The team behind Core Lightning, an open-source node software for the Bitcoin Lightning Network, has issued an urgent security update urging operators to upgrade immediately. The warning follows reports that attackers are specifically targeting unpatched nodes running version 26.06.7 or earlier. While Core Lightning did not specify which vulnerabilities were being exploited or the potential impact, the directive emphasizes upgrading to the latest release as soon as possible.

This alert builds on previous security developments. On Sept. 16, Core Lightning announced it was investigating a potential issue affecting experimental features that could impact user funds. Approximately six days later, the team released version 26.06.8, which included bug fixes and patches for vulnerabilities responsibly reported by the Bitcoin Red Team and other sources. The changelog noted fixes for flaws that could crash sender nodes, exhaust memory in the REST interface, or cause users to lose funds due to a channel-closing bug. Notably, the update deliberately withheld some tests to hinder attackers from reverse-engineering vulnerabilities during the transition period. Earlier in August, Core Lightning had addressed confirmed vulnerabilities with version 26.06.7 after assessing a high volume of AI-generated Common Vulnerabilities and Exposures (CVE) reports.