Attackers are going after unpatched Bitcoin Lightning nodes right now. Core Lightning’s team put out an urgent call for operators still running version 26.06.7 or earlier to upgrade immediately — because people are actively getting hit.
Why It Matters
The urgency surrounding the upgrade to Core Lightning’s latest version underscores the ongoing security challenges within the Bitcoin Lightning Network, particularly as it gains traction in facilitating faster and cheaper transactions. As adoption increases, the ramifications of unpatched vulnerabilities could lead to significant financial losses for node operators and erode trust in the network’s reliability. This incident highlights the critical need for continuous vigilance and proactive maintenance among cryptocurrency infrastructure operators to safeguard against emerging threats.
The push started September 16, when Core Lightning began digging into potential problems affecting experimental features in its software. Within roughly a week, they had version 26.06.8 ready to ship. The update covered a range of vulnerabilities flagged by multiple sources, including the Bitcoin Red Team and various other individuals and groups who reported issues. The bugs were serious: some could crash nodes outright, others could exhaust memory through the system’s REST interface, and at least one could trigger unexpected channel closures that exposed users to penalty-based fund losses. That last one is particularly nasty in Lightning Network terms — a forced channel close under the wrong conditions can mean losing funds you should have kept.
Not pretty.
What Got Patched — and What Didn’t Get Disclosed
Core Lightning was deliberate about what it published alongside the release. Certain testing details were held back on purpose. The reasoning is pretty straightforward: if you hand attackers a full technical map of every patched flaw before operators have had time to upgrade, you’re basically giving them a window to hit the remaining vulnerable nodes. So the team kept some specifics quiet while the upgrade rollout happens.
The team hasn’t said which specific vulnerabilities attackers are currently exploiting. That’s frustrating if you’re an operator trying to assess your own risk, but it’s probably the right call from a security standpoint. Disclosing exact attack vectors mid-campaign tends to help the attackers more than the defenders. Efforts to reach Core Lightning for further comment haven’t produced a response yet.
What’s clear from the release notes is that version 26.06.8 credited multiple contributors for vulnerability reports. It wasn’t just the Bitcoin Red Team — anonymous sources and named individuals both fed into the process. That kind of broad community reporting is actually how Lightning Network security has tended to work, given how spread out the developer ecosystem is.
The AI-Generated CVE Surge That Came First
There’s some context here worth knowing. Back in August, Core Lightning dealt with a flood of AI-generated Common Vulnerabilities and Exposures reports. Someone — or multiple someones — was using AI tools to churn out CVE submissions, probably hoping a few real vulnerabilities would slip through in the noise. The team had to sort through all of it, confirm which ones were legitimate, and then coordinate fixes. That process produced version 26.06.7, which addressed the confirmed vulnerabilities from that batch.
So 26.06.8 isn’t a standalone event. It’s the second significant security release in a fairly compressed stretch of time, and it came specifically because the threat environment kept moving after 26.06.7 shipped.
Lightning Network node operators run software that handles real money in real time. A crashed node or an unexpected channel closure isn’t an abstract bug — it can mean actual financial loss for whoever’s on the other end of those payment channels. The stakes are different from, say, a web app vulnerability where the worst case is downtime.
That’s probably why Core Lightning moved fast. Roughly a week from initial investigation to a patched release is a quick turnaround, especially for a team that also had to coordinate with external reporters and decide what to disclose publicly.
What Operators Need to Do
Upgrade to 26.06.8. That’s it. Version 26.06.7 is now considered vulnerable, and anything older than that is obviously in worse shape. The team has been clear that the current attacks are targeting unpatched nodes specifically, so staying on an old version isn’t a calculated risk at this point — it’s just exposure.
Core Lightning says it’s continuing to monitor for new vulnerabilities and is staying engaged with the broader community to catch emerging threats early. No specifics yet on what comes after 26.06.8 or whether additional patches are already in the pipeline.
The Bitcoin Red Team’s involvement in flagging these vulnerabilities is worth noting. Their participation alongside anonymous reporters and named contributors made the patch possible at this speed.
Version 26.06.8 is out. Attackers are already moving. Operators still on 26.06.7 are the target.
Hub: Bitcoin price, news, and analysis
Frequently Asked Questions
Which Core Lightning version do operators need to run right now?
Operators should be on version 26.06.8, released after September 16 investigations. Anything at 26.06.7 or earlier is considered vulnerable to active attacks.
What kinds of bugs did the 26.06.8 update fix?
The update patched flaws that could crash nodes, exhaust memory via the REST interface, and trigger unexpected channel closures that expose users to penalty-based fund losses.