version 26.06.8 · version 26.06.7 · Common Vulnerabilities and Exposures · Cointelegraph
Source: cointelegraph.com
Written by Paparazzi with AI. Not financial advice.

